Chattr — Privacy Policy
1. Who we are
Chattr is operated by Chattr Ltd, a company registered in England and Wales (company number 17199526). Chattr Ltd is the "controller" of your personal data — this means we are responsible for deciding how and why it is used. Our registered office is at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.
We are registered with the Information Commissioner's Office ("ICO"), the UK's data protection regulator, under registration number ZC149597.
2. The short version
We try to collect as little as possible. Chattr is anonymous to other users, and we want to keep it that way. The essence: - We use your phone number and (where required) your university email only to verify that you are a real, eligible student. They are never shown to other users. - Your posts, comments and votes are shown to others without your name attached. - We use limited technical and analytics data to run the Service safely and keep it working. - We do not sell your personal data. - You can download your data or delete your account from within the app.
The rest of this policy gives the full detail, as the law requires.
3. What personal data we collect
3.1 Information you give us
- Mobile phone number — collected at sign-up and used to send a one-time verification code. - University email address — where verification is required, used to confirm you are an eligible student and to determine your campus. We store whether you are verified and the institution your email belongs to. - Age confirmation — your confirmation that you are 18 or over, and the date you gave it. - Content you create — your posts, comments, poll answers, votes, bookmarks, and any images you upload. - Reports and appeals — information you submit when you report content or appeal a decision. - Messages to us — anything you send to our support or other contact addresses.
3.2 Information we collect automatically
- Usage and activity data — such as your karma score, when you are active, and how you interact with content, used to run features like leaderboards and to keep the Service safe. - Technical and log data — such as IP address, device and browser type, and timestamps, generated through our infrastructure providers and used for security, abuse prevention, and diagnosing faults. - Error and performance data — collected through our monitoring tools to detect and fix problems. - Product analytics and session replay — we use a privacy-focused analytics tool (PostHog), which processes this data in the European Union (EU region), to understand how the Service is used (pages and features used, taps, time spent, and where people get stuck) and to view anonymised session replays to diagnose usability problems. We mask all text input — including anything you type into a post — so it is never recorded, and we run this analytics without storing cookies on your device. We configure these tools to reduce the personal data they capture. - Advertising measurement — only if you accept advertising cookies. Meta's cookies record that you came from one of our adverts, and we record which advert, campaign and campus a signup came from. Nothing here is collected if you refuse.
4. How we use your data, and our lawful basis
Under UK data protection law we must have a "lawful basis" for each use of your personal data.
We check the content you submit — posts, poll options, comments, images and direct messages — using automated systems and human review, to keep illegal and harmful content off the Service. The automated layer runs at the moment you submit: pattern detection against a watchlist of harmful content and personal information, a scoring of the submission and the account that made it (for example, a brand-new account or a sudden burst of posts), and, for images, an automated safety check. Depending on the result, content is refused, published, or held or flagged for a person on our moderation team to review; content that other users report is reviewed by a person too. We rely on our legal obligations under the Online Safety Act 2023 and on our legitimate interests in keeping the Service safe. Chattr is also integrating the Internet Watch Foundation's hash list, and once that membership is active we will use it to detect known child sexual abuse imagery at the point of upload; it is not running yet.
We may also republish content you post on Chattr, in anonymised form — with no name or identifying detail — on Chattr's own marketing and social media channels (for example, Instagram and TikTok), relying on our legitimate interests in promoting the Service.
We use your own activity on the Service — the posts you upvote and bookmark — to rank the content we show you, for example to order the "Popular" and "For you" sections. This uses only actions you take within the app; we do not track what you read or how long you look at it. We rely on our legitimate interests in showing you relevant content.
If — and only if — you accept advertising cookies, we measure whether our adverts lead to signups: that you visited, requested a code, created an account and confirmed a university email. Our lawful basis is your consent, which you can withdraw at any time in Settings → Advertising cookies. Withdrawing stops any further sharing; it does not undo measurement already carried out, and it does not affect anything else about your account. We do not use this to profile you, to decide what you see on Chattr, or to target adverts at you individually.
5. Anonymity and identification
Your posts are shown to other users without your name. Internally, however, your account is linked to your verification details. We keep this link so that we can meet our safety and legal duties — for example, to act on illegal content or to respond to a valid request from the police or a court.
We will only identify an account, or disclose the data behind it, where we are legally required or permitted to do so, or where it is necessary to protect someone's safety. We do not reveal who posted what to other users.
