Privacy
Last updated: July 20, 2026
ChatCoreHub is a chat application and download site for the ChatCoreHub desktop and mobile clients. This privacy notice explains the information that may be handled by the website, the ChatCoreHub server, and the ChatCoreHub clients when you create an account, exchange messages, manage contacts and groups, place calls, upload files, or change account settings.
Information We May Collect
- Account information, such as username, email address, password hash, verification status, password reset codes, profile picture, phone number if provided, and account timestamps.
- Authentication information, such as refresh tokens and session records used to keep you signed in.
- Contacts and group information, such as contact entries, contact request status, favorites, blocked contacts, group membership, group ownership, invitations, join requests, group visibility, and group access settings.
- Message and attachment information, such as sender, recipient, group, sent time, read status, attachment filename, content type, file size, and stored attachment data.
- Call information, such as call identifiers, caller, recipient, whether the call used video, and start time.
- Camera and microphone access when you choose to place or answer voice and video calls. ChatCoreHub uses these permissions to capture local audio/video for the call experience.
- Device and app settings, such as language, theme, and notification preferences in the Windows client. Some settings may stay on your device; others may be stored by the server when needed to provide the service.
- Local client data, such as cached session state, local encryption state, WebView2 browser data, temporary files, and app logs stored on your device.
- Website, server, and diagnostic technical data, such as IP address, browser or device information, request times, error logs, crash or reliability diagnostics, and security events.
How We Use Information
- To create accounts, verify email addresses, sign users in, restore sessions, and reset passwords.
- To deliver direct messages, group messages, attachments, read receipts, typing indicators, presence, contact lists, group membership, invitations, and join requests.
- To support voice and video call signaling and call history.
- To request camera and microphone access only when needed for call-related features that you start, answer, preview, or test.
- To show profile information, profile pictures, account settings, and notification-related state inside the app.
- To maintain security, prevent abuse, troubleshoot errors, monitor reliability, and improve the service.
- To provide downloads and basic website navigation.
Google Contacts Data
ChatCoreHub requests the Google Contacts read-only permission only when you explicitly choose People → Add from Google. ChatCoreHub uses the Google People API to read contact names and email addresses and displays them unselected so that you can choose which contacts to import. ChatCoreHub does not modify or delete contacts in your Google Account.
Contact candidates that you do not select are not saved by ChatCoreHub. For contacts you explicitly select, only the contact name and email address are stored as entries in your ChatCoreHub contact list. This information is used only to provide the contact-import and communication features you requested. It is not used for advertising, profiling, or credit decisions, and is not sold or shared with data brokers or advertising platforms.
Google OAuth access tokens are used only to read contacts when you start a Google Contacts import. Depending on the client and Google platform, authorization may be cached so that a later import does not ask for permission again. ChatCoreHub does not request or store your Google account password and does not retain Google OAuth refresh tokens on the ChatCoreHub server.
You can revoke this read-only access inside ChatCoreHub by opening Account → Account safety and selecting Disconnect Google Contacts. Disconnecting clears or revokes the client's Google Contacts authorization, and the next import will ask for permission again. You can also revoke ChatCoreHub from your Google Account permissions. Disconnecting Google Contacts does not delete contacts you previously selected and added to ChatCoreHub; those contacts can be removed separately from your ChatCoreHub contact list.
ChatCoreHub's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Message Privacy and Encryption
ChatCoreHub provides end-to-end encryption for direct messages, group messages, and their attachments. Direct messages use Signal-style end-to-end encryption; group messages are encrypted with per-group keys that are shared securely to each member's own devices. When end-to-end encryption is active, message and attachment content is designed so that only the conversation participants can read it — not the server and not the operator. The server may still process metadata needed to operate the app, such as sender, recipient, group, delivery status, timestamps, attachment records, and call records.
Account records, contacts, invitations, settings, and operational logs are not end-to-end encrypted and are handled by the server so it can run the service. Do not use ChatCoreHub for information that requires a legal, medical, financial, or regulated secure communications system unless your deployment has been reviewed for that purpose.
Voice and video calls use camera and microphone data only for call functionality. ChatCoreHub does not intentionally record calls or sell call media. Calls still require signaling and operational metadata so the app can start, accept, reject, and end calls.
App Permissions and Local Data
The Windows app may request access to your camera and microphone for voice calls, video calls, media previews, or local media tests. You can control camera and microphone permissions through Windows settings. If access is disabled, call features that need that device may not work.
The app stores some data locally on your device, including sign-in state, preferences, encryption-related state, cached WebView2 data, temporary files, and logs. Removing the app or deleting local app data may sign you out or make some encrypted content unreadable on that device.
Sharing
ChatCoreHub does not sell personal information. Information may be visible to other users when required by the app, for example your username, profile picture, contact status, group membership, messages you send, read receipts, typing indicators, or call invitations. Information may also be shared with infrastructure providers, hosting providers, email delivery providers, or administrators who operate the ChatCoreHub server, only as needed to run and protect the service.
ChatCoreHub may use third-party infrastructure such as hosting, database, storage, email delivery, push notification, analytics, crash reporting, or app store services. These providers may process limited data needed to provide, secure, distribute, or diagnose the service.
Retention and Deletion
ChatCoreHub keeps information for as long as needed to provide the app, maintain security, comply with legal obligations, resolve disputes, and operate backups. The server may automatically delete some old messages or expired sessions based on configured retention settings.
The Windows client includes a Delete account option in Settings. Deleting an account is intended to remove the account and related data such as messages, contacts, groups owned by the user, invitations, call history, settings, sessions, and encryption pre-key records. Deletion cannot be recovered from the app. Some information may remain temporarily in backups, logs, caches, or records required for security or legal reasons.
Your Choices
- You can update your username, profile picture, contacts, groups, and device preferences in the app where those controls are available.
- You can sign out of the client to remove the active local session.
- You can delete your account from the Windows client Settings screen by typing your username to confirm.
- You can ask the server operator for access, correction, export, or deletion help when those actions are not available directly in the app.
Security
ChatCoreHub uses technical controls such as password hashing, token-based authentication, transport encryption, database access controls, and end-to-end encryption features where implemented. No system can guarantee perfect security. Keep your device, operating system, and ChatCoreHub client updated, and protect your account credentials.
Children
ChatCoreHub is not designed for children under 13 and should not be used by children without appropriate parent, guardian, school, or organization approval. Server operators should disable or remove accounts that they know are being used in violation of applicable age requirements.
International Use
ChatCoreHub may be accessed from different countries, and data may be processed where the server, administrators, or hosting providers are located. If you operate a ChatCoreHub server for users in a regulated region, you are responsible for configuring and documenting that deployment appropriately.
Changes
This privacy notice may be updated as ChatCoreHub features change. Material updates should be reflected on this page with a new updated date.
Contact
For privacy questions, contact the person or organization operating your ChatCoreHub server. For the public ChatCoreHub service and Microsoft Store listing, contact privacy@chatcorehub.com.