Privacy score
PeerTalkID achieves a 93% privacy score across 7 criteria: data minimization, IP handling, identity linkability, session encryption, third-party exposure, tracking prevention, and replay protection.
1. Overview
This Privacy Policy explains what data PeerTalkID collects, why we collect it, and how it is used on id.peertalk.chat and related services.
PeerTalkID is designed from the ground up to collect the absolute minimum data necessary to function. Privacy is not a feature we added — it is the foundation of everything we built.
2. Who We Are
PeerTalkID is operated by Mind Chat AI, 10 W 37th St, New York, NY 10018, United States ("we", "us", "our"). Mind Chat AI is the controller of the data described in this policy.
Privacy requests: support@peertalk.chat
3. What We Collect
| Data | Collected | Purpose |
|---|---|---|
| SHA-256 hash of your public key | Yes | Identify your account without storing your actual key |
| Session identifiers | Yes | Maintain login sessions |
| Session timestamps | Yes | Session expiry and security |
| Refresh token identifiers | Yes | Token rotation security |
| One-time nullifiers | Yes | Prevent replay attacks |
| Premium status | Yes | Link PeerTalk Premium subscription |
| Email address | Never | — |
| IP address | Never | — |
| Name or username | Never | — |
| Device fingerprint | Never | — |
| Location data | Never | — |
| Browser/OS information | Never | — |
| Your 12-word passphrase | Never | — |
| Your private key | Never | — |
| Cookies | Never | — |
4. How Your Identity Works
Your 12-word passphrase never leaves your browser. Here is exactly what happens:
- Your browser derives an Ed25519 keypair from your 12 words using PBKDF2 (210,000 iterations)
- Your browser signs a one-time challenge message using your private key
- Only the signature and your public key are sent to our server
- Our server verifies the signature and stores only SHA-256(publicKey + salt)
- This hash cannot be reversed to reveal your public key or passphrase
Result: Even if our entire database were stolen, an attacker would have no way to link any account to a real person, and no way to recover any 12-word passphrase.
Session storage (client-side)
Your session token is stored encrypted in your browser's IndexedDB using AES-256-GCM with a non-extractable cryptographic key. This means the token cannot be read even if an attacker executes JavaScript on a page that embeds PeerTalkID — because the decryption key never leaves the WebCrypto API's secure context.
Your light/dark theme preference is stored in your browser's localStorage. It never leaves your device. This storage is strictly necessary to provide the service you request, so we do not show a consent banner.
5. How We Use Data
We use the data above only to authenticate you, keep sessions secure, prevent abuse and verify Premium status. We do not use it for advertising or profiling, and we do not sell or share it. For users in the European Economic Area (EEA) and the United Kingdom, we rely on performance of a contract (providing the login you request) and our legitimate interests in securing the Service and preventing abuse.
6. What Third-Party Sites Receive
When you sign in to a website using PeerTalkID, that website receives only:
- accountId — a random UUID (e.g.
5ea84ef5-0210-4eb9-9350-7cd3dd60a748). This is not linked to any personal information. - isPremium — a boolean indicating whether you have an active PeerTalk Premium subscription
Third-party sites do not receive: your name, email, avatar, IP address, passphrase, public key, or any other identifying information.
Different websites that use PeerTalkID each see the same accountId for a given user. This is necessary for persistent identity. However, because the accountId is a random UUID with no link to any real-world identity, this does not constitute a privacy risk unless a user voluntarily identifies themselves to those websites. Each website's own handling of data is governed by its own privacy policy.
7. Data Retention
We retain data only as long as necessary:
- Account hash: Retained indefinitely (as long as the account exists)
- Active sessions: Until expiry (maximum 1 year) or manual logout
- Refresh tokens: Until expiry or revocation. Revoked tokens are deleted in hourly cleanup jobs
- Nullifiers: Deleted after 7 days
- Login notifications: Deleted after 30 days
Database backups are taken every 6 hours and retained for 7 days, then permanently deleted.
8. Service Providers
PeerTalkID uses the following third-party services:
- Hostinger — server hosting in Frankfurt, Germany.
- Google Fonts — for typography (fonts.googleapis.com, fonts.gstatic.com). Font requests include your IP address as part of the HTTP request.
- esm.sh — for loading cryptographic libraries in the browser. Requests to esm.sh include your IP address.
- cdnjs (Font Awesome) — for interface icons (cdnjs.cloudflare.com). Icon requests include your IP address as part of the HTTP request.
PeerTalkID does not process payments. Payments for PeerTalk Premium are described in the PeerTalk Privacy Policy. We are actively working to self-host the CDN dependencies above to eliminate these third-party connections.
9. Where Data Is Processed
Our servers are located in Frankfurt, Germany. Mind Chat AI is based in the United States, and some service providers listed above may process data in other countries. Where personal data from the EEA, the UK or Switzerland is transferred to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses where required.
10. Your Privacy Rights
The data we hold is pseudonymous: it cannot be linked to you without your 12-word passphrase. To the extent it is personal data, you have the rights described below.
EEA and UK users
Subject to applicable law, you have the right to access, correct, delete, restrict or object to the processing of your data, and to data portability. You also have the right to lodge a complaint with the data protection supervisory authority in the country where you live or work.
U.S. state privacy rights
Depending on where you live (for example, California), you may have the right to know what personal information we process, to request its deletion or correction, and to opt out of its sale or sharing. We do not sell or share personal information, and we will not discriminate against you for exercising your rights.
How to exercise your rights
You can invalidate all sessions with the "Logout from all devices" feature at id.peertalk.chat/profile. For complete account deletion or any other request, you or an authorized agent can contact support@peertalk.chat. We will delete the account hash, effectively making the account unrecoverable. Technical documentation of our privacy architecture is available at id.peertalk.chat/developers.
11. Children's Privacy
PeerTalkID is not directed to children under 13 and does not knowingly collect personal information from children under 13, consistent with the U.S. Children's Online Privacy Protection Act (COPPA). Because we collect no personal data, we cannot determine user ages. If you are under 13, please do not use this service. If you believe a child under 13 has provided us with personal information, contact support@peertalk.chat.
12. Security
We take security seriously and implement industry-standard protections:
- All connections are encrypted via TLS 1.2+ with HSTS
- Strict Content Security Policy to prevent XSS attacks
- Rate limiting on all authentication endpoints
- Replay attack prevention via cryptographic nullifiers
- Rotating refresh tokens — stolen tokens are invalidated on use
- No access logs containing user activity
If you discover a security vulnerability, please report it to support@peertalk.chat.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of significant changes by updating the "Last updated" date and posting a notice on our website.
14. Contact
Mind Chat AI, 10 W 37th St, New York, NY 10018, United States
- Privacy requests: support@peertalk.chat
- General enquiries: contact@peertalk.chat
- Developers: id.peertalk.chat/developers