Last updated 2026-09-15 · Version 1.1
NoChat Privacy Policy
| Version | 1.1 |
| Effective date | 2026-09-15 |
| Controller | BITRY LTD, a private limited company registered in England and Wales, company number 16107519 |
| Registered office | 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom |
| ICO registration | Bitry LTD will register with the ICO before NoChat is made available to users; the number will be published here |
| EU representative (GDPR Art. 27) | Bitry LTD will appoint one before offering NoChat to users in the EU; until then, contact connect@bitry.io |
| Data controller representative in Turkey (KVKK) | Bitry LTD will appoint one before offering NoChat in Turkey, as required by KVKK |
| VERBIS registration | Bitry LTD will register with VERBIS before offering NoChat in Turkey, as required by KVKK |
| Data protection officer | Not appointed; data protection questions: connect@bitry.io |
| Privacy contact | connect@bitry.io |
| Languages | English, Azerbaijani, Turkish, Russian and Portuguese. If the versions differ, the English version prevails, except where the mandatory law of the country where you live requires the version in your language to prevail. |
What changed in version 1.1
- New data: date of birth, age and zodiac sign, attendance confirmations, reliability score and sanctions, purchase records from RevenueCat, event tickets and reservations, venue billing through Stripe.
- Selfie verification now includes an anti-spoofing check and a match with your profile photos, still on your phone and without storing a selfie or face template (section 5).
- New processors: RevenueCat and Stripe (section 6).
- EU GDPR, the Portuguese e-privacy rules and the Turkish KVKK now apply alongside UK GDPR, with representatives in the EU and Turkey (sections 7, 9, 15).
- Automated decisions for reports and no-show sanctions, and how to ask for human review (section 3.3).
This policy explains what personal data NoChat collects, why, who receives it, where it is stored, how long we keep it, and your rights. It applies to the NoChat mobile app and the people who use it. Venue partners: section 13 covers the business contact data we process about you.
Which laws apply. NoChat is operated by BITRY LTD ("Bitry LTD", "we", "us"), a company established in the United Kingdom. Bitry LTD is the controller of your personal data. We process your data in line with:
- the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, because the controller is established in the UK;
- the EU General Data Protection Regulation (GDPR), because we offer the App to people in the EU (Art. 3(2) GDPR), and, in Portugal, Law No. 58/2019 and Law No. 41/2004 on electronic communications privacy;
- for users in Turkey, the Law on the Protection of Personal Data No. 6698 (KVKK) and its secondary legislation. For users in Turkey this policy, together with section 15.2, is our information notice (aydınlatma metni) under Article 10 KVKK; explicit consents are asked for separately in the App;
- for users in Azerbaijan, the Law "On Personal Data" No. 998-IIIQ;
- in any other country, the data protection law of the country where you live, where it applies.
Where these laws differ, we apply the stricter rule.
1. Summary
- We collect your phone number, first name, date of birth, photos, gender, who you want to meet, interests, approximate location, your Meet/Pass choices, matches, meetings and attendance answers, verification results, reports, device and security data, and purchase and ticket records.
- Your selfie verification runs on your phone. We do not store or receive your selfie or a face template. We store only the result and scores.
- We never show your location or date of birth to other users. Other users see your first name, age, zodiac sign, photos, interests, approximate distance and whether you are Verified.
- A Venue receives only your first name and last-name initial, the booking time and the perk, so it can seat you. At events, door staff also see your main photo at check-in.
- Your data is hosted with Google Cloud / Firebase in the European Union (Belgium, region europe-west1). Some services process data in the UK, the US and Switzerland (section 7).
- We do not sell your personal data and we do not use it for third-party advertising.
- You can delete your account in the App at any time.
