Privacy Policy

Last updated: August 2026

Anonymous by design

Nightcap is built to minimize the personal data we collect. You do not need an account to use the core product. However, we do process certain data as described below, some of which constitutes personal data under applicable privacy regulations including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

What we collect and why

DataPurposeLawful basis (GDPR)
IP address (SHA-256 hashed)Ban enforcement, abuse prevention, rate limitingLegitimate interest (Art. 6(1)(f))
Session tokensSession continuity, matchmakingLegitimate interest
Moderation logs (hashed IP, confidence scores, categories)Content moderation, safety compliance, transparency reportingLegitimate interest / legal obligation (Art. 6(1)(c))
Session analytics (chat counts, mode, country)Service improvement, abuse pattern detectionLegitimate interest
Reports submitted by usersSafety enforcement, compliance with legal obligationsLegitimate interest / legal obligation
Payment data (processed by Stripe)Payment processing for one-time BoostsPerformance of contract
Derived age and self-identified genderMandatory 18+ enforcement and matchmaking routing. We never store your date of birth — only the age computed from it at the moment you confirm it.Legal obligation (age verification) / Legitimate interest
Device fingerprint (hashed signals from your browser's canvas, WebGL, audio, fonts, and screen configuration)Recognizing repeat visitors across IP changes, ban-evasion resistance, matchmaking fairness (preventing a small number of identities from dominating the match pool), and identifying high-demand profiles for Boost offersLegitimate interest (Art. 6(1)(f))
Video frames captured during sessionsContent moderation (see "Automated content moderation" below for retention and access)Legitimate interest / legal obligation
Messages you send to an AI chat companionGenerating the companion's reply, sent to our AI provider (Google Gemini) at the time you send the message. Not stored as a transcript.Performance of contract / legitimate interest
Country / region, derived from request headers supplied by our infrastructure providers (Vercel, Cloudflare) at the network edgeDetermining whether the service is available in your location and whether mandatory age verification applies there (see "Regional availability" in the Terms)Legal obligation / legitimate interest

Note on device fingerprinting: we compute a fingerprint from passive browser signals on each visit and send only the resulting hash — the raw signals never leave your device and nothing is stored in cookies or localStorage to produce it. Because the hash is stable across sessions, it is pseudonymized personal data under GDPR (similar to hashed IPs) and is used solely for the purposes above, never for advertising or cross-site tracking.

Note on IP hashing:For moderation and ban enforcement, we store only a salted SHA-256 hash of your IP address — not the plaintext address. Because re-identification is theoretically possible with the salt, hashed IPs still constitute pseudonymized personal data under GDPR and we treat them accordingly. The one exception is legally mandated CSAM reporting: your raw IP address may be included, transiently, in a CyberTipline report to NCMEC where the law requires it (see "Law enforcement and legal disclosure" below) — it is not otherwise persisted anywhere in plaintext.

Automated content moderation

Nightcap uses automated systems to detect prohibited content during your sessions:

  • Video frames: Periodically captured during sessions and analyzed by AWS Rekognition for prohibited visual content. Unlike text messages, frames are stored — not indefinitely, and not for you or the other participant to browse. They are retained for up to 30 days for moderation purposes, viewable only by Nightcap's trust & safety admins (never by other users), and then automatically deleted by a daily job. A frame is kept longer than 30 days only if it is evidence in an active NCMEC CyberTipline report or an open human review, in which case it is retained for at least one year as required by the federal REPORT Act (18 U.S.C. § 2258A).
  • Text messages: Analyzed by OpenAI's moderation API for prohibited language. Message text is processed transiently and not stored as a transcript.
  • Client-side detection: MediaPipe runs in your browser for real-time content classification. This data does not leave your device.

When the automated system detects a potential violation, it logs the confidence score, category, and action taken. Depending on severity and repeat history, this can range from an on-screen warning to a temporary access restriction (see the enforcement ladder in our Community Rules). Apparent CSAM is escalated for urgent human review and reported to NCMEC. All automated enforcement decisions can be appealed, except bans tied to CSAM or underage use.

