SigmaChat Privacy Policy
Effective August 9, 2026
SigmaChat is a chat app at sigmachat.org where people talk in boards, group DMs, and direct messages. This policy covers the app, the website and blog, and the public report form, and it explains what information we collect, what happens to it, and the controls you have. SigmaChat is operated in the United States
We do not run ads, and we do not sell personal information or share it for targeted advertising.
What we collect
Account
An email address and password, or your Google account if you sign in with Google. Google sign-in gives us the name, email address, and profile photo on your Google account. You can add an authenticator app for two-factor sign-in; the secret for it is stored with your account. We do not ask for your phone number or birth date.
Profile
A display name, and optionally an avatar, banner, bio, pronouns, a status line, and an accent color. You can use a different name and look in each board. Your profile is visible to people in the boards and conversations you share.
Content you create
Messages and everything in them: text, images, video, audio, files, polls, GIFs, links, reactions, and pins, along with edit and deletion times. Poll votes, which other participants can see unless the poll is anonymous. Boards you create and their names, icons, roles, invites, and settings. Message drafts stay in your browser and are not sent to us until you hit send.
Connections and blocks
Friend connections, connection requests, and your block list.
Reports
When you report a message or a user, we keep the report, any notes, and a snapshot of the reported content, including content the author deletes afterward. The public form at /report accepts reports from people without accounts; it asks for an email address so we can send a reference code and the outcome, and whether you are reporting for yourself or for someone else. Reports sent to our report email address are kept the same way.
Settings
Notification preferences, appearance choices, and your analytics opt-out.
Collected automatically
Request data
Our servers receive your IP address, browser type, and basic device information with every request. This appears in hosting logs, sign-in records, rate-limit counters, and error reports.
Usage events
The app records a fixed list of named product events, such as "board created," "search performed," or "push enabled." An event carries the action, the page path, a random device identifier, and basic device details like browser, operating system, and screen size. No event has a field that can hold message text, a name, or an email address. Events reach our analytics provider through our own domain; that request strips your cookies and does not include your IP address. There is no click autocapture and no session recording. You can turn usage events off in Settings, under Data.
Error reports
When something breaks, a report with the stack trace, the page, and device details goes to Sentry, our error-monitoring provider. Reports from your browser go to Sentry directly, so Sentry receives your IP address in transit.
Messages, visibility, and automated screening
Messages are stored on our servers, encrypted in transit and at rest. They are not end-to-end encrypted.
Where you send a message decides who can read it. A board message is visible to the board's members, and membership is controlled by that board's admins through invites. A DM or group DM is visible only to its participants.
Automated screening works differently in the two:
- Every uploaded file, everywhere including DMs, is fingerprinted (a SHA-256 hash of the bytes) and checked against a list of known violating material, such as intimate images reported under the federal Take It Down Act. The fingerprint is recorded with the upload; the file itself is not sent anywhere for this check. A match removes the message.
- In boards, uploaded images and video thumbnails are screened through OpenAI's moderation API, and board admins can turn on the same screening for text. Screening sends that content to OpenAI, which returns category scores. Under OpenAI's API data policies, content sent this way is not used to train its models and is retained for up to 30 days for abuse monitoring.
- DMs and group DMs are never sent to OpenAI or any other AI service. The database schema enforces this restriction.
Content that gets flagged or reported goes to a moderation queue that our staff review, together with the context needed to act on it. Beyond that queue, staff cannot browse private boards or conversations. There is one exception: the platform owner can open a 15-minute review window into a single regular board by recording a written reason, and every use is logged. DMs and group DMs are not eligible for this.
A few features involve outside servers:
- Link previews. When a message contains a link, our server fetches the page to build the preview and caches the result for up to 7 days. The linked site sees our server's address, not yours.
- GIFs. GIF search runs through our server, and Klipy receives your search text with a pseudonymous identifier derived from your account ID rather than the ID itself. The GIF images load in your browser from Klipy's CDN, which sees your IP address the way any image host does.
- Embedded players. When a message embeds a YouTube or Spotify player, your browser loads it from their servers, and their privacy policies apply to that request. YouTube embeds use its reduced-tracking domain.
- Board apps and webhooks. Admins can install third-party apps and webhooks into boards they manage. Events from that board, including message text, are then delivered to that developer's server, and the developer's own privacy practices apply to what they receive.