2. What we collect
| Category | Data | Source |
|---|---|---|
| Account | Mobile phone number; account ID; sign-up and last sign-in time | You, Firebase Authentication |
| Profile | First name, last name or initial [see note], date of birth, 3 photos, gender, gender(s) you want to meet, interests | You |
| Derived profile data | Age and zodiac sign, calculated from your date of birth | Us |
| Location | Approximate location from your phone; the city assigned to you | Your device (with permission), us |
| Activity | Meet / Pass decisions, Meets and Super Meets used, matches, time slots, meetings, cancellations, the Venue booked | Your use of the App |
| Attendance and reliability | Your answers and the other person's answers to "Did they come?", no-shows, late cancellations, reliability score, warnings, suspensions, bans and appeals | You, other users, our moderators |
| Verification | Pass/fail result; results of the head-movement challenges; anti-spoofing score; face-match score against your profile photos; model versions; a code (hash) identifying which photos were checked; consent version; date and time. No image, video or face template | The App on your device |
| Safety | Blocks, reports you make or that are made about you, notices of illegal content, moderation decisions, statements of reasons and appeals | You, other users, Venues, third parties, our moderators |
| Device and security | App version, device type and OS, app instance identifiers, Firebase App Check attestation tokens (Apple App Attest / DeviceCheck, Google Play Integrity), IP address, crash and error information | Your device, Apple, Google |
| Purchases | Product, time, price, currency, Store country, Store transaction IDs, refund and cancellation events, your Meet balance. We do not receive your card details | Apple App Store / Google Play, through RevenueCat |
| Events and tickets | Event, ticket or reservation status, price and currency, check-in time, refund reason, Stripe payment and refund IDs for tickets paid in the App. We do not receive your card details | You, Stripe, Venues |
| Communications | Messages you send to support, privacy or appeal emails | You |
| Consents | Which documents and consents you accepted (Terms, Privacy Policy, biometric consent, KVKK explicit consents, marketing and İYS status), their version, time and language | The App |
Note on last name: the App stores a last name so the booking can be shown to the Venue with an initial only.
Special category data.
- The gender(s) you want to meet may reveal your sexual orientation, which is special category data under GDPR Article 9 and may be data about sex life under Article 6 KVKK. We use it only to show you matching profiles, never show it to others as a label, and process it on the basis of your explicit consent.
- Face processing during verification is biometric processing (section 5), based on your explicit consent.
- We do not ask for religion, political views, health or ethnic origin. Please do not put them in your profile. Photos can reveal such things; we do not use photos to infer them.
3. Why we use your data and on what legal basis
3.1. Purposes and legal bases
| Purpose | Data used | UK GDPR and EU GDPR (Art. 6, and Art. 9 where marked) | Turkey: KVKK (Art. 5, and Art. 6 where marked) |
|---|---|---|---|
| Create and run your account, log you in | Phone, account ID, device data | Contract (6(1)(b)) | Necessary for the contract (5(2)(c)) |
| Check that you are 18+, show your age and zodiac sign, prevent age changes | Date of birth, age, zodiac sign | Contract (6(1)(b)); legitimate interests in protecting minors and other users (6(1)(f)) | Contract (5(2)(c)); legitimate interest (5(2)(f)) |
| Show you to people nearby and nearby people to you, including ranking with the zodiac boost | Profile, age, zodiac sign, approximate location, interests, activity | Contract (6(1)(b)); consent for location (6(1)(a)) | Contract (5(2)(c)); explicit consent for location |
| Match by gender preference | Gender, interested-in | Contract (6(1)(b)) + explicit consent (9(2)(a)) | Explicit consent (6(2)) |
| Arrange meetings and book a Venue; share first name + initial with the Venue | Matches, time slots, approximate location, first name + initial | Contract (6(1)(b)) | Contract (5(2)(c)) |
| Selfie verification and the Verified badge | Verification results and scores (on-device check) | Explicit consent (6(1)(a) and 9(2)(a)) | Explicit consent (6(2)) |
| Attendance confirmation, reliability score, no-show sanctions and appeals | Attendance answers, meetings, reliability, sanctions | Contract (6(1)(b)); legitimate interests in reliable meetings for users and Venues (6(1)(f)) | Contract (5(2)(c)); legitimate interest (5(2)(f)) |
