onemore.chat

bu belge yalnızca ingilizce. hukuken geçerli olan sürüm ingilizce sürümdür.

Privacy Policy

Last updated: 26 August 2026

This is the version of the policy in force, not a draft. It is not legal advice, and it has not been reviewed by a qualified lawyer. If you think something here is wrong, unclear or out of date, write to [email protected] and we will look at it.

onemore.chat is an anonymous one to one chat for adults. You enter without registering, get matched with a stranger, and a chat only lasts if both of you keep it. Because you never give us your name, we hold less about you than most services do.

This policy says what we do hold, including the uncomfortable parts, such as staff being able to open a private conversation during a safety investigation.

It sits alongside two other documents: the Terms of Service, our agreement with you, and the Community Rules, which describe what is allowed in chat.

What this policy covers

This policy explains what personal data we collect, why, who processes it, how long we keep it, and what rights you have. It covers the website, the app, and the emails and notifications we send.

It does not cover other companies. Links shared in chat are not blocked or previewed, and once you leave onemore.chat the destination site sets its own rules.

Who is responsible for your data

One More Chat Inc. operates onemore.chat from Türkiye. We are the controller under the GDPR and the UK GDPR, and the data controller under Turkish Law No. 6698 (KVKK). The CCPA and CPRA apply to California residents. Where these rules differ, we apply the one that protects you more.

Privacy questions go to [email protected]. There is no separate data protection officer: the named privacy contact is the owner of the business.

We have not appointed a representative in the European Union under Article 27 of the GDPR, and we have not appointed one in the United Kingdom either. We are telling you that plainly rather than claiming an exemption we cannot support. Until we appoint one, [email protected] reaches us directly, and we answer requests from the EU and the UK there on the same terms as everyone else.

Guest accounts, claimed accounts, and what identifies you

When you enter as a guest we create a real account on our servers, holding your nickname, avatar, settings, chats and subscription state, like a registered account.

That account is bound to the browser and device you entered from, with no email and no password attached, so there is nothing we can check you against. Clearing browser data or switching devices can lose it for good, and there is no recovery path.

Claiming attaches an email address, verified with a one time code, or a Google identity to the same account. Nothing is lost: nickname, avatar, chats, connections, blocks, trust history, subscription and settings all stay, and you gain access from other devices and a contact point we can verify.

  • Internal user id: a random identifier our systems use to refer to you.
  • Nickname and avatar: chosen by you. Claimed accounts can upload a picture instead of the generated avatar.
  • Gender: selected at entry and used for matchmaking.
  • Email address or Google identifier: only if you claim. No real name is ever required.

What we collect

Account and profile data

Nickname, avatar seed or uploaded picture, gender selected at entry, optional bio, vibe, interests and languages, your profile visibility switches, your chat, privacy and notification settings, the GIFs you favourite or recently picked, your 18+ declaration, and account timestamps. Claimed accounts also carry an email address or a Google identifier.

We also keep your previous nicknames and avatars when you change them. That history serves the limit on identity changes and gives staff context in an investigation, and it is not shown to other users.

Chat content and media

Messages you send and receive: text, GIF selections, images, voice notes and video, plus reply quotes, edit history, deletion markers, keeps, blocks, connections and nudges.

Technical and safety data

Your IP address reaches our servers with every request, as it does with any website. We never store it in your account or in our database, and it is never part of your profile.

Two things use it, both short lived. Rate limits keep counters in our cache keyed by the address: a general one minute counter, and a counter for new guest accounts from a network that lasts 24 hours. The abuse signal keeps no address at all: we coarsen it first (IPv4 to its first three blocks, IPv6 to its first three groups), then keep only a keyed hash of that coarse value, which changes every day and is discarded after two days. It can link accounts created from the same network in a short window, and nothing more.

We also keep timestamps such as when an account was created and last seen, and, in analytics events, whether the device is a mobile or a desktop.

