iChat Privacy Policy

Effective Date: September 6, 2026

Genframe LLC (“we”, “us”, or “our”) deeply understands the importance of personal information to you. We will take appropriate security measures as required by applicable laws to keep your personal information secure and under your control. This policy applies to all products and services provided through the iChat mobile application and related websites (ichat365.app, collectively the “Product”), and such services are collectively referred to as the “Services”.

Please read this policy carefully and fully understand it, especially the content in bold, before using the Product. By checking your consent to this policy or starting to use the Product, you signify that you have read and agreed to this policy in its entirety. This policy, together with the iChat Terms of Service, forms the complete agreement between you and us.

Summary (for convenience only; the full text prevails):

1. How We Collect and Use Your Information

1.1 Information You Provide to Us

  1. Account information: the email address you provide when registering or logging in; if you sign in with Apple or Google, we receive the verified user identifier (ID) from that platform. We do not collect your name, avatar, or other profile data from those platforms unless you separately authorize it.

  2. Profile information: the nickname, age, and gender you provide when completing your profile, and the avatar you upload. We recommend that you do not use your real name or other identifying information in your nickname.

  3. Content generated in your use of the Service:

  4. Payment-related information: order and receipt information generated when you purchase memberships or credits (e.g., transaction IDs, products, timestamps, platform). We do not collect or store your full payment instrument details such as bank card numbers; payments are processed by the App Store / Google Play and their payment providers.

1.2 Information Collected Automatically When You Use the Service

  1. Device and login information: device identifiers, device model, operating system version, app version, and the source IP address of your login (used for account security and single-device login enforcement).
  2. Push tokens: to deliver offline message notifications, we collect your device’s push token (APNs / FCM token).
  3. Usage data: analytics such as page views, feature usage, and purchase-funnel events. Our analytics events contain only user identifiers, event types, and aggregate values such as counts and durations — never message content, prompts, email addresses, nicknames, or IP addresses.

1.3 Permissions

To provide the following features, we request device permissions when you use the corresponding features; you may revoke them at any time in your device’s system settings:

Permission Purpose
Camera Taking photos for your avatar and chats
Microphone Voice messages and voice calls
Photo library (read/write) Selecting images to upload; saving generated content
Notifications Push message notifications

We do not request location, contacts, Bluetooth, or other permissions.

1.4 How We Use Your Information

  1. To provide core services such as AI character conversations, long-term memory, content generation, and the community;
  2. To create and verify your account, send verification-code emails, and secure your account;
  3. To process the purchase, granting, refund, and revocation of memberships and credits;
  4. To send service notifications and necessary operational messages;
  5. To improve the Product (analytics) and perform necessary risk control and security protection;
  6. To comply with obligations under applicable laws (including lawful requests from regulators and judicial authorities).

For any purpose beyond those listed above, we will seek your separate consent.

In accordance with applicable law, we may process your personal information without your consent in the following circumstances: where necessary for the performance of a contract to which you are a party; where necessary to comply with legal obligations; where necessary in response to a public health emergency or to protect vital interests; where within a reasonable scope we process information you have made public or that has been lawfully made public; and other circumstances provided by law.

2. How We Share and Entrust the Processing of Your Information

We do not sell your personal information. Solely for the purpose of providing the Service, we share the information necessary for each function with the following processors/partners, and require them to process the data in accordance with this policy and our contracts:

Provider Purpose Information Shared Processing Location
Tencent Cloud (messaging cloud, international edition) Message transport and offline channels Account identifiers, message content United States (Silicon Valley)
Large-language-model providers (third-party AI providers we integrate, including xAI (Grok), OpenRouter, DeepSeek, Google (Gemini), OpenAI (GPT Image), Seedream, Seedance, MiniMax, and others; see the app for the current configuration) Generating conversational replies, images, and video Conversation context, retrieved memories, character settings, links to images you send As deployed by each provider
SiliconFlow Vectorizing memory text (AI memory retrieval) Memory / message text China
Linode (Akamai) Object Storage Storing your uploaded images, voice, and files Avatars, wallpapers, conversation images, voice, character-card files United States
Brevo Sending verification-code emails Email address, verification code European Union
RevenueCat In-app purchase verification User identifiers, transaction receipts United States
Apple / APNs; Google / Firebase Cloud Messaging Login identity verification, push notifications Login credentials, push tokens As applicable
PostHog (self-hosted by us) Product analytics Anonymized aggregate events (no message content) Servers under our control

Beyond the above, we share your personal information only when: (1) we have obtained your explicit consent; (2) necessary to comply with legal obligations or lawful requests from judicial or administrative authorities under statutory procedures; or (3) otherwise provided by law.

