Privacy Policy
Effective Date: September 13, 2026
HZ Chat provides lightweight chat rooms designed for real-time communication, including temporary chat rooms and optional reusable Fixed Rooms with account features and paid subscription plans.
We follow a Data Minimization philosophy. Beyond the essential information required for authentication, account management, subscription management, and service integrity, we do not collect or retain unnecessary personal data. Chat messages are transmitted in real time and are not used for profiling or stored as a permanent server-side message archive.
1. Data Minimization and Account Information
We operate on a Data Minimization basis to ensure only the absolute minimum information required for service delivery is processed. We commit to not integrating any third-party advertising, marketing, or behavioral tracking SDKs.
1.1 Guest Users
Guest users can access core chat features without creating an account. We do not require personal identification information for basic participation.
1.2 Account Holders (Registered Users)
To provide basic account management and authentication, we only process the following information upon account creation:
Account Credentials: A unique username and a cryptographically hashed password. We cannot access or recover your actual plain-text password.
Optional Email: Collected only if you choose to provide it. This email is used exclusively for account recovery purposes, such as password reset or account access assistance. We do not use this email for marketing, promotional messages, or non-essential communications.
Activity Metadata: We record your last login timestamp. This data is used solely for analyzing user activity trends, optimizing server resource allocation, and maintaining account security.
Subscription Information: If you subscribe to a paid Pro plan, we process limited subscription-related information required to provide and manage your subscription. This may include your subscription status, plan type, renewal date, and payment provider customer or subscription identifiers. We do not store or process your full payment card details.
2. Message History, Temporary Data Handling, and Local Storage
This section outlines the core data handling model of HZ Chat. Different types of data follow different lifecycle management processes based on room type, user settings, and service requirements.
2.1 Conversation Content (Text Messages)
Text messages in HZ Chat are delivered through real-time communication channels. Depending on the room type and user settings, message history may be stored locally or temporarily synchronized between active participants.
Lifecycle: HZ Chat does not maintain a permanent server-side message database. Temporary rooms do not provide message history, while Fixed Rooms may enable message history through local storage and synchronization between active participants. Server memory may temporarily maintain active room status, client connections, and synchronization data required for message delivery and history synchronization. Such data is not maintained as a permanent archive.
Data Purge: Temporary room message data is automatically cleared when the session lifecycle ends. Fixed Room message data follows its configured history settings and account lifecycle management.
2.2 Message History and Synchronization
HZ Chat uses a privacy-focused synchronization model instead of a traditional permanent message database.
For Fixed Rooms with message history enabled, messages may be stored locally in the user’s browser through IndexedDB and synchronized when needed through active room participants.The server may temporarily cache synchronized message data in memory to improve synchronization efficiency, but this data is not maintained as a permanent archive and is cleared when the temporary synchronization state expires or the room is removed.
Temporary Rooms do not provide message history and are designed for short-term conversations only.
2.3 Authentication, Local Storage, and Cookies
We strive to minimize reliance on traditional Cookies by utilizing privacy-centric technical alternatives for our core services:
Local Storage (JWT & Guest ID): We primarily utilize JWT, browser storage technologies, and IndexedDB for local data management. Your authentication token, guest identifier, UI preferences, and locally stored message history (when enabled) remain stored locally in your browser and are not uploaded as a permanent server-side archive.
Strictly Necessary Cookies: While our core business logic does not utilize tracking Cookies, certain Strictly Necessary Cookies may be deployed for the following purposes:
Security & Defense: To prevent malicious attacks, ensure server stability, and implement rate limiting.
Payment and Subscriptions: HZ Chat offers optional paid Pro subscriptions. Payments are processed securely through third-party payment providers. HZ Chat does not collect or store your full payment card information. Subscription-related identifiers and status information may be processed to manage access to Pro features, billing status, and subscription lifecycle events.
