Privacy Policy

Last updated September 24, 2026

1. Who we are

CicadaChat (“CicadaChat”, “we”, “us”) runs the chat service at cicadachat.com (“the app”) and this blog (“the blog”). We are responsible for the personal data described in this policy. You can reach us at support@cicadachat.com.

2. What the app collects

When you open CicadaChat (guest account)

There is no sign-up. Your first visit creates a guest account with a generated name (such as “Cicada 4821”) and avatar style. To recognise your browser the next time, it stores a random device ID. We keep the dates the account was created and last used.

If you create an account

  • Your username, the full name you choose to show, and your email address.
  • Your password, stored only as a salted scrypt hash. We cannot read it.
  • If you sign in with Google, Google tells us your Google account ID, email address and name. We do not get your Google password or anything else from your Google account.
  • A profile photo, if you add one.
  • Whether you have confirmed your email address.

Your location

With your permission, your browser shares your device's location with us, and it updates as you move. See section 3 for exactly what we do with it. If you decline, you can still use the global room.

What you post and do

  • Messages, emoji reactions, and when you sent them.
  • Photos, voice notes and documents you attach, with each file's name, type and size. Photos are re-encoded in your browser before upload, which removes embedded data such as the GPS position your camera may have recorded.
  • Locations you choose to share in a message (see section 3).
  • Private chats, private rooms you create or join, friends and friend requests.
  • A business card, if you create one: the business name, description, address, phone number, email, website and photos.

Technical information

Our servers record your IP address, the address requested and the time of each request. We use this to run the service, limit abuse such as repeated password guesses, and investigate problems. We do not use it to build a profile of you.

3. How the app handles your location

Location is what makes CicadaChat work, so here it is in full:

  • While you are connected, we use your current position to decide which messages reach you and who is “in range”. This live position is held in memory only for as long as you are connected, and is not saved to our database.
  • When you post in a local room (anything but global), we store the exact point you posted from with the message. This point is used only to measure how far that message is from each reader. It is never sent to another user.
  • What other people see is your name, your avatar and an approximate distance, rounded more coarsely in wider rooms (for example “~300 m” or “~5 km”). People in range can also see that you are there.
  • Sharing a location on purpose is different. When you use “share location” in the composer, the exact point you picked is visible to everyone who can read that message. In a public room, that means everyone in range. The app warns you before you send it.
  • Friends can see whether you are online, but never your location or distance.
  • To stop sharing your location, turn off location access for cicadachat.com in your browser or device settings. You will then only have access to the global room.

4. Who can see what in the app

WhatWho can see it
Local room messagesAnyone within the distance you posted to, including guests
Global room messagesAnyone using CicadaChat
Private chatsYou and the other person
Private room messagesThe room's current members, including people who join later
Your name, avatar and usernameAnyone who sees your messages or searches for you to add as a friend
Your email addressOnly you and us
Your business cardAnyone signed in to CicadaChat, including guests who open a private chat with you
Whether you are onlineYour accepted friends only

Links to attached files are unguessable and expire after a few days, but anyone you pass a link to can open it until then. Anything you post can be copied or screenshotted by the people who can see it.

5. The blog

You can read the blog without an account, and it collects much less:

  • Comments. If you comment, we store the name you give, what you wrote and when. Both are shown publicly once a moderator approves the comment. We also store a one-way hash of your IP address (never the address itself). It lets us limit how often one person can post and spot abuse. It is used the same way to record which comments you liked, so you can like each comment once.
  • Reads. When you read an article, we count it, with the time, to show which articles are popular. Nothing about you is stored with that count.
  • Google Analytics, only if you allow it. When you first visit, the blog asks whether it may use Google Analytics. If you say yes, Google Analytics sets cookies and tells us, in aggregate, which pages are read, where readers come from and roughly which country and device they use. If you say no, or don't answer, it is never loaded. You can change your answer at any time from “Cookie settings” at the bottom of every page.
  • Technical information. As with the app, our servers see your IP address when you load a page and may record it in error logs.

6. How we use it

  • To run CicadaChat: deliver messages to the right people, show distances, keep you signed in.
  • To run the blog: show comments, count reads and, if you allow it, understand how the blog is read.
  • To send emails you need: confirming your address, resetting your password, and security notices such as a changed password. We do not send marketing email.
  • To keep the service safe: rate limiting, preventing abuse, moderating comments, and enforcing our Terms of Service.
  • To comply with the law and respond to lawful requests.

