top of page

Chatit Privacy Policy

Privacy Policy 

Effective Date: Sep 25, 2025
Developer: Eunseong Choi
Contact: jxlove2004@gmail.com
Scope: This Policy applies to the chatit mobile app and all user-generated content (UGC) features in the United States.

1) Who can use chatit

  • Age 13+ only. If you’re under 13, do not use chatit (COPPA).

  • Eligibility. We primarily serve verified U.S. university communities and may require verification via a school (.edu) email.

2) Information we collect

Account & identity. School email (and confirmation status), display name/nickname you choose, password stored as a salted hash (never the raw password), your selected school/campus.
Approximate location by campus. We infer your campus (and thus an approximate location) from your school selection/email domain; we do not request precise GPS location.
Content you create. Posts, comments, images, messages, and related timestamps/board or chat identifiers.
App & device data (Firebase). Analytics events (app opens, screens, taps, performance), crash logs/diagnostics (device model, OS version, error traces, approximate IP at time of error), Firebase instance identifiers.
Support & reports. Email, description, and attachments you send when contacting support or reporting abuse.
Push notifications (optional). Device push token, used only to deliver notifications you enable.

3) How we use information

  • Provide the service (account, login, campus feeds, search, notifications you request).

  • Safety & moderation (detect and address spam, harassment, illegal content; enforce Terms).

  • Analytics & reliability (measure features, improve performance, debug crashes via Firebase).

  • Communications (respond to inquiries, important service notices).

  • Advertising (see §4).

  • Legal compliance (comply with law, protect rights, safety, and property).

4) Advertising, tracking & your choices

We use Google Mobile Ads (AdMob) to show ads. With personalized ads, Google and its partners may use device identifiers (IDFA/AAID), limited app interaction signals, and approximate location to select and measure ads across apps and websites.

  • AppTrackingTransparency (iOS). We request ATT consent before any cross-app tracking for ads.

  • California (CPRA). Personalized ads are treated as “sharing” for cross-context behavioral advertising. You can opt out at any time via Settings → Privacy → “Do Not Sell or Share My Personal Information”. We do not sell personal information for money.

  • Other states (e.g., VA/CO/CT/UT). You can opt out of targeted advertising via Settings → Privacy → “Opt-Out of Targeted Ads”.

  • Choice. If you opt out (or decline ATT), we will serve non-personalized (contextual) ads instead.

  • What we don’t do. We don’t use or disclose sensitive personal information for purposes requiring a “Limit” right.

5) When we disclose information

We don’t sell or rent your data. We disclose only:
Service providers (e.g., Google Firebase/AdMob, cloud hosting, email delivery) under contracts to process data on our behalf;
Legal & safety (e.g., to comply with law, enforce Terms; CSAM is reported to NCMEC/law enforcement);
Business changes (e.g., merger/transfer with notice and equal or stronger protections).

6) Your rights & controls

  • Account controls. Edit or delete your posts; delete your account at My Page → Delete Account.

  • Ads/privacy controls.

    • iOS ATT consent manager;

    • Do Not Sell or Share and Opt-Out of Targeted Ads toggles in Settings → Privacy.

  • State privacy rights (incl. California). You may request access, deletion, or correction of personal information, and appeal a denied request.

    • Submit requests to jxlove2004@gmail.com. We verify identity (e.g., via school email).

    • Authorized agents may submit requests with proof of authorization.

7) Automated moderation & appeals

We use automated tools and human review to flag harmful or clearly policy-violating content (e.g., spam, doxxing). These tools can affect posting or account status.

  • Appeal any moderation action via [INSERT CONTACT EMAIL] with links/screenshots.

8) Data retention

We keep personal information only as long as necessary to fulfill the purposes described above or to comply with legal obligations (e.g., tax, security, safety, audit), and then delete or irreversibly de-identify it.

  • Account deletion. When you delete your account, we delete or de-identify associated personal information without undue delay, retaining only minimal records we are legally required (or reasonably necessary) to keep for security/fraud prevention and to honor opt-out preferences.

  • We aim to use the shortest feasible retention periods for analytics/ads diagnostics consistent with provider defaults.

9) Security

Transport encryption (TLS), credential hashing, access controls, least-privilege practices. No method is 100% secure; use a strong, unique password.

10) Children’s privacy

Not for children under 13. If we learn we collected data from a child under 13, we will delete it and may disable the account.

11) International transfers

Data is primarily processed in the United States, but service providers may process in other countries. We use contractual and technical safeguards for such transfers.

12) Changes to this Policy

We’ll update this Policy as the app evolves. We’ll post the new effective date and notify you of material changes in-app or by email.

13) Contact us

Questions or privacy requests: jxlove2004@gmail.com

bottom of page