What we do NOT collect

  • Permanent recordings of video or audio streams from your sessions (moderation frames are individual still images, captured periodically and retained as described above — not a recording of the session)
  • Conversation transcripts, whether with another user or with an AI chat companion (message text is processed to detect violations and, for AI companion messages, to generate a reply — neither is stored as a transcript)
  • Your date of birth (only the derived age is stored, computed once at verification)
  • Precise geolocation (only country/region is derived from request headers at the network edge)
  • Advertising or cross-site tracking identifiers — our device fingerprint (see above) is used only for matchmaking integrity, never ad targeting

Data processors

We share data with the following third-party processors:

  • Stripe: Payment processing for Boosts and Translate minute packs. Subject to Stripe's privacy policy and DPA.
  • AWS (Rekognition): Video frame moderation and free selfie age estimation. Processed under AWS's GDPR DPA. Frames are not used for model training.
  • OpenAI: Text moderation. Processed under OpenAI's API data usage policy and DPA. Messages are not used for model training.
  • Google (Gemini): Powers the AI chat companion feature. When you chat with an AI companion, your message text is sent to Google's Gemini API to generate the companion's reply. Subject to Google's API data usage terms.
  • Didit: Optional, stronger ID-based 18+ verification, used only if you choose that verification method instead of the free selfie estimate.
  • Cloudflare: CDN, DDoS protection, WebSocket signaling. Subject to Cloudflare's privacy policy and DPA.
  • Vercel: Web application hosting and geolocation headers used for regional availability. Subject to Vercel's DPA.

Data retention

This schedule is enforced automatically by a daily deletion job, not by policy alone:

  • Moderation frames (screenshots): retained 30 days, then deleted, unless the frame is evidence attached to an NCMEC report or an open human review — those are retained for at least 1 year per the federal REPORT Act, and only as long as the review or report stays active
  • Hashed IP bans: deleted within 30 days of the ban's expiry (not deleted the instant it expires — the extra window preserves a short post-ban probation period); permanent bans retained until reversed
  • Session reports: resolved reports retained for 90 days; unresolved reports are retained until reviewed
  • Moderation logs: retained for 90 days; CSAM-tier moderation decisions are retained for at least 1 year per the REPORT Act
  • Session analytics / identity records: retained for 12 months, then deleted
  • Network-reputation cache entries: purged automatically once they expire (typically within 24 hours)
  • Boost and Translate-minute payment records: retained for 3 years for accounting and tax purposes
  • Device fingerprint hash, derived age, and gender: retained while the identity remains active (visits within the last 12 months), then deleted along with the rest of that identity's record

Law enforcement and legal disclosure

We may disclose information to law enforcement when required by law, subpoena, or court order, or when we have a good-faith belief that disclosure is necessary to prevent imminent harm.

We report apparent CSAM to the NCMEC CyberTipline as required by 18 U.S.C. § 2258A. Where configured, reports are transmitted directly through NCMEC's CyberTipline API; if that transmission cannot complete, the report is queued for prompt manual filing by our team rather than dropped. As part of a CyberTipline report, your raw (non-hashed) IP address may be included transiently, as NCMEC's reporting format requires — this is the one circumstance in which a plaintext IP address leaves our systems.

Regional availability and geo-processing

We derive a coarse country and region from headers our hosting and CDN providers (Vercel, Cloudflare) attach to each request at the network edge — not from a third-party lookup we perform ourselves. We use this only to apply jurisdiction-based legal requirements: keeping the service unavailable in regions we do not currently serve (for example, the UK), and requiring completed 18+ verification before chat access in U.S. states with age-verification statutes. This processing happens on every request regardless of account status, and is separate from — and coarser than — the country field associated with your session data described above.

Your rights

Under GDPR, CCPA, and similar frameworks, you have the right to:

  • Access: Request a copy of the data associated with your IP hash or device fingerprint.
  • Deletion: Request deletion of data associated with your IP hash or device fingerprint, including the derived age/gender and popularity signals.
  • Rectification: Request correction of inaccurate data.
  • Object: Object to processing based on legitimate interest, including device fingerprinting.
  • Portability: Receive your data in a structured, machine-readable format.

To exercise these rights, email privacy@nightcap.chat from the browser/device in question so we can compute the same fingerprint hash to locate your records (or provide your current IP address, which we will hash the same way). We will respond within 30 days.

California residents:Under the CCPA, you have the right to know what personal information we collect, request deletion, and opt out of any sale or sharing of personal information. Nightcap does not sell personal information. To the extent that sharing data with our processors constitutes "sharing" under CCPA, you may opt out by emailing privacy@nightcap.chat.

Cookies and local storage

Nightcap does not use tracking cookies. We use browser localStorage to store your session token, age verification status, gender/matching preferences, and active Boost status. These are functional storage items necessary for the service to operate and do not track you across sites.

Changes to this policy

We may update this Privacy Policy at any time. Material changes will be announced via an in-app banner. Continued use after changes constitutes acceptance.

Contact

Questions? Email privacy@nightcap.chat