If you are in the EU, the UK or a similar jurisdiction, our legal bases are: performing our contract with you, which is providing the service you asked for; your consent for location and for Google Analytics, which you can withdraw at any time; our legitimate interests in keeping the service secure and free of abuse and in showing which articles are popular; and legal obligations.

7. Who we share it with

We do not sell or rent personal data, and we do not share it with advertisers. We share only with:

  • Service providers that run parts of the service for us under contract: our hosting provider, which stores the data; Cloudflare, which our traffic passes through; and Brevo, which delivers our emails and so receives your email address and the message.
  • Google, if you use “Sign in with Google” in the app, and on the blog if you allow Google Analytics. Google's sign-in button is loaded when you open the app's log-in or sign-up dialog. At that point Google receives the usual information a browser sends (such as your IP address) and may set its own cookies. See Google's Privacy Policy.
  • Authorities, when the law requires it, or when it is necessary to protect someone from serious harm.
  • A successor, if CicadaChat is sold or merged. This policy would continue to apply to your data, and we would tell you first.

8. What we store on your device

The app does not set cookies. It uses your browser's local storage to keep your sign-in token, your guest device ID, the room you last used and your light/dark preference. If you turn off “Keep me signed in”, the sign-in token is kept only until you close the tab. Clearing your browser's site data removes all of this. For a guest, that means losing access to that guest account.

The blog sets one cookie of its own, a security token that protects the comment form from forged requests. It keeps your analytics choice and the comments you liked in local storage. Google Analytics cookies (_ga and _ga_…) are set only if you allow them, and choosing “No thanks” later removes them.

9. How long we keep it

  • App accounts, messages, files and the location stored with messages are kept until the account is deleted. You cannot yet delete individual messages yourself. Write to us if you need one removed.
  • Files you attach in the app but never send are deleted after 24 hours.
  • Email confirmation and password reset links stop working once used or expired. Password reset links expire after one hour.
  • Your business card and profile photo are deleted, along with the stored images, as soon as you remove them.
  • Blog comments are kept until they are deleted, and a comment that is not approved may be deleted at any time. Write to us to have your comment removed.
  • Blog read records are deleted after 31 days, leaving only each article's running total.
  • Google Analytics data is kept by Google for up to 14 months.
  • Server logs are kept for a limited time for security and troubleshooting, and then deleted.

When an app account is deleted, its messages, reactions, files, private chats, friendships and memberships are deleted with it. Private rooms it owned are handed to another member, or deleted if nobody is left.

10. Your choices and rights

  • Correct your name, username, email and photo in the app's Your account.
  • Stop sharing location in your browser settings (see section 3).
  • Turn Google Analytics off on the blog with “Cookie settings” at the bottom of any page.
  • Get a copy, or delete your account and data, by writing to support@cicadachat.com. Write from the email address on your account. A guest account has no email, so tell us your guest name and when you used it. For a blog comment, tell us the article, the name you used and roughly when you posted. We may ask for more to confirm the data is yours.

Depending on where you live, you may also have the right to object to or restrict how we use your data, and to take it elsewhere. You can complain to your local data protection authority. We respond to requests within one month.

11. Security

Traffic to the app and the blog is encrypted with HTTPS, and passwords are hashed. Changing your password signs you out on every device. Files are served only through signed, expiring links. No system is perfectly secure, though. Messages, including private ones, are stored on our servers without end-to-end encryption. Please don't use CicadaChat for anything that must stay secret.

12. Children

CicadaChat is for people aged 18 and over, because it connects you with strangers near where you are. We do not knowingly collect data from anyone younger. If you believe a child is using CicadaChat, tell us and we will delete the account.

13. International transfers

Our servers and service providers, including Google and Cloudflare, may be in a country other than yours. Where the law requires it, we protect such transfers with appropriate safeguards, such as the European Commission's standard contractual clauses.

14. Changes to this policy

If we change this policy, the “Last updated” date at the top changes too. If a change materially affects how we use your data, we will tell you in the app, or by email if you have an account, before it takes effect.

15. Contact

Questions, requests or complaints: support@cicadachat.com.

See also our Terms of Service.