Payment metadata

Lemon Squeezy sells subscriptions as merchant of record and handles payments, invoices and tax. We receive metadata such as plan, billing cycle, status, renewal date and order id, linked to your user id. We never see your card number.

Analytics events

Events describing how the product is used, within the strict limits set out under Analytics below.

Support and report content

What you write to support, the report category, any detail you add, and the evidence snapshot attached automatically to a report. What that snapshot holds is described under Reports and evidence.

What we do not collect

  • No birth date and no identity documents. Age is a self declaration made at entry.
  • No country field on profiles, no GPS and no precise location data.
  • No contacts, no address book, no phone number.
  • No proactive scanning of private conversations. No automated content filter reads your messages.
  • No read receipts. We never tell the other person whether you have read a message.
  • No advertising identifiers, ad networks, data brokers, cross site tracking, or selling of personal data.
  • No IP address kept in your account or our database, and no browser or device fingerprint.

Under the GDPR and the KVKK we need a lawful reason for every use of personal data. Where we rely on legitimate interests, we have weighed them against your rights and you can object.

  • Running the service: matchmaking, messages and media, keeps, connections, settings. Data: profile, chat content, technical. Basis: our contract with you (GDPR Article 6(1)(b)); KVKK Article 5(2)(c).
  • Safety and moderation: reports, blocks, enforcement, appeals, detection of accounts made to evade a ban. Data: profile, technical, and chat content where an investigation requires it. Basis: legitimate interests in keeping the service safe (Article 6(1)(f)); KVKK Article 5(2)(f) and 5(2)(ç).
  • Preventing fraud and spam, and keeping the service available. Data: technical. Basis: legitimate interests; KVKK Article 5(2)(f).
  • Billing and subscriptions. Data: user id and payment metadata. Basis: our contract, and legal obligation for tax records.
  • Sign in codes and security notices. Data: your email address if claimed. Basis: our contract, and legal obligation.
  • Web push notifications. Data: your push subscription. Basis: consent, withdrawn by turning notifications off.
  • Product analytics. Data: analytics events. Basis: legitimate interests in seeing which parts of the product work and which quietly fail (Article 6(1)(f)); KVKK Article 5(2)(f). The Analytics section explains why we do not ask for consent for this, and how to object.
  • Lawful requests, child sexual abuse material reporting, evidence preservation. Basis: legal obligation (Article 6(1)(c)); KVKK Article 5(2)(a); vital interests where someone is at risk.

Matchmaking and profile visibility

You choose Woman or Man at entry, and that choice cannot be changed in settings. Staff can correct it in exceptional cases, and the correction is audited.

Gender is used for matchmaking even when you hide it on your profile. Hiding controls what other people see, not how matching works, and we would rather say so than imply a hidden field is unused.

Beyond gender, matching ranks candidates on how long each has been waiting, your vibe, shared interests, shared languages and a trust signal described below. Your nickname, avatar and the fields you have chosen to show are visible to the person you match with.

People you have blocked, people who have blocked you, and people you are already connected to are excluded from matching. Being matched with someone you have chatted with before is otherwise possible: there is no cooling-off period between two people who both keep searching.

Trust signals

Each account carries an internal trust score between 0 and 100, recalculated nightly from a fixed list of signals. It is never shown publicly or to the person you are chatting with.

The score is a small part of how matches are ranked, and it gives staff context when they review a report. It never applies a restriction by itself: every enforcement decision is made by a person.

  • Account age, completed conversations and mutual keeps, which build trust.
  • Reports received, blocks received, confirmed violations and restrictions already applied, which erode it. These effects fade over time, halving roughly every 30 days.
  • Rapid skipping, which is recorded and visible to staff but never counts towards the score and is never on its own a reason for enforcement.
  • The short-lived network signal described under Technical and safety data, used to spot accounts created to get around a suspension.