6. Who we share your data with
We do not sell your personal data. We share it only in these situations:
6.1 Service providers (processors)
They act on our instructions and are bound by contracts requiring them to protect your data:
6.2 Legal and safety disclosures
We may disclose data where the law requires or permits it: to the police, courts, regulators such as Ofcom or the ICO, or organisations such as the Internet Watch Foundation or the National Crime Agency, in connection with illegal content or a risk to safety.
6.3 Advertising measurement (only with your consent)
Where you have consented to advertising cookies, we share a record of your signup steps with Meta Platforms Ireland Limited so we can measure our advertising. Your email address and phone number are sent only as an irreversible cryptographic code (a SHA-256 hash), never as the address or number itself; we also send identifiers Meta's own cookies set, your IP address and your browser type. Your posts, comments, votes and reading are never shared. For this measurement Chattr and Meta are joint controllers, which means you can exercise your data rights with either of us and we each remain responsible to you. This is the only situation in which we share your data for advertising, and it does not happen at all unless you accept. See the Cookie Policy for the detail.
6.4 Business transfers
If Chattr is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that, subject to the same protections in this policy.
7. Where your data is stored and processed
We aim to host data in the UK or European Economic Area where practical. Some of our providers are based in, or process data in, countries outside the UK, including the United States. Where data is transferred outside the UK, we rely on safeguards approved under UK data protection law — such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision.
8. How we protect and how long we keep your data
8.1 Security
We take reasonable technical and organisational measures to protect your data: encryption of data in transit (HTTPS/TLS), access controls and row-level security on our database, restricted administrative access, key rotation, and regular security review.
8.2 Retention
- Verification codes are deleted shortly after use (within a short time-to-live window). - Account and content data are kept while your account is active. - When you delete your account, we begin deletion or anonymisation after a 30-day cooling-off period. Some data may be retained for a limited further period where we must keep it for legal, safety, or backup reasons. - Aggregated or anonymised data that no longer identifies you may be kept indefinitely.
9. Your rights
Under UK data protection law you have the right to: - Be informed about how we use your data (this policy); - Access a copy of your data — you can download your data from within the app; - Have inaccurate data corrected; - Have your data erased — you can delete your account from within the app; - Restrict or object to certain processing, including processing based on our legitimate interests; - Data portability — to receive your data in a usable format; and - Withdraw consent, where we rely on consent.
To exercise any of these rights, use the tools in the app where available, or contact privacy@chattr.uk. We will respond within one month, which we may extend by up to two further months for complex requests, telling you if we do. There is normally no charge.
10. Complaints about how we use your data
You have the right to complain to us about how we handle your personal data, and we make this straightforward. You can complain by emailing privacy@chattr.uk, or by any other reasonable means — we accept complaints however they reach us, and you do not need to use any special form or particular wording. Tell us what the problem is and what you would like us to do.
In line with our duties under the Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025), we will acknowledge your complaint within 30 days of receiving it, investigate it, and respond without undue delay in plain language, explaining the outcome.
If you are not satisfied with our response, you can complain to the Information Commissioner's Office ("ICO"), the UK's data protection regulator — though we would welcome the chance to put things right first. You can contact the ICO by post at: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; by telephone on 0303 123 1113; or online at ico.org.uk/make-a-complaint.
11. Cookies and similar technologies
We use the cookies and local storage necessary to run the Service — for example, to keep you logged in and secure — and, only if you consent, advertising cookies that measure whether our adverts lead to signups. Our product analytics runs without cookies at all. We ask before any advertising cookie is set, refusing costs you nothing, and you can change your mind at any time in Settings → Advertising cookies. Our Cookie Policy lists everything we use and explains how to refuse or withdraw consent.
12. Children
Chattr is for adults aged 18 and over and is not intended for children. We do not knowingly collect data from anyone under 18. If we learn that we hold data about someone under 18, we will delete it. If you believe a child is using Chattr, please tell us at privacy@chattr.uk.
13. Direct messages
Direct Messages are available in the app. This is how they work and how we handle them.
