OrioChat agreement title: Privacy Policy and Personal Information Collection/Use Consent

Privacy Policy and Personal Information Collection/Use Consent

Last revised August 26, 2026; effective immediately

Operator and global privacy contact

OrioChat is operated by holykhw. Privacy, security, data-rights, account-deletion, abuse-reporting, and moderation-review requests can be sent to [email protected].

This policy reflects OrioChat's actual app functions: Cloudflare Workers for APIs, authentication, and authorization; Cloudflare D1 for account, session, friend, room, membership, billing, and report records; Cloudflare Durable Objects for real-time chat, presence, and push-to-talk control; Cloudflare R2 for media, custom emoji, and report attachments; Cloudflare Queues and D1 durable state machines for delivery and deletion jobs; Cloudflare observability and Cloudflare Pages; Cloudflare Realtime SFU for push-to-talk voice transport; local-first message storage on the user's device; optional user-started Orio Cloud backup and restore; Android push delivery through Firebase Cloud Messaging (FCM); iOS push delivery through APNs; Apple and Google sign-in; Qonversion for store entitlements where enabled; Google Mobile Ads / AdMob, consent-management signals, and advertising identifiers only where advertising is enabled.

If you choose Google Sign-In, OrioChat receives only the basic Google account information authorized by you, such as your Google account identifier, email address, display name, and profile image. OrioChat uses that information only for authentication, account identity, profile setup, account security, abuse prevention, customer support, and service operation. The sign-in integration does not request access to Gmail, Google Photos, or other unrelated Google product data, and OrioChat does not sell Google user data or use it for advertising, unrelated profiling, or training generalized AI/ML models.

Effective August 26, 2026, OrioChat stores, accesses, or collects information directly or indirectly on or from users' devices and allows its service providers to do so where applicable. This includes placing, accessing, or recognizing cookies, local storage, advertising identifiers such as AdID or IDFA, SDK or device identifiers, and similar technologies on users' devices or browsers. Depending on the feature, region, consent choice, and device settings, these technologies process device and app information, approximate region, advertising and consent choices, diagnostics, fraud-prevention signals, and feature state to provide, secure, measure, and operate the service. OrioChat requires service providers and SDK operators to process this information only for the disclosed purposes and to provide the same or equivalent protection required by this policy and applicable law.

Core retention and safety baseline

OrioChat keeps personal data only for as long as needed for the purposes described in this policy, including service delivery, local-first message delivery support, account security, content moderation, abuse prevention, legal compliance, dispute handling, billing and refund support, backup cleanup, and account deletion processing.

Purchase, entitlement, cancellation, refund, and chargeback support may require transaction identifiers, entitlement state, delivery status, activation time, usage or consumption status, support history, and fraud-prevention records. Safety reports, moderation actions, and safety records may be retained after content or account deletion where needed to prevent repeat abuse, handle disputes, comply with law, or protect users.

For post-launch operation at scale, OrioChat may process report queues, moderation signals, appeal records, incident response records, lawful request records, account-compromise signals, rate-limit records, and transparency metrics where needed to protect users, comply with law, respond to authorities, and operate the Safety, Reporting, and Transparency Policy.

AI voice model packs are downloaded from OrioChat's Cloudflare-hosted model service, integrity-checked, and stored on the user's device. A model-download request may create ordinary network metadata such as an IP address, request time, requested model path, and security logs. Voice conversion itself runs on the device. Microphone audio is not uploaded to the model-download service or used to train a generalized AI model; only the resulting live audio follows the same Cloudflare Realtime SFU transport selected for push-to-talk communication.

OrioChat will publish changes to this policy with an updated revision date. It will provide advance notice or request renewed consent before a material change, a new collection or use purpose, or another change where applicable law requires notice or consent. Mandatory privacy rights that cannot be waived remain unaffected.

YouTube Music playlist sharing

When a user shares a public or unlisted YouTube Music playlist, OrioChat uses YouTube API Services to validate the playlist and show its playlist ID, title, owner name, item count, thumbnail, and most recent API refresh time in the user's profile capsule. Opening a playlist may request its current item list from YouTube through OrioChat, but OrioChat does not store that item list or page tokens. This feature does not use Google OAuth, does not receive Google account credentials, does not download or separate audio, and sends users to YouTube Music for playback.