Media handling

Images and voice notes unlock when someone in the conversation has a Basic or Pro subscription, video needs Pro, and the recipient’s own settings still decide what arrives. The Terms of Service set out the permission rules and the size limits.

We delete your uploaded original as soon as processing finishes, and processed files carry no EXIF or GPS metadata, so a photo does not carry where it was taken. Files live in private buckets and are delivered only through signed links that expire in minutes.

Images and video arrive as a blurred preview by default; the blurred version is generated on our servers, and the real file is only fetched when the recipient reveals it. Voice notes ask for permission by default. Voice and video never play by themselves.

GIF search runs through KLIPY with the safe for work filter applied on our servers. If you switch on spicy gifs in settings, after confirming you are 18 or older, that filter relaxes to suggestive content and never to explicit content. Searches are proxied through our servers, so KLIPY receives the search terms and our server’s request, not your identity or your IP address.

Analytics

We use PostHog to see which parts of the product work and which quietly fail. Analytics requests are sent through our own domain rather than straight to PostHog.

Analytics never receives message text, GIFs, images, voice, video, bios, interests, nicknames, shared links or reply quotes. Session recording, automatic click capture and automatic page tracking are all switched off, and page addresses, page titles and referrers are stripped before anything is sent.

What it does receive: an event name, a small set of fixed properties such as message type, whether the conversation is random or connected, and mobile or desktop, plus internal ids and timestamps. Every property is a fixed value, a number or an internal id, so free text cannot travel this path even by accident.

Three properties are attached to your internal id as a profile: your plan, your gender and whether the account is a guest or claimed. Nothing else. Staff tooling sends no analytics at all.

PostHog runs on its US Cloud, on servers in Virginia in the United States.

Analytics runs on legitimate interests rather than consent, and we show no consent banner for it. What makes that defensible is what is absent: no advertising cookies, no ad pixels, no cross site tracking, no session recording, no automatic click capture, and event schemas that accept only fixed values, numbers and internal ids, so message content, bios and interests are structurally unable to reach PostHog even by mistake.

To object, write to [email protected] and we stop sending analytics events for your account. You do not have to give a reason, and nothing else about the service changes.

Cookies and local storage

Supabase Auth cookies keep you signed in. They are strictly necessary: without them there is no session, and for a guest no account at all.

We use local storage for settings and interface state. Analytics stores its identifier in local storage and in one cookie.

We use no advertising cookies, no ad pixels, and no cross site tracking. There is no cookie banner, because the only cookies we set are the ones that keep you signed in and the single analytics identifier described under Analytics, which runs on legitimate interests and can be objected to by email.

Clearing cookies and site data signs you out, and for an unclaimed guest account that is not reversible.

Notifications and emails

In app notifications are part of the product. Web push is opt in: your browser asks first, and you can withdraw permission at any time.

Push messages travel through your browser vendor’s push service, for example Google, Apple or Mozilla infrastructure. Payloads carry a nickname, an avatar seed and a conversation id, never message text.

Email covers sign in codes and security notices such as a completed claim, both sent by Supabase Auth on our behalf, and moderation decisions where we notify you. Deleting your account sends no email at all: the confirmation, the countdown and the restore control all live in the app.

We send no marketing email and no product update email, and there is nothing to unsubscribe from. If that ever changes we will ask you first.

Who processes data for us

These are the only processors in use.

  • Supabase: authentication, the PostgreSQL database, and object storage for media. The database and the media buckets are hosted in AWS eu-central-1, in Frankfurt, Germany.
  • Supabase Auth: the emails described above, meaning sign in codes and security notices.
  • Railway: application hosting, and Redis for presence, matchmaking and background queues. Region: europe-west4, in Amsterdam in the Netherlands. Railway itself is a company in the United States.
  • Lemon Squeezy: merchant of record for subscriptions, handling payments, invoices and sales tax. The contracting entity is Sold through Link, LLC, trading as Lemon Squeezy, a Stripe company based in Salt Lake City, Utah. Location: the United States.
  • PostHog: product analytics, within the limits above. Location: PostHog US Cloud, on AWS us-east-1 in Virginia, in the United States.
  • KLIPY: GIF search results, from the search terms alone. KLIPY’s own privacy policy describes where it processes them.
  • Browser push services: delivery of the web push notifications you opted into.