In the event of a merger, acquisition, or asset transfer requiring the transfer of your personal information, we will require the successor to remain bound by this policy; otherwise we will require it to obtain your fresh consent.

3. How We Store and Protect Your Information

3.1 Storage Location and Period

  1. Your personal information is primarily stored on servers located in the United States (object storage is located in the United States). Because the processing facilities of us and some of our providers are located in different countries/regions (see Section 2), you understand and agree that your information may be transferred across borders, and we will apply appropriate safeguards required by applicable law.
  2. Retention: we retain your personal information only for as long as necessary to achieve the purposes described in this policy, unless a longer period is required by law. After you delete your account, your data is handled as described in Section 4.

3.2 Security Measures

  1. Data in transit is protected with industry-standard encryption protocols (TLS); private files in object storage are accessible only via time-limited signed URLs;
  2. Sensitive configuration such as AI provider keys is stored encrypted;
  3. Our analytics never contain message content, prompts, email addresses, nicknames, or IP addresses;
  4. We maintain access controls and audit mechanisms to restrict internal access to personal information.

3.3 Security Incident Response

In the unfortunate event of a personal information security incident, we will, as required by law, promptly inform you of the basic facts of the incident, its possible impact, and the remedial measures taken or to be taken, via push notifications, email, or (where individual notification is impracticable) reasonable and effective public announcements.

4. Your Rights

Subject to the data protection laws applicable in your jurisdiction (where applicable), you have the following rights over your personal information:

  1. Access and correction: you can view and correct your profile information (nickname, avatar, age, gender) in the app;
  2. Deletion: you can delete individual content such as conversations, messages, characters you created, and memories;
  3. Account deletion: you can delete your account via “Settings — Delete Account”. A 7-day cooling-off period applies; logging back in during that period withdraws the deletion request. After the cooling-off period, we permanently delete your chat history and long-term memories, content you created, uploaded files, and generation task records, and delete or anonymize your account information. To meet audit and legal obligations, necessary transaction records are retained for the period required by law, but no longer associated with an identifiable account;
  4. Data export: we plan to offer a data export feature; until it launches, you may request an export via our support email;
  5. Withdrawal of consent: you may withdraw authorization by disabling device permissions, ceasing to use the relevant features, or deleting your account. Withdrawal of consent does not affect the validity of processing already carried out based on your consent;
  6. Complaints and suggestions: contact us at support@ichat365.app.

After verifying your identity, we will respond to your request within 15 business days (or a shorter period required by applicable law). For requests that are unreasonably repetitive or require disproportionate technical means, we may decline and explain why.

5. Protection of Minors

  1. The Product is intended solely for users aged 18 or older. You must complete an age confirmation on first use; users under 18 are refused registration and use.
  2. If you are the parent or guardian of a person under 18, please safeguard your devices and account credentials to prevent them from using the Product.
  3. We strictly prohibit the generation of any content that sexualizes or exploits minors, and have implemented content safety measures for this purpose. If you discover any violation, please report it immediately via the in-app reporting feature or our support email.
  4. If we learn that we have collected the personal information of a minor without verifiable parental consent (i.e., an ineligible registration), we will take steps to delete that information promptly.

6. How This Policy Is Updated

We may revise this policy from time to time. Without your explicit consent, we will not reduce your rights under this policy. When this policy is updated, we will notify you of the changes via in-app announcements, pop-ups, or other appropriate means, and give you reasonable time to review the updated version before it takes effect.

7. How to Contact Us

If you have any questions, comments, or suggestions about this policy or about personal information protection, or wish to exercise your rights, please contact us:

We will generally respond within 15 business days. If you are not satisfied with our response, you may also lodge a complaint with the competent data protection authority in your jurisdiction.