YouTube API-derived profile metadata is refreshed at least once every 30 calendar days. If refresh is unavailable, OrioChat removes the API-derived title, owner, item count, thumbnail, and refresh time and keeps only the user-submitted playlist reference for a bounded retry. A user can replace or remove the shared playlist in profile editing. Related stored profile data is deleted through OrioChat account deletion as soon as reasonably possible and no later than 7 days after the deletion command is accepted.

Learn how Google handles information in the Google Privacy Policy. Google account permissions can be reviewed in Google security settings, although this playlist-sharing feature does not request Google OAuth access.

Shared policy for all supported regions

The shared policy applies across all supported regions. Regional provisions are also shown in full to every reader and apply to the regions they name. Mandatory local rights remain unaffected.

OrioChat collects and uses personal information for account creation and sign-in, profiles, friends and contact-based friend discovery, chats, messages, media transmission, reporting and blocking, letters/mailbox, custom emoji, real-time Walkie Talkie voice communication, push notifications, security, customer support, incident analysis, and service improvement.

Information processed may include email addresses, social sign-in identifiers, user IDs, personal serial numbers or friend-code identifiers, nicknames, profile images, contact-matching information, friend relationships, chat-room and message metadata, text and media sent by users, reporting and blocking records, letter/mailbox data, custom emoji data, information processed for voice communication through Cloudflare Realtime SFU, push tokens, device information, access records, and error and performance logs. Depending on the features used, OrioChat may process camera, microphone, photos, videos, files, contacts, notification tokens, Bluetooth or audio-route status, Android foreground-service, overlay, and battery-optimization status, advertising IDs when ads are enabled, and biometric-authentication status for local app lock. The OS processes biometric authentication; OrioChat does not receive or store biometric templates. Legal-document pages may use GeoJS for IP-based country determination to display the regional document first, and users can switch regions manually on the page.

Voice communications are processed to provide real-time transmission. Chat messages, shared media, profile data, reports, blocks, and account records may be stored as needed to provide the service, enforce policies, prevent abuse, and comply with legal obligations.

OrioChat is designed as a local-first chat service. Chat history shown in the app is primarily stored in the local message database on your device. Server systems are used for authentication, permission checks, push or wake signals, temporary per-recipient delivery, media transfer, delete or control events, and cloud backup or restore that you explicitly start. After delivered messages are applied locally and acknowledged, server-side delivery copies may be deleted.

Cloud storage and cloud backup are optional product features. If you choose to upload a backup, the backup may contain selected local messages, media, message metadata, chat identifiers, room information, backup identifiers, file names, storage paths, sizes, timestamps, and transfer status. Orio Cloud backups are controlled by OrioChat and can be deleted through the app's backup controls. Final account deletion schedules that account's Orio Cloud backup records and stored objects for deletion as part of account-deletion processing.

Secret rooms are excluded from chat export and cloud backup by design. Supported secret-room text is stored and transmitted as client-side encrypted text, but secret rooms are not a promise that every communication is end-to-end encrypted or invisible to all service systems. Membership, room identifiers, delivery and control metadata, timestamps, system messages, reports, security records, push and diagnostic logs, and media or voice information needed to operate the service may still be processed.

Service providers may include Cloudflare for Cloudflare Workers API, authentication, and authorization; Cloudflare D1 records; Cloudflare Durable Objects real-time coordination; Cloudflare R2 object storage; Cloudflare Queues delivery and deletion jobs; Cloudflare observability; Cloudflare Pages; and Cloudflare Realtime SFU voice transport. Google is used only for Android Firebase Cloud Messaging (FCM), Google sign-in, and Google Mobile Ads / AdMob and Advertising ID where advertising is enabled. Apple is used for Apple sign-in, APNs, and Apple Music-related APIs selected by the user. Qonversion manages subscription entitlements when paid features are enabled. GeoJS may display the appropriate legal region, which users can change manually.

