NoChat Legal documents

Last updated 2026-09-15 · Version 1.1

NoChat Privacy Policy

Version1.1
Effective date2026-09-15
ControllerBITRY LTD, a private limited company registered in England and Wales, company number 16107519
Registered office71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
ICO registrationBitry LTD will register with the ICO before NoChat is made available to users; the number will be published here
EU representative (GDPR Art. 27)Bitry LTD will appoint one before offering NoChat to users in the EU; until then, contact connect@bitry.io
Data controller representative in Turkey (KVKK)Bitry LTD will appoint one before offering NoChat in Turkey, as required by KVKK
VERBIS registrationBitry LTD will register with VERBIS before offering NoChat in Turkey, as required by KVKK
Data protection officerNot appointed; data protection questions: connect@bitry.io
Privacy contactconnect@bitry.io
LanguagesEnglish, Azerbaijani, Turkish, Russian and Portuguese. If the versions differ, the English version prevails, except where the mandatory law of the country where you live requires the version in your language to prevail.

What changed in version 1.1

This policy explains what personal data NoChat collects, why, who receives it, where it is stored, how long we keep it, and your rights. It applies to the NoChat mobile app and the people who use it. Venue partners: section 13 covers the business contact data we process about you.

Which laws apply. NoChat is operated by BITRY LTD ("Bitry LTD", "we", "us"), a company established in the United Kingdom. Bitry LTD is the controller of your personal data. We process your data in line with:

Where these laws differ, we apply the stricter rule.


1. Summary

2. What we collect

CategoryDataSource
AccountMobile phone number; account ID; sign-up and last sign-in timeYou, Firebase Authentication
ProfileFirst name, last name or initial [see note], date of birth, 3 photos, gender, gender(s) you want to meet, interestsYou
Derived profile dataAge and zodiac sign, calculated from your date of birthUs
LocationApproximate location from your phone; the city assigned to youYour device (with permission), us
ActivityMeet / Pass decisions, Meets and Super Meets used, matches, time slots, meetings, cancellations, the Venue bookedYour use of the App
Attendance and reliabilityYour answers and the other person's answers to "Did they come?", no-shows, late cancellations, reliability score, warnings, suspensions, bans and appealsYou, other users, our moderators
VerificationPass/fail result; results of the head-movement challenges; anti-spoofing score; face-match score against your profile photos; model versions; a code (hash) identifying which photos were checked; consent version; date and time. No image, video or face templateThe App on your device
SafetyBlocks, reports you make or that are made about you, notices of illegal content, moderation decisions, statements of reasons and appealsYou, other users, Venues, third parties, our moderators
Device and securityApp version, device type and OS, app instance identifiers, Firebase App Check attestation tokens (Apple App Attest / DeviceCheck, Google Play Integrity), IP address, crash and error informationYour device, Apple, Google
PurchasesProduct, time, price, currency, Store country, Store transaction IDs, refund and cancellation events, your Meet balance. We do not receive your card detailsApple App Store / Google Play, through RevenueCat
Events and ticketsEvent, ticket or reservation status, price and currency, check-in time, refund reason, Stripe payment and refund IDs for tickets paid in the App. We do not receive your card detailsYou, Stripe, Venues
CommunicationsMessages you send to support, privacy or appeal emailsYou
ConsentsWhich documents and consents you accepted (Terms, Privacy Policy, biometric consent, KVKK explicit consents, marketing and İYS status), their version, time and languageThe App

Note on last name: the App stores a last name so the booking can be shown to the Venue with an initial only.

Special category data.

