Last updated: 13 September 2026
StrongChat is a private messenger. You add people by standing near them — within about 100 yards — or by sending an invite link. This policy describes exactly what we collect, what we store, and what we cannot see. It is written to be accurate rather than reassuring; where something is stored on our servers, we say so plainly.
This is the only feature that sends anything you type to a company other than us, so it deserves saying plainly. When you search for a GIF, your phone asks our server and our server asks Giphy. Giphy sees our server, never your address or your name. We see the word you typed and nothing else — not who you are talking to, not which GIF you picked, not what you sent. We do not log it and we do not keep it. If you never search for a GIF, none of this applies to you.
Three other services see something, and it would be wrong to leave them out. Apple relays notifications to your phone — bytes it cannot read. Apple also verifies Sign in with Apple, if you use it. And our email provider receives the text of any report you file, because a human has to read it. That is the complete list.
Some of what the app holds is never sent to us, and we would rather list it than let you assume. One caveat first, because "never leaves your phone" is the sort of sentence people read literally: these live on your device, not on our server — but your device is backed up. If you use iCloud Backup or an unencrypted computer backup, most of the list below is in it, as it would be for any app. The exception is your notes to yourself, whose key cannot leave the phone that made it, so a restored backup contains them and cannot open them.
Messages, photos, files and voice notes between contacts are end-to-end encrypted on your phone before they reach us. We cannot read them. The server stores ciphertext, and the keys required to open it exist only on the two devices.
A conversation opens with an X3DH key agreement — four Diffie-Hellman exchanges combining both identity keys, an ephemeral generated for that session alone, a signed prekey that rotates weekly, and a one-time prekey destroyed on first use. From there each message is sealed with its own key, derived through a ratchet that moves forward with every message and destroys the material needed to recompute earlier ones.
This means forward secrecy: someone who obtains your device and its current keys cannot read your older messages, because the keys that opened them no longer exist anywhere. It also means someone holding your long-term identity key still cannot reconstruct a past session, because the prekeys that session was built on have been deleted.
The ratchet header is encrypted together with the message rather than travelling in front of it, so we cannot group a conversation's messages by their shape even though we relay them.
When both phones run iOS 26 or later, the key agreement also mixes in ML-KEM-768, a post-quantum algorithm standardised by NIST. Traffic recorded today cannot be decrypted later by an attacker with a quantum computer, so long as either the classical or the post-quantum layer holds. If either phone is older, the conversation is classical-only, and the app tells you which — per conversation, on the encryption screen.
You can verify there is no impostor in the middle. Open a conversation and tap the encryption bar to see twelve words derived from both public keys; if those words match on both phones, no one has substituted a key. In person, the app can also confirm identity with a sound your two phones play to each other, derived from your shared secret.
If you enable notifications, Apple's servers relay a wake-up to your phone. When a message preview is possible, the notification carries the encrypted message, which is decrypted on your own device before it is displayed. Apple relays bytes it cannot read; we do not send readable content to Apple or anyone else. If you set an app lock, previews are suppressed entirely and notifications show nothing but that something arrived.
The app requests location access while in use. Your position is used to calculate distance to other people. Other users are shown a distance and never your coordinates, and that distance is rounded to the nearest ten metres so that it cannot be used to work out where you are standing. If you use "share my location", you are choosing to send your actual position to one specific contact — that is the only case in which another person receives a coordinate from you.
You can block or report any person or piece of content. Reports are reviewed within 24 hours and accounts are removed for violations. Because messages are encrypted, a report includes a copy of the content taken from your device — that is the only way a human can review something we cannot read. The push alert telling us a report exists contains no message content; the email copy that reaches our moderation inbox does, because that is the copy a person reads. Reports are kept for moderation and are not deleted when an account is deleted.
Settings includes "What our server knows", which shows you your own record live from our database, including the raw stored form of your most recent message and a count of any attachments we are currently holding for you. A privacy policy nobody can check is just marketing; this one is falsifiable from inside the app.
It is your account record, not a database dump: it shows what we hold about you and not the ciphertext of every message, which would be thousands of lines of nothing. The list under "What we store" above is the complete inventory; the screen is how you check the parts of it that are specific to you.
Settings includes "Delete account". It removes your account, display name, contacts, blocks, chat threads, held attachments, unused prekeys and presence records from our live database immediately. Three honest caveats: our nightly backups are kept for fourteen days, so that is when the last copy of your data goes; reports are retained for moderation; and the app's own "wipe my messages" option is narrower than deleting the account — it clears the stored messages and held attachments and leaves the account itself, so that screen will still show your account identifier, display name and public key afterwards. Deleting the account removes those too. You can also delete your message history without deleting your account. This cannot be undone. Photos and messages already delivered to another person's phone remain on that phone, as they would with any messenger.
Limits we want to be honest about. We can see that two accounts are contacts and that traffic passes between them, even though we cannot see what it says. Anyone holding your unlocked phone can read your messages — the app lock and its duress code help, but encryption was never the protection against that. Nobody can prevent screenshots; the app tells you when the other person takes one. And if you lose your phone without Sign in with Apple, your messages are gone, because nothing readable exists on our server to restore them from — though a device backup you made yourself may still hold what was on the phone at the time.
StrongChat is not intended for anyone under 17 and we do not knowingly collect information from children. If you believe a child is using the service, contact us and we will remove the account.
We do not sell data and we do not run advertising. We share your information with no one for their own purposes; the three services listed under "Searching for a GIF" each receive the minimum needed to do their job. The service runs on servers we operate at Hetzner in Germany. If you sign in with Apple, Apple provides us with a stable identifier; we do not receive your Apple password.
Questions, complaints and data requests: support@strongchat.app. We respond within 24 hours to reports and within seven days to other requests.