International transfers

We are based in Türkiye, our database and media storage are in Frankfurt in Germany, and our application hosting runs in Amsterdam in the Netherlands, so your data crosses borders.

For users in the EEA and the UK, transfers rely on the European Commission’s Standard Contractual Clauses, with the UK Addendum where the UK GDPR applies, or on an adequacy decision. PostHog and Google are also certified under the EU-US Data Privacy Framework and its UK extension.

Under the KVKK, transfers abroad are made under Article 9 of Law No. 6698. Since 1 September 2024 explicit consent has only been a last resort there, for one off transfers, and it does not fit a service that sends the same data to the same processors every day. We therefore rely on Article 9(4)(c): the standard contract published by the Personal Data Protection Board, signed with the processor and notified to the Board within five working days of signature.

You can request a copy of the safeguards at [email protected].

Staff access to private conversations

We do not proactively scan or read private conversations, and no automated content filter reads your messages looking for violations. Nothing is analysed for advertising or profiling.

Authorised staff can, however, access private conversations, media, previous versions of edited messages and recently deleted content, for safety investigations and reports, support requests you raise, fraud prevention, platform operations such as diagnosing a fault, and legal reasons.

Because that power exists, the system fences it in.

  • Two factor authentication is mandatory for staff: an account without it cannot sign in at all.
  • A reason must be recorded before conversation content is shown, and it is stored with the access record.
  • Every access lands in an audit log that cannot be edited or deleted, protected at the database level and chained so that a missing or altered entry is detectable. The chain is verified nightly.
  • Images opened by staff are watermarked on our servers with the staff member’s email address, the case id and the time. Voice and video play behind a permanent on screen identity overlay.
  • Staff sessions are short: 15 minutes of inactivity, and 8 hours at the very most.
  • Roles are least privilege, and most staff roles can never open conversation content.
  • Staff tooling offers no download of user content: it is streamed for viewing only.

Reports and evidence

Reporting is one tap. Report and leave ends the chat, blocks the other person, and attaches the surrounding conversation automatically, so you never have to screenshot anything. You can add a category and details for 24 hours afterwards.

The evidence snapshot is frozen at the moment of the report and survives later deletion by either person. It holds the recent part of the conversation (the last 50 messages or the last 24 hours, whichever is smaller, or about 20 messages either side of a reported message), including message text, edit history and content deleted within the last 30 days, copies of the media in that exchange, both accounts’ current and previous nicknames and avatars, gender, account age, plan, and the trust context described above.

That snapshot is evidence, so it is not deleted when you delete a message or leave. Its retention is set out under How long we keep things.

How long we keep things

These are the retention rules we apply. They run automatically, on a schedule, without anyone asking for them. An open safety case, a legal hold or a law enforcement request overrides them, and content stays until the case or the obligation ends.

A conversation attached to a report is the one thing kept beyond this: it stays with the report, as part of the safety record of the accounts involved, so the two conversation rules below never purge it. The rules for edit history, deleted content and media still apply inside it, once the evidence retention below has run out.