3. Why we use your data and on what legal basis

3.1. Purposes and legal bases

PurposeData usedUK GDPR and EU GDPR (Art. 6, and Art. 9 where marked)Turkey: KVKK (Art. 5, and Art. 6 where marked)
Create and run your account, log you inPhone, account ID, device dataContract (6(1)(b))Necessary for the contract (5(2)(c))
Check that you are 18+, show your age and zodiac sign, prevent age changesDate of birth, age, zodiac signContract (6(1)(b)); legitimate interests in protecting minors and other users (6(1)(f))Contract (5(2)(c)); legitimate interest (5(2)(f))
Show you to people nearby and nearby people to you, including ranking with the zodiac boostProfile, age, zodiac sign, approximate location, interests, activityContract (6(1)(b)); consent for location (6(1)(a))Contract (5(2)(c)); explicit consent for location
Match by gender preferenceGender, interested-inContract (6(1)(b)) + explicit consent (9(2)(a))Explicit consent (6(2))
Arrange meetings and book a Venue; share first name + initial with the VenueMatches, time slots, approximate location, first name + initialContract (6(1)(b))Contract (5(2)(c))
Selfie verification and the Verified badgeVerification results and scores (on-device check)Explicit consent (6(1)(a) and 9(2)(a))Explicit consent (6(2))
Attendance confirmation, reliability score, no-show sanctions and appealsAttendance answers, meetings, reliability, sanctionsContract (6(1)(b)); legitimate interests in reliable meetings for users and Venues (6(1)(f))Contract (5(2)(c)); legitimate interest (5(2)(f))
Safety, reports, notices of illegal content, moderation, fraud prevention, enforcing our TermsProfile, activity, reports, blocks, device and App Check dataLegitimate interests in keeping users safe (6(1)(f)); legal obligation (6(1)(c)), including the EU Digital Services ActLegal obligation (5(2)(ç)); legitimate interest (5(2)(f))
Meet packs and Super MeetsPurchase records, balanceContract (6(1)(b))Contract (5(2)(c))
Event tickets, reservations, check-in and refundsTicket data, first name + initial, main photo at check-inContract (6(1)(b))Contract (5(2)(c))
Tax and accounting recordsPurchase, ticket-fee and venue billing recordsLegal obligation (6(1)(c))Legal obligation (5(2)(ç))
Support, appeals and data-rights requestsCommunicationsContract; legal obligation; legitimate interestsContract; legal obligation (5(2)(ç))
Security, debugging, aggregated statistics to improve the ServiceDevice and security data, activityLegitimate interests (6(1)(f))Legitimate interest (5(2)(f))
Marketing messages (email, SMS)Phone, email if given, consent statusConsent (6(1)(a))Explicit consent under Law No. 6563, registered in İYS
Establishing, exercising or defending legal claimsRelevant recordsLegitimate interests (6(1)(f))Establishing, exercising or protecting a right (5(2)(e))
Complying with law, court orders and lawful requests of authoritiesAny relevant dataLegal obligation (6(1)(c)); vital interests (6(1)(d)) in emergenciesLegal obligation (5(2)(ç)); protection of life (5(2)(b))

Azerbaijan. For users in Azerbaijan we rely on consent, the performance of the contract and legal obligations under Law No. 998-IIIQ.

3.2. Legitimate interests and consent

Where we rely on legitimate interests, we have weighed them against your rights. You can ask us for details and you can object (section 9). You can withdraw consent at any time (section 9). Withdrawal does not affect processing before it. If you withdraw consent that a feature needs (for example location or gender preference), that feature stops working.

3.3. Automated decisions and profiling

For these decisions you have the right to get human review, express your point of view and contest the decision by writing to connect@bitry.io (GDPR Art. 22; KVKK Art. 11(1)(g)).

4. Who can see what

5. Selfie verification (face check)

5.1. How it works. The check runs entirely on your phone:

  1. The App asks you to do random head movements (for example turn your head left or right). Face detection software on the device (Google ML Kit) checks that a live person did them.
  2. An anti-spoofing model (MiniFASNet) checks that the camera sees a real face and not a printed photo or a screen.
  3. A face-matching model (SFace) turns the live face and each of your profile photos into numbers in the phone's memory and compares them, to check that the photos show you.

5.2. What we store. We store only: pass/fail, the challenge results, the anti-spoofing and face-match scores, the method and model versions, a hash code identifying the photos checked, whether the App's security check (App Check) was present, your consent version, and the date and time.

5.3. What we do not store. No selfie photo, video, camera frame or face template (biometric template) is saved to your device storage, sent to our servers, or shared with anyone. The numbers used for the comparison exist only in the phone's memory during the check and are discarded.

5.4. Google ML Kit may send Google limited diagnostic information (such as device model, app ID and performance metrics). It does not include images.