| Safety, reports, notices of illegal content, moderation, fraud prevention, enforcing our Terms | Profile, activity, reports, blocks, device and App Check data | Legitimate interests in keeping users safe (6(1)(f)); legal obligation (6(1)(c)), including the EU Digital Services Act | Legal obligation (5(2)(ç)); legitimate interest (5(2)(f)) |
| Meet packs and Super Meets | Purchase records, balance | Contract (6(1)(b)) | Contract (5(2)(c)) |
| Event tickets, reservations, check-in and refunds | Ticket data, first name + initial, main photo at check-in | Contract (6(1)(b)) | Contract (5(2)(c)) |
| Tax and accounting records | Purchase, ticket-fee and venue billing records | Legal obligation (6(1)(c)) | Legal obligation (5(2)(ç)) |
| Support, appeals and data-rights requests | Communications | Contract; legal obligation; legitimate interests | Contract; legal obligation (5(2)(ç)) |
| Security, debugging, aggregated statistics to improve the Service | Device and security data, activity | Legitimate interests (6(1)(f)) | Legitimate interest (5(2)(f)) |
| Marketing messages (email, SMS) | Phone, email if given, consent status | Consent (6(1)(a)) | Explicit consent under Law No. 6563, registered in İYS |
| Establishing, exercising or defending legal claims | Relevant records | Legitimate interests (6(1)(f)) | Establishing, exercising or protecting a right (5(2)(e)) |
| Complying with law, court orders and lawful requests of authorities | Any relevant data | Legal obligation (6(1)(c)); vital interests (6(1)(d)) in emergencies | Legal obligation (5(2)(ç)); protection of life (5(2)(b)) |
Azerbaijan. For users in Azerbaijan we rely on consent, the performance of the contract and legal obligations under Law No. 998-IIIQ.
3.2. Legitimate interests and consent
Where we rely on legitimate interests, we have weighed them against your rights. You can ask us for details and you can object (section 9). You can withdraw consent at any time (section 9). Withdrawal does not affect processing before it. If you withdraw consent that a feature needs (for example location or gender preference), that feature stops working.
3.3. Automated decisions and profiling
- Ranking (Terms, section 6), including the zodiac boost, orders profiles. It does not decide whether you can use the Service.
- Verification decides only whether you get the Verified badge. You can retry, and you can ask a person to review a failure.
- Reports: a report that a user is under 18, or several reports in a short time, automatically hide the account until a moderator reviews it.
- No-shows: warnings and 7-day suspensions are applied automatically from attendance answers. 30-day suspensions and bans are confirmed by a person.
For these decisions you have the right to get human review, express your point of view and contest the decision by writing to connect@bitry.io (GDPR Art. 22; KVKK Art. 11(1)(g)).
4. Who can see what
- Other users see your first name, age, zodiac sign, photos, interests, approximate distance (rounded) and the Verified badge. Matched users also see the meeting time and, 30 minutes before, the Venue. Other users never see your phone number, date of birth, exact location, reliability score, sanctions or verification scores.
- Venues see your first name + last-name initial, booking date and time, party size and the perk. For events, door staff see your first name + initial and your main photo when they check you in, through a link that expires after a few minutes. Venues may use this only to seat you or check your ticket (Venue Partner Agreement).
- Our staff and moderators see only what they need to handle reports, appeals, support and safety. They never see a selfie, because none is stored.
5. Selfie verification (face check)
5.1. How it works. The check runs entirely on your phone:
- The App asks you to do random head movements (for example turn your head left or right). Face detection software on the device (Google ML Kit) checks that a live person did them.
- An anti-spoofing model (MiniFASNet) checks that the camera sees a real face and not a printed photo or a screen.
- A face-matching model (SFace) turns the live face and each of your profile photos into numbers in the phone's memory and compares them, to check that the photos show you.
5.2. What we store. We store only: pass/fail, the challenge results, the anti-spoofing and face-match scores, the method and model versions, a hash code identifying the photos checked, whether the App's security check (App Check) was present, your consent version, and the date and time.
5.3. What we do not store. No selfie photo, video, camera frame or face template (biometric template) is saved to your device storage, sent to our servers, or shared with anyone. The numbers used for the comparison exist only in the phone's memory during the check and are discarded.
