Legal
Privacy Policy
Last updated September 2026
The short version. Random chat and rooms are never stored — those messages are relayed between browsers and gone when the chat ends. Chatting needs an account, and the account holds a username, an email address, your gender and your birthdate, plus a record of each sign-in, including your IP address. A photo or file shared in a chat is held only until it has been viewed as many times as the sender allowed, or 24 hours at most. The single exception to "nothing you said" is messages to a friend, which are kept so they can be read later, and deleted when either of you removes the other.
What we do not collect
- No password, no phone number, no ID. Chatting needs an account, but it is only a username, an email address, your gender and your birthdate. You sign in with a code we email you, and nothing here can be used to log in anywhere else.
- No message history. Messages pass through our server in memory and are never stored.
- No video recording. Video connects directly between browsers wherever the network allows, and is never recorded by us.
- No analytics and no ad network. No analytics or session-recording scripts anywhere on the site, and we never sell or share personal data.
- No cookies on any page but the chat screen, and none there until you sign in — see the cookie policy.
Your account
An account is required to chat. It is what keeps the site 18+, lets the people you are matched with know your age and gender, and keeps a nickname yours between devices. It is free, and it holds:
- Your username and the display name you chose to be shown as.
- Whether you are a man or a woman. Shown to the people you are matched with.
- Your birthdate. It enforces the 18+ rule; only your age is shown to matches, never the date itself.
- Your email address. It is how you sign in — there is no password, only a six-digit code we email you — so an account needs one. Used for that and to reach you about your own account, and for nothing else: never sold, never shared, never used for marketing.
- Sign-in codes, only while they are live. Stored as a hash rather than the code itself, and deleted the moment one is used or ten minutes pass.
- When the account was created and when it was last signed in to.
- Accounts made before sign-in codes existed may still hold a scrypt hash of a password. It is deleted the first time that account signs in with a code.
What each sign-in records
Signing in creates one session per device, and each is recorded separately so you can see them and end them one at a time. For every session we store:
- Your IP address and, where our network provider supplies it, the country and city it resolves to.
- Your browser's user agent, and a plain-language summary of it such as "Safari on iOS".
- The language you were using, when the session opened, and when it was last active.
This is more than we store for anyone else. An IP address is personal data, and it is kept only for accounts, only per session, and only to secure them — so you can spot a sign-in you do not recognise, and so we can act on abuse. It is never used to profile you, target you or measure you, and there is still no analytics anywhere on this site.
Sessions expire automatically after 30 days of inactivity and the record is deleted with them. You can see every session on your account and end them yourself, and signing out deletes that session's record immediately.
Administrators of the site can see accounts and their sessions, including these fields. That access exists to handle abuse and support requests, nothing else.
Friends, and messages to them
This is the one place we store what people said to each other.Random chat and rooms are unchanged and always will be — those messages are relayed between browsers and never written down. Messages to a friend are different, because a message to somebody who is offline that vanishes before they read it is not a message.
A friendship exists only when both people agreed to it. Sending a request stores that you asked; nothing else happens until it is accepted, and declining is silent — the sender is never told, so a refusal cannot be used to provoke a second approach. Both people need an account, because a friendship has to survive a closed tab.
- Who is friends with whom, and who asked first.
- The messages between you, with the time each was sent.
Removing a friend deletes the conversation with them. Not hidden, not archived — the messages are erased for both of you, because keeping a thread neither person can reach would mean we hold a conversation for our benefit rather than yours. Deleting your account erases every friendship and every message in it.
Photos and files you share in a chat
A shared file is stored, briefly, because it has to be. Messages pass between browsers; a photo has to sit somewhere until the other person opens it. That is the whole extent of it.
- Only the two of you can fetch it. The file is tied to the conversation it was sent in; nobody else — no URL to share, nothing to guess.
- You choose how many times it can be opened — once, twice, or unlimited. A once-or-twice file is deleted from our server the moment its last view is served, and the sender is told it was opened.
- Everything expires within 24 hours whether or not it was opened. Nothing is kept beyond that, and nothing is kept after the conversation for any purpose of ours.
- We do not look at, scan or index what is shared. The record beside the file is its size, type, view budget and the two connection ids — no account, no IP.
- The other person can still screenshot it. No website can prevent that, and we would rather say so than pretend.
What we stored if you asked to be remembered (retired)
This checkbox was removed in September 2026. Chatting needs an account now, and the account is what remembers you. No new records of this kind are created; the ones that exist expire on their own, and you can have yours deleted by writing to us. What follows describes what that record held.
The chat screen used to offer to remember you between visits. It was off until you pressed the button, and if you never did, this whole section is empty for you. If you accepted, one record was created holding:
- A random identifier we generated — not derived from your device, network or anything about you.
- The nickname you chose, which is what reserves it so nobody else can use it.
- The age, gender and "meet" preference you typed — the same values you were already sending for matching.
- Your language, and two timestamps: first seen and last seen.
That was the entire record. No messages, no conversation history, no video, no IP address, and nothing inferred about you. It existed so your nickname stayed yours and so switching language did not make you a stranger again.
Still have one? Forget me, which deleted the record and expired the cookie in one action, went with the checkbox. A record left over from before expires on its own, or write to us and we will delete it — you do not have to explain.
What is unavoidably processed
- Your IP address, in the ordinary course of serving a web request and maintaining a WebSocket connection. It sits in short-lived server logs used for abuse prevention and debugging, and is not linked to any profile.
- A temporary connection ID and display name, held in memory for the life of your connection and discarded when you disconnect.
- Standard request metadata — browser user agent, timestamps — in the same short-lived logs.
Cookies and analytics
We run no analytics, and set no cookies except the one that keeps you signed in. Microsoft Clarity, which used to show us heatmaps and session replays of the marketing pages after an opt-in, was removed in September 2026 and nothing replaced it — so there is no cookie banner left to answer either.
Nothing measures you, on any page. There is no session recording anywhere on the site, least of all on /app: replay there would capture the messages on screen, and handing your conversations to a third party would contradict everything else on this page.
The nickname and matching preferences you typed are also kept on your own device in local storage, so you do not retype them. Full detail — including the session cookie, the retired identity cookie and the cookies Clarity left behind — is in thecookie policy.
Third parties
Video calls use public STUN servers to help two browsers find each other across the internet. These see connection metadata such as IP addresses in order to work, but no message or video content passes through them.
Children
meetorchat is for people aged 18 and over. We do not knowingly process data from anyone younger, and we block access where we become aware of it.
Your rights
If you have no account, we hold nothing about you and there is nothing to export or delete. If you asked to be remembered before September 2026 and that record has not yet expired, write to us and we will delete it. If you have an account, signing out ends a session and deletes its record, and you can end every other session from your account. To delete an account entirely, or for access, correction, portability or any objection, write to[email protected] and we will respond.
Changes
If we ever start storing more than we do today, this page changes before that happens, and the date at the top will tell you.