5.5. Biometric data and consent. Processing your face to confirm that you are the person in your photos is biometric data processing under GDPR Article 9 and KVKK Article 6. In Azerbaijan, the law lists face images as biometric data, so your profile photos may count as biometric data too. We ask for your separate explicit consent before the camera opens. You can refuse and ask for manual verification instead. You can withdraw consent at any time: we then delete your verification result, the badge is removed and meetings cannot be scheduled until you are verified again.

5.6. The badge is removed when you change your profile photos. The badge is not an identity, background or safety guarantee (Terms of Service, section 5.3).

6. Processors and recipients

We use these service providers. Processors act on our instructions under written contracts, including data processing terms:

ProviderWhat forDataLocation
Google Cloud / Firebase (Google Ireland Ltd / Google LLC)Database (Firestore), server functions, photo storage, authentication, SMS one-time codes (Firebase Authentication), App CheckAll App data aboveFirestore and Cloud Functions: EU, Belgium (europe-west1). Authentication and SMS delivery: Google global infrastructure, including the US.
Google Cloud Vertex AI (Gemini)Only to read a Venue's uploaded menu PDF into a list of menu items. No user data is sentVenue menu content
Google ML KitOn-device face detection for verificationDiagnostics only, no imagesOn device; diagnostics to Google
RevenueCat, Inc. (US)Confirming in-app purchases and keeping your Meet balance in syncAccount ID (a random ID), Store transaction data, product, price, currency, Store country, device and app version, IP addressUS
Apple (App Store, App Attest) and Google (Google Play Billing, Play Integrity)App distribution, payments for paid items, device integrity. The Stores are independent controllers for the payments they processPurchase records, device attestationGlobal, including the US
Stripe (Stripe Payments UK Ltd / Stripe Payments Europe Ltd)Venue subscription billing (processor for us). For event tickets paid in the App, Stripe and the Venue are independent controllers of the payment; we receive payment status and IDsVenue billing contacts; ticket payment status, amounts, IDsUK, EU, US
MapTiler AG (Switzerland), with OpenStreetMap dataMap tiles on the meeting screenYour IP address and the map area requested when a map is shownSwitzerland / global CDN
SMS and telecom carriers used by Firebase AuthenticationDelivering one-time codesPhone number, codeGlobal
Venues (independent businesses, not our processors)Seating your booking; selling and checking event ticketsFirst name + initial, booking details; for events, main photo at check-inCountry of the Venue
Our representatives in the EU and TurkeyActing as contact point for you and authoritiesRequests you send themEU; Turkey

We may also disclose data to: law enforcement or authorities when required by law or to protect someone's life or safety; professional advisers (lawyers, accountants) under confidentiality; and a successor if our business is sold or reorganised, who will be bound by this policy.

7. International transfers

7.1. Where your data goes. Using NoChat means your data is transferred from the country where you live to the controller in the United Kingdom and to our hosting in the European Union (Belgium). Some services also process data in the United States (Google, Apple, RevenueCat, Stripe) and Switzerland (MapTiler).

7.2. From the EU to the UK we rely on the European Commission's adequacy decision for the UK. From the UK to the EU and Switzerland we rely on UK adequacy regulations.

7.3. To the United States we rely on the EU-US Data Privacy Framework and its UK Extension where the provider is certified, or on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum in the provider's data processing terms.

7.4. From Turkey. Transfers of data of users in Turkey abroad are made under Article 9 KVKK, using the standard contracts approved by the Personal Data Protection Board, which are notified to the Personal Data Protection Authority within 5 business days of signature.

7.5. From Azerbaijan. Law No. 998-IIIQ allows transfers abroad to countries with adequate protection and otherwise generally requires your consent, which you give in the App before your data is transferred.

