IronChat Privacy Policy
Last Updated: August 27, 2026
1. Introduction
IronChat (hereinafter referred to as "the Extension," "we," "our," or "us") is a Google Chrome browser extension developed to provide users with a simple, reliable, and private messaging experience. We are committed to protecting your privacy and handling your personal data with transparency, security, and respect.
This Privacy Policy (hereinafter "Policy") explains what information we collect, how we use it, how we store it, and what rights you have regarding your data when you use the IronChat Extension (hereinafter "the Service").
By installing, accessing, or using IronChat, you agree to the terms of this Policy. If you do not agree with the terms set forth herein, please do not use the Service.
2. Data We Collect
In order to provide the core functionality of the Service, we collect the following categories of data:
2.1. Authentication Information
When you create an account or log in to IronChat, we collect your email address and a hashed password. This information is used solely for the purpose of user authentication, account management, and maintaining a secure session. We do not store passwords in plain text; all passwords are encrypted using industry-standard hashing algorithms prior to storage.
2.2. Personal Communications
IronChat is a messaging platform. As such, the Service transmits, stores, and delivers chat messages sent between users. This includes, but is not limited to:
- Text messages
- User-created content shared within the platform
These communications are stored on our secure backend servers solely for the purpose of delivery to the intended recipients. Messages are retained only as long as necessary for the functioning of the Service, unless otherwise requested by the user.
2.3. Usage Data
We may collect limited, non-identifiable usage data to improve the Service. This may include:
- Timestamps of messages sent and received
- User interaction with the Extension interface
- General usage patterns (e.g., feature engagement)
This data is anonymized and aggregated, meaning it cannot be used to individually identify you. We do not use this data for marketing, advertising, or any commercial purposes beyond improving the user experience.
3. What We Do NOT Collect
We explicitly do not collect, store, or process the following categories of data:
- Personally identifiable information beyond your email address
- Health information
- Financial and payment information
- Location data
- Web history
- User activity (e.g., clicks, mouse position, scroll, or keystroke logging)
- Website content
- Any data unrelated to the core messaging functionality of the Service
4. How We Use Your Data
4.1. Authentication
Your email address and password are used to create and authenticate your account. This ensures that only you can access your messages and that your identity is verified when sending and receiving communications.
4.2. Message Delivery
Your messages are stored temporarily on our backend servers and delivered to the recipient(s) you have chosen. This is the essential function of the Service. Messages are not used, analyzed, or shared for any purpose other than their intended delivery.
4.3. Service Improvement
Anonymized usage data may be analyzed to identify bugs, improve performance, and optimize the overall user experience. No personal data is used for this purpose.
5. Data Storage
All data collected by IronChat is stored securely on cloud-based servers operated by trusted third-party providers. These providers are compliant with industry-standard security protocols, including encryption in transit and at rest.
- Authentication Data: Stored in a secure database with restricted access.
- Messages: Stored on secure servers to ensure reliable delivery and retrieval.
- Encryption: All data transmitted between your device and our servers is encrypted using TLS (Transport Layer Security) to prevent interception by unauthorized third parties.
We retain data only for as long as necessary to provide the Service. Messages are stored until they are successfully delivered to the recipient and may be stored on your local device for offline access.
6. Data Sharing
6.1. Third-Party Sharing
IronChat does not sell, rent, trade, or share your personal data with third parties for any purpose, including marketing or advertising. The only third-party entities we interact with are:
- Backend Service Providers: Cloud storage and database providers used to host and deliver the Service. These providers are bound by strict data protection agreements.
- Authentication Providers: Services used to manage user authentication, such as Clerk or Supabase.
6.2. Legal Requirements
We may disclose your data if required to do so by law or in response to a valid legal request (e.g., a court order or subpoena). In such cases, we will take reasonable steps to notify you, provided we are legally permitted to do so.
6.3. User Consent
We will not share your data with any third party without your explicit consent, except as necessary for the operation of the Service or as described in this Policy.
7. User Rights and Control
You have control over your data. You may:
- Access: Request a copy of the data we hold about you.
- Correction: Request that we update or correct any inaccuracies in your data.
- Deletion: Request that we delete your account and all associated data. Upon such a request, we will permanently remove your data from our systems within a reasonable timeframe.
- Opt-Out: Refuse the collection of anonymized usage data without affecting your ability to use the Service.
To exercise any of these rights, please contact us using the information provided in Section 10.
8. Security
We take the security of your data seriously. We implement a combination of technical, administrative, and physical safeguards to protect your data from unauthorized access, disclosure, alteration, or destruction. These measures include:
- Encryption of data in transit and at rest
- Regular security audits and vulnerability assessments
- Access controls limiting data access to authorized personnel only
Despite our efforts, no method of transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.
9. Compliance with Laws and Regulations
This Policy complies with applicable data protection laws, including but not limited to:
- General Data Protection Regulation (GDPR) – For users located in the European Union
- California Consumer Privacy Act (CCPA) – For users located in California, USA
- Personal Data Protection Act (PDPA) – For users located in Singapore
We are committed to upholding the principles of data minimization, purpose limitation, and transparency in all our data processing activities.
10. Changes to This Privacy Policy
We reserve the right to update or modify this Policy at any time. Changes will be effective immediately upon posting the revised Policy on this page. We encourage you to review this Policy periodically to stay informed of any updates.
Material changes to this Policy will be communicated to you via:
- A notification within the Extension
- An email to the address associated with your account (if available)
Your continued use of the Service after any changes constitutes your acceptance of the new terms.
11. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact us at:
Email: hih507164@gmail.com
We endeavor to respond to all inquiries within a reasonable timeframe, typically no later than 30 days from receipt.
12. Effective Date
This Privacy Policy is effective as of August 27, 2026.