13.1 What direct messages are
A direct message is a private, one-to-one conversation started from a post — you message the author of a post, not a named person. Both sides stay pseudonymous: each conversation uses per-conversation handles, and we never show one participant the other's identity, phone number, email address, or account details. The first message you send arrives as a request: the other person sees it and chooses whether to accept or decline, and if they decline, you cannot message them again. Direct messages are available only between verified students at the same university.
13.2 Direct messages are not end-to-end encrypted
We want to be plain about this, because it is a deliberate choice and not an oversight. Direct messages are encrypted in transit and stored securely, but they are not end-to-end encrypted — they are readable on our systems. That is what allows our safety systems and, where necessary, our moderators to act on them. In practice: message content goes through the same automated pattern detection and scoring that posts do, and can be held for human review in the same way; images sent in a message are handled the same way as images posted publicly; and if a message is reported, a moderator can read the conversation it came from in order to review it. Content that appears to involve the sexual abuse or exploitation of a child is treated as the most serious category we handle, escalated immediately, and preserved for the authorities. Private messaging is where the most serious harms usually happen, and encrypting messages so that nobody — including us — could ever act on a report would make it impossible to meet our safety duties under the Online Safety Act 2023. We limit access to message content to what is needed for these purposes, and administrative access to identifying information is logged.
13.3 How long we keep direct messages
We keep your messages and conversations while your account exists. If you delete your account, your messages are not deleted with it: they remain, attached to a stripped-down account record from which your phone number, email address, and other identifying details have been erased — the same approach we take to your posts (see sections 5 and 8.2). We do this for legal and safety reasons. A message is often the only record of harassment or of a threat to someone, deleting it on demand would destroy the evidence of what was said, and it would also remove the message from the other person's side of a conversation they took part in. Where content is subject to a legal hold — for example, material preserved for the police or the National Crime Agency, or under child-safety legislation — we keep it for as long as that hold requires, and a deletion request cannot override it. If a legal hold prevents us from completing your deletion request, we will tell you.
13.4 Reporting, declining, and blocking
You can report any message from within the conversation. Reported messages go to the same moderation queue, with the same report reasons, escalation routes, and right of appeal as public content. You can decline a request without the sender being able to try again, and you can block the other participant from within a conversation, which ends it and stops any further contact. Blocking someone on Chattr also prevents them from starting a conversation with you.
13.5 We do not use your messages for advertising or profiling
We do not use the content of your direct messages for advertising, we do not sell it, and we do not use it to build a profile of you or to target anything at you. Our product analytics record actions, never content — for example, that a message was sent, not what it said. We use message content only to deliver the conversation, to keep people safe, and to meet our legal obligations.
14. Charlie, the campus assistant
Charlie is an in-app assistant you can ask about your university and student life, found at the top of your Messages. This is what happens when you use him.
14.1 What we record
We keep a log of every question you type to Charlie, with the time you asked it, your campus, how the question was handled and whether Charlie declined to answer it. We keep this log while your account exists, to see what students want to know so we can improve the information Charlie holds, and to review refusals and safety signposting. Where Charlie has answered a question for one student, the answer may be stored for a limited time and shown to other students at the same campus who ask the same question. Chattr does not use your questions to train any AI model, and we do not use them for advertising or to profile you. We rely on our legitimate interests in providing and improving the assistant.
14.2 Who generates the answer
To produce an answer, your question — and, for a follow-up, your last few questions in the same thread — is sent, together with the name of your university and any campus information Charlie has retrieved to answer from, to Anthropic, PBC, the provider of the Claude models, which acts as our processor. Your name, phone number, email address and account identifier are never sent, and Charlie holds no memory of you beyond the open thread. Some questions — for example anything about a named person, or anything medical or legal — are declined by a fixed check on our own systems before any of this happens, and are never sent to a model. Every answer Charlie gives passes the same automated content filter a post does.
14.3 Who Charlie answers at the moment
While Charlie is being tested, he may be visible only to Chattr staff accounts, and generated answers are given only to those accounts. Where other accounts can see him, they receive a fixed holding reply rather than a generated answer — and their question is still recorded as described in 14.1, so that we can see what to add before Charlie answers everyone.
14.4 Your rights over the log
Your questions to Charlie are included when you download your data from within the app, and they are deleted when your account is deleted.
15. Changes to this policy
We may update this policy from time to time. If we make significant changes, we will tell you through the app or by other appropriate means. The "last updated" date at the top shows when it last changed.
Last updated: 14 September 2026