5.4. Google ML Kit may send Google limited diagnostic information (such as device model, app ID and performance metrics). It does not include images.
5.5. Biometric data and consent. Processing your face to confirm that you are the person in your photos is biometric data processing under GDPR Article 9 and KVKK Article 6. In Azerbaijan, the law lists face images as biometric data, so your profile photos may count as biometric data too. We ask for your separate explicit consent before the camera opens. You can refuse and ask for manual verification instead. You can withdraw consent at any time: we then delete your verification result, the badge is removed and meetings cannot be scheduled until you are verified again.
5.6. The badge is removed when you change your profile photos. The badge is not an identity, background or safety guarantee (Terms of Service, section 5.3).
6. Processors and recipients
We use these service providers. Processors act on our instructions under written contracts, including data processing terms:
| Provider | What for | Data | Location |
|---|---|---|---|
| Google Cloud / Firebase (Google Ireland Ltd / Google LLC) | Database (Firestore), server functions, photo storage, authentication, SMS one-time codes (Firebase Authentication), App Check | All App data above | Firestore and Cloud Functions: EU, Belgium (europe-west1). Authentication and SMS delivery: Google global infrastructure, including the US. |
| Google Cloud Vertex AI (Gemini) | Only to read a Venue's uploaded menu PDF into a list of menu items. No user data is sent | Venue menu content | |
| Google ML Kit | On-device face detection for verification | Diagnostics only, no images | On device; diagnostics to Google |
| RevenueCat, Inc. (US) | Confirming in-app purchases and keeping your Meet balance in sync | Account ID (a random ID), Store transaction data, product, price, currency, Store country, device and app version, IP address | US |
| Apple (App Store, App Attest) and Google (Google Play Billing, Play Integrity) | App distribution, payments for paid items, device integrity. The Stores are independent controllers for the payments they process | Purchase records, device attestation | Global, including the US |
| Stripe (Stripe Payments UK Ltd / Stripe Payments Europe Ltd) | Venue subscription billing (processor for us). For event tickets paid in the App, Stripe and the Venue are independent controllers of the payment; we receive payment status and IDs | Venue billing contacts; ticket payment status, amounts, IDs | UK, EU, US |
| MapTiler AG (Switzerland), with OpenStreetMap data | Map tiles on the meeting screen | Your IP address and the map area requested when a map is shown | Switzerland / global CDN |
| SMS and telecom carriers used by Firebase Authentication | Delivering one-time codes | Phone number, code | Global |
| Venues (independent businesses, not our processors) | Seating your booking; selling and checking event tickets | First name + initial, booking details; for events, main photo at check-in | Country of the Venue |
| Our representatives in the EU and Turkey | Acting as contact point for you and authorities | Requests you send them | EU; Turkey |
We may also disclose data to: law enforcement or authorities when required by law or to protect someone's life or safety; professional advisers (lawyers, accountants) under confidentiality; and a successor if our business is sold or reorganised, who will be bound by this policy.
7. International transfers
7.1. Where your data goes. Using NoChat means your data is transferred from the country where you live to the controller in the United Kingdom and to our hosting in the European Union (Belgium). Some services also process data in the United States (Google, Apple, RevenueCat, Stripe) and Switzerland (MapTiler).
7.2. From the EU to the UK we rely on the European Commission's adequacy decision for the UK. From the UK to the EU and Switzerland we rely on UK adequacy regulations.
7.3. To the United States we rely on the EU-US Data Privacy Framework and its UK Extension where the provider is certified, or on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum in the provider's data processing terms.
7.4. From Turkey. Transfers of data of users in Turkey abroad are made under Article 9 KVKK, using the standard contracts approved by the Personal Data Protection Board, which are notified to the Personal Data Protection Authority within 5 business days of signature.
7.5. From Azerbaijan. Law No. 998-IIIQ allows transfers abroad to countries with adequate protection and otherwise generally requires your consent, which you give in the App before your data is transferred.