User Control: You may clear all local storage and Cookie data at any time through your browser settings. Please note that clearing these data will require you to re-authenticate upon your next visit.
2.4 IP Address
- Internal Usage: Your IP address is briefly retained in server memory (typically for less than 5 minutes) exclusively for Rate Limiting or other anti-abuse security checks. It is strictly prohibited from being logged into any file or database.
2.5 File Uploads and Attachments (Images, Audio, Video, Documents, etc.)
When you upload multi-format files (such as images, videos, PDFs, etc.) as attachments, they undergo controlled temporary storage.
Isolated Storage: Files are stored in an encrypted object storage space associated with a specific Chat session, and the transmission is secured via TLS/SSL protocols.
Access Control: Access to file links is restricted to active participants within the current Chat session. Once a user leaves the room or the session expires, the temporary access authorization invalidates immediately.
Mandatory Purge: All uploaded files are automatically and permanently deleted within 24 hours after a successful upload. This process is irreversible; once deleted, files cannot be recovered by anyone.
3. Limitation of Liability and Third-Party Services
3.1 No-Tracking Commitment
We commit that HZ Chat neither integrates nor plans to integrate any third-party advertising services. We do not use any behavioral tracking SDKs or marketing analytics tools (such as Google Analytics or Facebook Pixel) to monitor, profile, or track your usage behavior.
3.2 Payment Processing and Subscription Services
HZ Chat uses third-party payment providers to securely process Pro subscription payments. Payment providers handle payment card information and payment transactions directly according to their own privacy policies and security standards.
HZ Chat only receives limited information necessary to manage your subscription, such as subscription identifiers, customer identifiers, subscription status, plan information, and renewal dates.
We do not store your complete payment card number, CVV, or other sensitive payment credentials.
Subscription events, such as successful payments, cancellations, refunds, or subscription changes, may be processed to update your account access and ensure that Pro features are correctly provided or removed.
3.3 Service Availability and Monetization
HZ Chat provides both free and paid subscription plans. Optional Pro subscriptions are available for users who need higher usage limits, Fixed Rooms, and enhanced account features.
Paid subscriptions are processed through third-party payment providers. Subscription availability, pricing, and included features may change over time. Any changes affecting existing subscribers will be communicated through appropriate channels.
3.4 Data Security and User Rights (GDPR/CCPA)
All data transmission is secured via TLS/SSL (HTTPS/WSS) protocols.
Chat Data Rights: Our service is designed without a permanent server-side message archive. Message availability depends on room type, local storage settings, and temporary synchronization between active participants. Temporary room messages and server-side synchronization data are not maintained as permanent archives and may no longer exist when an access or portability request is made. Therefore, access or export requests for such data are generally not applicable because HZ Chat does not maintain a permanent server-side archive of message content.
Account Data Rights: HZ Chat respects and protects your GDPR/CCPA rights regarding your account information. You have the right to request access, portability, or rectification of your personal account data (such as your username, associated recovery email, and subscription-related account information) in a structured format. You may also exercise your “Right to be Forgotten” by requesting the permanent deletion of your account credentials from our database via email. Upon verification, we will fulfill such requests within the legally mandated 30-day window.
Infrastructure: While the file storage and processing logic are controlled and managed by the HZ Chat, the Service relies on industry-standard secure infrastructure provided by enterprise-grade partners to host these encrypted temporary assets.
4. Policy Revisions and Contact
4.1 Policy Updates
We may revise this Privacy Policy periodically to reflect changes in our technology or legal requirements. Any updates will be posted directly on this page with an updated “Last Updated” date. Continued use of HZ Chat after such changes constitutes your acknowledgment and acceptance of the revised policy.
4.2 Contact Us
If you have any questions or wish to exercise your data rights, please contact the HZ Chat via our dedicated privacy email:
We strive to address all inquiries promptly. For formal data rights requests, we typically provide an initial response within 7 business days, and ensure all matters are fully resolved within the legally mandated 30-day window.
