آخری بار اپ ڈیٹ کیا گیا: July 2026
Nightcap کو اس طرح بنایا گیا ہے کہ ہم کم سے کم ذاتی ڈیٹا جمع کریں۔ بنیادی پروڈکٹ استعمال کرنے کے لیے آپ کو اکاؤنٹ کی ضرورت نہیں۔ تاہم، ہم نیچے بیان کردہ کچھ ڈیٹا پراسیس کرتے ہیں، جس میں سے کچھ قابلِ اطلاق پرائیویسی ضوابط بشمول EU جنرل ڈیٹا پروٹیکشن ریگولیشن (GDPR) اور کیلیفورنیا کنزیومر پرائیویسی ایکٹ (CCPA) کے تحت ذاتی ڈیٹا شمار ہوتا ہے۔
| Data | Purpose | Lawful basis (GDPR) |
|---|---|---|
| IP address (SHA-256 hashed) | Ban enforcement, abuse prevention, rate limiting | Legitimate interest (Art. 6(1)(f)) |
| Session tokens | Session continuity, matchmaking | Legitimate interest |
| Moderation logs (hashed IP, confidence scores, categories) | Content moderation, safety compliance, transparency reporting | Legitimate interest / legal obligation (Art. 6(1)(c)) |
| Session analytics (chat counts, mode, country) | Service improvement, abuse pattern detection | Legitimate interest |
| Reports submitted by users | Safety enforcement, compliance with legal obligations | Legitimate interest / legal obligation |
| Payment data (processed by Stripe) | Payment processing for one-time Boosts | Performance of contract |
| Derived age and self-identified gender | Mandatory 18+ enforcement and matchmaking routing. We never store your date of birth — only the age computed from it at the moment you confirm it. | Legal obligation (age verification) / Legitimate interest |
| Device fingerprint (hashed signals from your browser's canvas, WebGL, audio, fonts, and screen configuration) | Recognizing repeat visitors across IP changes, ban-evasion resistance, matchmaking fairness (preventing a small number of identities from dominating the match pool), and identifying high-demand profiles for Boost offers | Legitimate interest (Art. 6(1)(f)) |
Note on device fingerprinting: we compute a fingerprint from passive browser signals on each visit and send only the resulting hash — the raw signals never leave your device and nothing is stored in cookies or localStorage to produce it. Because the hash is stable across sessions, it is pseudonymized personal data under GDPR (similar to hashed IPs) and is used solely for the purposes above, never for advertising or cross-site tracking.
Note on IP hashing: We hash your IP address using SHA-256 with a server-side salt. While we never store your plaintext IP, hashed IPs constitute pseudonymized personal data under GDPR because re-identification is theoretically possible with the salt. We treat this data accordingly.
Nightcap uses automated systems to detect prohibited content during your sessions:
When the automated system detects a potential violation, it logs the confidence score, category, and action taken. High-confidence detections may result in automatic session termination and access restriction. All automated decisions can be appealed.
Private Mode disables the automated NSFW content filter. It does not create an encrypted or unmonitored channel. Nightcap retains the right and obligation to scan for illegal content (including CSAM, credible threats, and terrorism-related material) in all modes, including Private Mode. No video or audio is stored permanently.
We share data with the following third-party processors:
We may disclose information to law enforcement when required by law, subpoena, or court order, or when we have a good-faith belief that disclosure is necessary to prevent imminent harm. We cooperate fully with NCMEC CyberTipline reports and applicable mandatory reporting requirements.
Under GDPR, CCPA, and similar frameworks, you have the right to:
To exercise these rights, email privacy@nightcap.chat from the browser/device in question so we can compute the same fingerprint hash to locate your records (or provide your current IP address, which we will hash the same way). We will respond within 30 days.
California residents:Under the CCPA, you have the right to know what personal information we collect, request deletion, and opt out of any sale or sharing of personal information. Nightcap does not sell personal information. To the extent that sharing data with our processors constitutes "sharing" under CCPA, you may opt out by emailing privacy@nightcap.chat.
Nightcap does not use tracking cookies. We use browser localStorage to store your session token, age verification status, gender/matching preferences, and active Boost status. These are functional storage items necessary for the service to operate and do not track you across sites.
We may update this Privacy Policy at any time. Material changes will be announced via an in-app banner. Continued use after changes constitutes acceptance.
Questions? Email privacy@nightcap.chat