If ads are enabled, OrioChat may process advertising identifiers, device and app information, approximate region, ad delivery and interaction data, fraud-prevention signals, and consent or privacy-choice signals. Marketing-message consent is separate from advertising personalization choices. See the Ads and Privacy Choices page for more detail.

These providers may process or store data in the United States, Canada, Europe, Japan, Korea, and other infrastructure or subprocessor locations used to provide the service. OrioChat uses these providers as service vendors or processors for hosting, storage, delivery, security, diagnostics, payments, ads where enabled, and legal-page region display.

OrioChat uses reasonable technical and organizational safeguards appropriate to the service, including encrypted network transport, server-side authorization, least-privilege access controls, secure local storage, Cloudflare observability, abuse investigation, and client-side encryption at rest for supported chat text. These safeguards do not mean that every message or communication is end-to-end encrypted.

You may request access, correction, deletion, or other privacy assistance by contacting [email protected].

When you use GIF search or view GIF results, KLIPY may receive your search terms, a session-scoped pseudonymous customer ID, locale, IP address, viewed-content history, and, when GIF advertising is enabled, device display and ad-delivery parameters. KLIPY uses this information to provide and localize GIF search and content, measure usage, prevent fraud, and deliver advertising where enabled.

Canada

Canadian users may request access to personal information, correction of inaccurate or incomplete information, deletion assistance, withdrawal of consent where applicable, and privacy support by contacting [email protected]. OrioChat may retain information where needed for service delivery, security, abuse prevention, legal compliance, dispute handling, backup cleanup, or account deletion processing.

Europe

For Europe, OrioChat is operated by holykhw, which is the published controller/developer contact for this service. Privacy contact: [email protected].

OrioChat processes personal data to perform the service contract, maintain account and communication features, protect users and the service, comply with legal obligations, and, where required, based on consent. Users in Europe may have rights to access, rectification, erasure, restriction, portability, objection, and withdrawal of consent.

Personal data from users in the United States, Canada, Europe, Korea, Japan, and other supported regions may be transferred to and processed by service providers used to operate OrioChat. We use reasonable contractual and technical safeguards appropriate to the service provider and data type.

Where ads are enabled and European consent rules apply, OrioChat uses Google privacy messaging or another Google-certified consent management platform where required before requesting ads that need consent. Consent and privacy-choice signals may be processed for ad selection, measurement, fraud prevention, and vendor compliance. Users can change available ad privacy choices through the app's privacy options entry point when required.

대한민국

개인정보 처리위탁 및 국외 처리는 서비스 제공에 필요한 범위에서 이루어집니다. 수탁자 또는 처리 제공자에는 Cloudflare Workers, Cloudflare D1, Cloudflare Durable Objects, Cloudflare R2, Cloudflare Queues, Cloudflare 운영 모니터링·진단 기능, Cloudflare Pages 및 Cloudflare Realtime SFU를 제공하는 Cloudflare, Android 푸시 전달용 Firebase Cloud Messaging (FCM)과 Google 로그인, Google Mobile Ads를 제공하는 Google, Apple 로그인, APNs, Apple Music API를 제공하는 Apple, Qonversion, GeoJS 등이 포함될 수 있습니다. 관련 정보는 미국, 유럽, 일본, 대한민국 및 각 제공자의 인프라 또는 재위탁 처리 위치에서 처리 또는 보관될 수 있습니다.

개인정보는 서비스 제공, 보안 및 부정 이용 방지, 법령 준수, 분쟁 대응, 백업 보관, 계정 삭제 처리에 필요한 기간 동안 보관합니다. 이용자는 [email protected]으로 열람, 정정, 삭제, 처리정지, 동의 철회를 요청할 수 있습니다.

개인정보 보호 및 문의 담당: holykhw, 이메일 [email protected].

Other Regions

If local law gives you additional rights to access, correct, delete, restrict, object to, port, or withdraw consent for personal data processing, contact OrioChat and we will handle the request according to applicable law and the technical limits of local device data, other users' copies, security records, and backup cleanup.