7.6. You can ask us for a copy of the safeguards we use (section 16).
8. How long we keep data
| Data | Retention |
|---|---|
| Account and profile, date of birth, photos, interests | While your account exists. Deleted when you delete your account |
| Location | Replaced on each update; deleted with your account; [target] deleted after 30 days of inactivity |
| Decisions, matches, time slots, bookings | While your account exists; [target] match and booking details deleted 90 days after the meeting date |
| Attendance answers | Used for sanctions over a rolling 90 days; kept up to 12 months for appeals, then deleted |
| Reliability score and sanctions | While your account exists; ban records as in the safety record row |
| Verification results | Until you verify again, withdraw consent or delete your account. Verification sessions: up to 24 hours |
| Purchase, ticket and billing records | As long as tax and accounting law requires: in the UK, generally 6 years after the end of the financial year |
| Safety record after a ban (hashed phone number, ban reason, report references) | Up to 3 years after the ban, to prevent banned users from re-registering and to support police investigations |
| Reports, notices, moderation logs and statements of reasons | Up to 3 years |
| Backups | Overwritten within 35 days |
| Consent and terms-acceptance records | While the account exists and up to 6 years after, as evidence in case of legal claims |
When you delete your account, we delete your profile, photos, location, decisions, matches, verification results and your bookings at Venues. The other person's pending meeting with you is cancelled. Data we must keep by law, and the limited safety record above, is kept only for the stated period, with restricted access. In Turkey, data is deleted, destroyed or anonymised under our personal data retention and destruction policy.
9. Your rights
Depending on the law that applies to you, you have the right to:
- access the data we hold about you and receive a copy;
- rectify inaccurate data (you can edit most profile data in the App; date of birth is corrected through support, see Terms section 4.3);
- erase your data: use Account → Delete account in the App, or write to us;
- restrict processing in certain cases;
- data portability: receive the data you gave us in a structured, machine-readable format (JSON);
- object to processing based on legitimate interests;
- withdraw consent at any time (location: in your phone settings; verification, gender preference and marketing consents: in the App or by writing to us);
- not be subject to solely automated decisions with legal or similarly significant effects, and to ask for human review (section 3.3);
- know who received your data and where it was transferred;
- in Turkey, the rights in Article 11 KVKK, including to ask that third parties who received your data are told about a correction or deletion, and to claim compensation for damage caused by unlawful processing.
How to ask. Send requests to connect@bitry.io (users in Turkey: see section 15.2). We may ask you to confirm that the account is yours (for example with a code sent to your phone number). We answer within one month (UK and EU GDPR; we may extend by up to two further months for complex requests and will tell you why) and within 30 days under KVKK. We do not charge for reasonable requests.
Complaints. Please contact us first so we can try to help. You can also complain to:
- the UK Information Commissioner's Office (ICO), ico.org.uk;
- in the EU, the data protection authority of the country where you live or work; in Portugal, the Comissão Nacional de Proteção de Dados (CNPD), cnpd.pt;
- in Turkey, the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu), after applying to us first (section 15.2);
- in Azerbaijan, the competent authority for personal data.
10. Security
We use encryption in transit (HTTPS/TLS) and Google Cloud's encryption at rest, access rules that limit who can read each type of data, App Check to block unauthorised apps, least-privilege access for staff, and review of access to safety data. No system is completely secure. If a personal data breach occurs, we will notify the ICO and the competent EU authorities within 72 hours where GDPR requires, notify the Turkish Personal Data Protection Board within 72 hours, inform affected users without undue delay where required, and meet any other notification duty.
11. Children
NoChat is only for people aged 18 and over. We require a date of birth at sign-up and do not knowingly collect data about anyone under 18. A report that a user is under 18 hides that account immediately until a moderator reviews it. If we confirm that a user is under 18, we suspend the account and delete the data, except what we must keep to prevent re-registration or to report to authorities. If you believe a minor is using NoChat, report it in the App or email connect@bitry.io.
12. Notifications, marketing and device storage
- Push notifications (for example a new match or a meeting reminder) are sent only if you allow them in your phone settings.