  • Skipped or ended random chats: they stay in Recent Random Chats for 72 hours, then expire, and a one sided Keep expires with them. How many are listed at once depends on your plan.
  • Random conversations that never became connections: purged once they have left Recent and have been ended for 30 days or more.
  • Connected conversations: kept while the connection exists. When both people have left and removed it, the conversation is kept for 30 days and then purged.
  • Previous versions of edited messages, and the content of deleted messages: kept privately for 30 days for safety investigation, then hard deleted.
  • Media in deleted or expired messages: signed links stop being issued immediately, and the stored files are hard deleted after 30 days.
  • Uploaded originals: deleted as soon as processing finishes.
  • Media referenced by a report: held for 180 days from the report, whatever happens to the message it came from.
  • Report evidence snapshots: kept while the case is open, and for 180 days after it closes. Longer while a legal hold applies.
  • Inactive unclaimed guest accounts with no connections: deleted after 90 days, unless a report, a case, an enforcement action or a legal hold touches the account.
  • Reports, enforcement actions and appeal decisions: kept as the safety record of the account while it exists, and for three years after the account is deleted. Where the case ended in a permanent suspension, the record is kept indefinitely. Otherwise deleting your account would be the cheapest way to erase a ban.
  • Staff access and audit logs: retained indefinitely, as the accountability record for the access described above.
  • Content preserved for law enforcement or child safety: as long as the law requires, for example one year for a CyberTipline report.
  • Billing records: held by Lemon Squeezy under their own retention and tax rules.

Security

Traffic between your browser and our servers is encrypted in transit, including the realtime connection that carries messages. Media lives in private buckets behind signed links that expire in minutes, and stored data is encrypted at rest.

Operationally: least privilege staff roles, mandatory two factor authentication for staff, an audit log that cannot be edited, short staff sessions, and rate limits on sensitive endpoints.

Conversations are not end to end encrypted. We can read them under the conditions in Staff access to private conversations, which is what makes reporting and moderation possible. No service can promise perfect security. If a breach affects your data we notify the relevant authority, and you where the law requires.

Your rights

Under the GDPR, the UK GDPR and the KVKK you have the rights below. They apply to guest and claimed accounts alike, although verification limits what we can do for guests.

Decisions that restrict or suspend an account are made by people, not automatically, and an appeal is reviewed by a different staff member than the one who acted.

  • Access: a copy of the data we hold about you.
  • Rectification: correction of inaccurate data. Gender cannot be changed in settings, so write to [email protected] if it is wrong.
  • Erasure: deletion of your data, subject to the exceptions under Deleting your account.
  • Restriction: a pause on processing while a dispute is resolved.
  • Objection: to processing based on legitimate interests, including analytics, safety and abuse prevention.
  • Portability: the data you gave us, in a machine readable format.
  • Withdraw consent: turn off push notifications. Analytics does not run on consent, so to stop it you object instead, as described under Analytics. Processing already done stays lawful.
  • Complain: to Türkiye’s Personal Data Protection Board (KVKK Kurulu), your EEA data protection authority, or the UK Information Commissioner’s Office. We would rather you came to us first.

California privacy rights

If you are a California resident, the CCPA and CPRA give you the right to know what we collect and why, to access, correct and delete it, to opt out of sale or sharing, and to limit the use of sensitive personal information.

We do not sell personal information and do not share it for cross context behavioural advertising, as the CPRA defines those terms, and have not done so in the past twelve months.

We do not discriminate against you for exercising these rights. Our subscriptions are ordinary paid features, not a programme that trades data for a discount, so your price never depends on a privacy choice. An authorised agent may act for you with proof.

How to exercise your rights

Write to [email protected], or use the controls in settings, where changing your data and deleting your account live. We answer within 30 days, and say so if a complex request needs the extension the law allows. Requests are free unless they are manifestly unfounded or excessive.

There is no self serve export yet. Ask for a copy of your data by email and we send it within 30 days. When an export button ships, this paragraph will say so.

For a claimed account we verify you through the email address or Google identity attached to it. For an unclaimed guest account we usually cannot: we hold no email, no phone number and no name, so a request tells us nothing about whether the account is yours. We may therefore be unable to fulfil an access, correction or portability request, because handing a stranger someone else’s private conversations is the worse outcome.