How we use information
We use the information above to run the service: delivering messages, syncing your boards, sending the emails the product needs (sign-in, export links, report outcomes, enforcement notices), and answering support requests. We use it for safety: enforcing our terms and guidelines, reviewing reports, running the screening described above, rate limiting, and bot detection on message sending and the public report form. We use usage events and error reports to fix bugs and understand which features get used. We use it to meet legal obligations, including handling intimate-image reports within the 48-hour window federal law requires.
For people in the EEA or UK: our legal bases are performance of our contract with you (running the service), legitimate interests (safety, security, and analytics), consent where we ask for it (push notifications), and legal obligation (report handling and lawful requests).
Who else receives information
We use a small set of companies to run SigmaChat, each limited to the job listed:
- Supabase hosts our database, sign-in system, and file storage, on AWS in Ohio
- Vercel hosts the app and keeps standard request logs. Its BotID service processes browser signals on message sending and the public report form to detect automated abuse.
- PostHog receives the usage events described above.
- Sentry receives error reports.
- Upstash stores short-lived rate-limit counters, which never contain message content.
- Resend sends our email and receives email addressed to our report inbox.
- OpenAI classifies board content submitted for moderation, as described above.
- Klipy provides GIF search and hosts the GIF files.
- Adobe Fonts serves a display font; Adobe receives standard request data and counts page views.
- Google handles sign-in if you use it. If you enable notifications, your browser vendor's push service (Google, Mozilla, or Apple) delivers them; the notification payload is encrypted to your device and contains the board name and a who-did-what line, never message text.
Beyond these, we disclose information when the law requires it, when it is necessary to prevent death or serious harm, to enforce our terms, or as part of a merger, acquisition, or sale of the service. If that last one ever happens, this policy continues to apply to the transferred data until a new one takes effect.
Cookies and data on your device
Cookies keep you signed in. A random identifier for usage events is stored in your browser, and clearing site data resets it. Recent messages and drafts are cached in your browser's storage so they are on your device as well as our servers. There are no advertising cookies.
How long things are kept
- Messages and files stay until you delete them or delete your account.
- A deleted message disappears from the app immediately. A sealed copy is kept for 30 days so that content deleted right before being reported can still be reviewed, and then it is purged. After that, the content is unrecoverable.
- Reports, enforcement records, and audit logs are retained after the accounts involved are gone, with the account references removed.
- File fingerprints are retained for matching against the block list.
- Export download links work for 7 days.
- Rate-limit counters expire with their window, between minutes and a day.
- Hosting logs and error reports are kept by those providers for their standard periods; Sentry keeps error events for about 90 days.
Your controls and rights
- Export your data. Settings, under Data. You get a zip with your profile, boards, messages, connections, blocks, and up to 80 MB of your media, by a download link emailed to you. Requests are limited to two per day.
- Delete your account. Also in Settings, under Data. Your profile, memberships, connections, reactions, votes, invites, push subscriptions, and notifications are deleted, and your messages are removed as described above. Reports, bans, and audit records survive with the reference to your account removed.
- Edit and delete messages you sent, in any space you still have access to.
- Turn off usage events, choose which notifications you get, block people, and leave boards, all in the app.
If you want access, correction, deletion, or a copy of your data and cannot use the in-app tools, email privacy@sigmachat.org and we will handle it, after verifying the request is really from you. We do not treat anyone differently for exercising these rights. If you are in the EEA or UK, you can also object to or ask us to restrict certain processing, withdraw consent, and complain to your local data protection authority.
Children
SigmaChat is for people 13 and older, or older where local law sets a higher age. We do not knowingly collect personal information from children under 13, and we delete accounts and their data when we learn one belongs to a child under 13. Parents and guardians can reach us at privacy@sigmachat.org.
Security
Traffic is encrypted with TLS, stored data is encrypted at rest, and database access is restricted by row-level security so accounts can only read what their memberships allow. Passwords are stored hashed, never in plain text, and you can add two-factor sign-in. No online service can promise perfect security, and we will notify affected people and regulators of a breach as the law requires.
Where the data lives
Our servers and providers are in the United States. If you use SigmaChat from somewhere else, your information is transferred to and processed in the United States, where privacy law differs from your country's.
California
The categories we collect, why, and who receives them are listed above. We do not sell personal information or share it for cross-context behavioral advertising, and we have not in the preceding 12 months. The site does not respond to Do Not Track or Global Privacy Control browser signals; there is no cross-site tracking or ad targeting for those signals to affect.
Changes
The date at the top is the current version. If a change is significant, we will say so in the app or by email before it takes effect.