- Marketing emails or SMS are sent only with your prior opt-in consent, which you can withdraw at any time. For users in Turkey, consent to commercial electronic messages is registered in the Message Management System (İYS).
- Device storage. The App stores on your device only what it needs to work and stay secure (for example your login session and App Check tokens). This is strictly necessary and does not need consent under Law No. 41/2004 and similar rules. We do not use advertising trackers or third-party advertising SDKs. If we ever add optional analytics, we will ask for your consent first.
13. Venue partner contacts
If you register a Venue on partners.nochat.site, we process the name, phone and email of the contact person and signatory, the Venue's business details (legal name, address, tax and VAT number), billing details, menu, photos and uploaded files, to run the partner account, bill the Venue through Stripe, list events, and communicate with you (including launch-date and billing notices). If the Venue opens a Stripe account for events, Stripe processes the identity checks it needs as an independent controller. The legal basis is contract (Art. 6(1)(b) GDPR; Art. 5(2)(c) KVKK), legal obligation (6(1)(c); 5(2)(ç)) and our legitimate interests in running the partner programme (6(1)(f); 5(2)(f)). The Venue's menu PDF is read by Google Vertex AI (section 6). We keep this data for the term of the partnership and afterwards as long as tax and accounting law requires.
14. Changes to this policy
We will publish updates here with a new version number and effective date. For material changes, we will tell you in the App before they apply and, where the law requires, ask for your consent again.
15. Country-specific information
15.1. Portugal and the European Union
- EU representative (Art. 27 GDPR): Bitry LTD will appoint a representative in the European Union under Article 27 GDPR before offering NoChat to users in the EU. Until then, you and the supervisory authorities can contact us at connect@bitry.io about any data protection matter.
- Supervisory authority in Portugal: Comissão Nacional de Proteção de Dados (CNPD).
- Data protection impact assessment. We carry out a DPIA under Article 35 GDPR for location, meetings with strangers, gender preference and face verification before launch in the EU.
15.2. Turkey (KVKK information notice)
- Data controller: BITRY LTD (details at the top). Data controller representative in Turkey and VERBIS registration: before offering NoChat in Turkey, Bitry LTD will appoint a data controller representative and register with VERBIS as required by KVKK.
- Purposes and legal grounds: section 3.1 (Articles 5 and 6 KVKK).
- Method of collection: electronically, through the App, the partner panel, Stripe, the Stores and RevenueCat, and by email, partly by automated means.
- Recipients and transfers abroad: section 6 and section 7.4 (Articles 8 and 9 KVKK).
- Explicit consents we ask for separately in the App: (1) processing of biometric data for selfie verification; (2) processing of your gender preference, which may reveal data about sex life; (3) where needed, location; (4) commercial electronic messages. Refusing (1) does not stop you using the rest of the App; (2) is needed for matching.
- Your rights under Article 11 KVKK: section 9.
- How to apply: in writing to our representative or to BITRY LTD, by registered electronic mail (KEP), secure electronic signature or mobile signature, or from the email address or phone number registered in the App, as provided in the Communiqué on the Procedures and Principles of Application to the Data Controller. We answer within 30 days. If we reject your application, do not answer in time or you find the answer insufficient, you can complain to the Personal Data Protection Board within 30 days of our answer, and in any case within 60 days of your application.
15.3. Azerbaijan
We process data of users in Azerbaijan under Law No. 998-IIIQ "On Personal Data".
15.4. United Kingdom
Bitry LTD will register with the UK Information Commissioner's Office (ICO) before NoChat is made available to users; the registration number will be published at the top of this Policy. You can complain to the ICO at any time.
16. Contact
BITRY LTD (controller)
Registered in England and Wales, company number 16107519
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Email: connect@bitry.io
EU representative (GDPR Art. 27): to be appointed before NoChat is offered in the EU (section 15.1)
Data controller representative in Turkey (KVKK): to be appointed before NoChat is offered in Turkey (section 15.2)
Data protection officer: not appointed; data protection questions to connect@bitry.io