7.6. You can ask us for a copy of the safeguards we use (section 16).

8. How long we keep data

DataRetention
Account and profile, date of birth, photos, interestsWhile your account exists. Deleted when you delete your account
LocationReplaced on each update; deleted with your account; [target] deleted after 30 days of inactivity
Decisions, matches, time slots, bookingsWhile your account exists; [target] match and booking details deleted 90 days after the meeting date
Attendance answersUsed for sanctions over a rolling 90 days; kept up to 12 months for appeals, then deleted
Reliability score and sanctionsWhile your account exists; ban records as in the safety record row
Verification resultsUntil you verify again, withdraw consent or delete your account. Verification sessions: up to 24 hours
Purchase, ticket and billing recordsAs long as tax and accounting law requires: in the UK, generally 6 years after the end of the financial year
Safety record after a ban (hashed phone number, ban reason, report references)Up to 3 years after the ban, to prevent banned users from re-registering and to support police investigations
Reports, notices, moderation logs and statements of reasonsUp to 3 years
BackupsOverwritten within 35 days
Consent and terms-acceptance recordsWhile the account exists and up to 6 years after, as evidence in case of legal claims

When you delete your account, we delete your profile, photos, location, decisions, matches, verification results and your bookings at Venues. The other person's pending meeting with you is cancelled. Data we must keep by law, and the limited safety record above, is kept only for the stated period, with restricted access. In Turkey, data is deleted, destroyed or anonymised under our personal data retention and destruction policy.

9. Your rights

Depending on the law that applies to you, you have the right to:

How to ask. Send requests to connect@bitry.io (users in Turkey: see section 15.2). We may ask you to confirm that the account is yours (for example with a code sent to your phone number). We answer within one month (UK and EU GDPR; we may extend by up to two further months for complex requests and will tell you why) and within 30 days under KVKK. We do not charge for reasonable requests.

Complaints. Please contact us first so we can try to help. You can also complain to:

10. Security

We use encryption in transit (HTTPS/TLS) and Google Cloud's encryption at rest, access rules that limit who can read each type of data, App Check to block unauthorised apps, least-privilege access for staff, and review of access to safety data. No system is completely secure. If a personal data breach occurs, we will notify the ICO and the competent EU authorities within 72 hours where GDPR requires, notify the Turkish Personal Data Protection Board within 72 hours, inform affected users without undue delay where required, and meet any other notification duty.

11. Children

NoChat is only for people aged 18 and over. We require a date of birth at sign-up and do not knowingly collect data about anyone under 18. A report that a user is under 18 hides that account immediately until a moderator reviews it. If we confirm that a user is under 18, we suspend the account and delete the data, except what we must keep to prevent re-registration or to report to authorities. If you believe a minor is using NoChat, report it in the App or email connect@bitry.io.

12. Notifications, marketing and device storage

13. Venue partner contacts

If you register a Venue on partners.nochat.site, we process the name, phone and email of the contact person and signatory, the Venue's business details (legal name, address, tax and VAT number), billing details, menu, photos and uploaded files, to run the partner account, bill the Venue through Stripe, list events, and communicate with you (including launch-date and billing notices). If the Venue opens a Stripe account for events, Stripe processes the identity checks it needs as an independent controller. The legal basis is contract (Art. 6(1)(b) GDPR; Art. 5(2)(c) KVKK), legal obligation (6(1)(c); 5(2)(ç)) and our legitimate interests in running the partner programme (6(1)(f); 5(2)(f)). The Venue's menu PDF is read by Google Vertex AI (section 6). We keep this data for the term of the partnership and afterwards as long as tax and accounting law requires.

14. Changes to this policy

We will publish updates here with a new version number and effective date. For material changes, we will tell you in the App before they apply and, where the law requires, ask for your consent again.

15. Country-specific information

15.1. Portugal and the European Union

15.2. Turkey (KVKK information notice)

15.3. Azerbaijan

We process data of users in Azerbaijan under Law No. 998-IIIQ "On Personal Data".

15.4. United Kingdom

Bitry LTD will register with the UK Information Commissioner's Office (ICO) before NoChat is made available to users; the registration number will be published at the top of this Policy. You can complain to the ICO at any time.

16. Contact

BITRY LTD (controller)
Registered in England and Wales, company number 16107519
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Email: connect@bitry.io
EU representative (GDPR Art. 27): to be appointed before NoChat is offered in the EU (section 15.1)
Data controller representative in Turkey (KVKK): to be appointed before NoChat is offered in Turkey (section 15.2)
Data protection officer: not appointed; data protection questions to connect@bitry.io