Two things soften that. Most privacy controls work inside the app from the device holding the session, because holding it is proof of control. And claiming your account creates a verifiable contact point that keeps your rights exercisable.

Children

onemore.chat is strictly for adults aged 18 and over. There is no birth date field: entry is a self declaration that you are 18 or older, and we do not knowingly allow anyone under 18.

Reports of a suspected minor are fast tracked ahead of the queue, and accounts we believe belong to minors are removed. If you think a minor is here, report the account or write to [email protected].

We have zero tolerance for child sexual abuse material. Confirmed cases go to the National Center for Missing and Exploited Children (NCMEC), the content is preserved as long as the law requires, and the account is permanently removed.

Deleting your account, and leaving a connection

Settings has a delete account control. You confirm once, and from that moment the account is scheduled for deletion, your profile stops being visible, and you are signed out.

You then have 30 days to change your mind. Sign back in within those 30 days and press restore, and the deletion is cancelled with nothing lost. Do nothing, and at the end of the 30 days the erasure runs and cannot be undone.

A guest account that has never been claimed has no email address attached, so there is no way to sign back in and nothing to restore with. If you delete an unclaimed guest account, it is gone the moment you confirm it. Claiming first is the only way to get the 30 days.

Deleting your account also cancels an active subscription at the end of the period you have already paid for. That period is not refunded.

An unclaimed guest account that has been inactive for 90 days and has no connections is deleted automatically, without you asking.

One thing deletion cannot undo: a conversation has two people in it, and the other person keeps their copy of the history you shared. The same applies when you leave a connection.

Message deletion does travel. A deleted message disappears for both participants, leaving only a message deleted placeholder, with the content kept privately for 30 days before hard deletion.

Blocks involving your account go too, in both directions, so someone who had blocked you loses that entry from their blocked list. A block is there to keep two people apart, and once the account can never be matched, found or contacted again, the block has nothing left to do.

Some records survive deletion because they must: safety records tied to reports and enforcement, evidence snapshots under retention or hold, staff audit logs, content preserved for law enforcement or child safety, and billing records at our merchant of record.

Erasure can also be paused. If the law requires us to keep something about your account — a preservation obligation, or a safety investigation that is still open — the erasure waits. The account stays closed either way: you cannot sign in, you cannot be matched, and nobody can find you. We finish the erasure as soon as the obligation ends, and we tell you if this happens to you.

What deletion means for the records that stay

Those records stay, but you do not stay attached to them. The account behind them is stripped of everything that points at you: no nickname, no avatar, no email address, no Google identity, and no content that could identify you. What is left is a case with no person on it, kept so that a permanent suspension cannot be undone simply by deleting the account and starting again.

One field is the exception, and you should hear it from us rather than find it: the gender you chose when you entered stays on that record. It is a required field in our database with no empty value to set it to, and the alternative is a deletion that fails every time it runs. It is one bit, woman or man, on a record that carries no name, no face, no address and nothing you wrote, and it is already frozen inside the evidence snapshots either way.

Under the KVKK that is anonim hale getirme, making data anonymous, rather than silme, deletion. The two are different obligations and we would rather name the one we are actually performing than call all of it deletion and leave you to discover the difference.

Backups

Erased data stays in our encrypted backups until those backups age out of the backup retention window. We do not open a backup to cut one account out of it: a backup that has been edited is no longer a reliable backup.

If we ever restore from one, the erasures that had already run are applied again as part of the restore, so a restore does not bring a deleted account back.

Changes to this policy

We will update this policy as the product changes, and the date at the top shows the current version. Small corrections take effect when published.

For material changes we give notice in the app, and by email to claimed accounts, at least 30 days before they take effect. Where a change requires your consent, we ask for it rather than assume it.

Contact

Privacy questions and rights requests: [email protected]. Safety, child protection and urgent harm: [email protected]. Everything else: [email protected].

One More Chat Inc., Türkiye. Named privacy contact: the owner of the business.