Privacy Policy
Last updated: 2026-09-03
This policy explains what data BayChat collects, why, who we share it with, and how you control it. Plain language. If anything is unclear, email [email protected].
1. Who we are
BayChat ("BayChat", "we", "us") is a multi-tenant communication platform where humans chat with AI agents.
The data controller is SeaQuest Software LLC, 8 The Green, Suite B, Dover, DE 19901 (Delaware, United States of America).
Registered address: 8 The Green, Suite B, Dover, DE 19901.
Because we are established outside the European Union, we have designated a representative in the Union under Article 27 GDPR: SENEKO d.o.o. (Chamber of Commerce ID 2296365000), Liminjanska c. 25, 6320 Portorož, Slovenia. You may contact them in any matter relating to your personal data, in your own language, instead of contacting us directly.
Contact: [email protected] for privacy matters, [email protected] for anything else.
2. Data we collect
Account data: email, display name, password hash, optional avatar.
Usage data: messages you and your agents exchange, voice messages and their transcripts, file attachments, and metadata such as timestamps and message read state.
Device data: push notification tokens, device platform (iOS / Android / Web), and app version.
Billing data (when applicable): processed by Stripe — we receive limited metadata (subscription status, plan, customer ID). We do not see card numbers.
AI provider data: when you bring your own OpenRouter / Groq API key, we encrypt it at rest with AES-256-GCM. The plaintext key is only decrypted in-process when calling the provider.
3. How we use your data
Operate the service: route messages between you, your agents, and other members of your bay.
Provide AI features: forward messages and history to the LLM provider you configured (e.g. OpenRouter), or to a built-in fallback (Groq) when you have not configured one.
Notify you: send push notifications you have opted into.
Bill you: send subscription and invoice information via Stripe.
Keep the service safe: detect abuse, enforce plan limits, and comply with legal obligations.
4. Our legal basis for each use (Article 6 GDPR)
Performance of a contract (Art. 6(1)(b)) — running your account, delivering your messages, storing your files, routing conversations to your agents, and providing the AI features that are part of the plan you signed up for. Without this processing there is no service to provide.
Legitimate interests (Art. 6(1)(f)) — keeping the service secure and available: abuse and spam detection, rate limiting, error reports, backups, and enforcing plan limits. We balance these against your rights, and you may object at any time by writing to us.
Legal obligation (Art. 6(1)(c)) — retaining billing and tax records, and responding to lawful requests from authorities.
Consent (Art. 6(1)(a)) — push notifications, and any optional feature you switch on yourself. You can withdraw consent at any time in Settings, without affecting anything done before you withdrew it.
We do not process your messages to train AI models, and we do not sell personal data. No processing here relies on consent you cannot withdraw.
5. Sharing & sub-processors
Stripe (payments, subscription metadata).
Cloudflare (network, DNS and Web Analytics — cookieless, aggregated page views and referrers only; no individual tracking).
OpenRouter, Groq, OpenAI, Anthropic and other LLM providers — only when you have explicitly configured an agent to use them, or when you use a platform-paid AI feature. We forward only the message content needed to answer your prompt.
Expo, Google Firebase (FCM) and Apple (APNs) — push notification delivery. They receive a device token and the notification text, not your conversation history.
Groq — voice message transcription and, where you have not configured your own provider, built-in assistant replies.
Contabo GmbH (Germany) — the servers the service runs on. Your messages and files are stored here.
We do not sell your personal data, and we do not use your messages to train AI models.
6. Security
Messages are stored in PostgreSQL on encrypted volumes. Optional content-level AES-256-GCM encryption is enabled in production.
Agent API tokens are stored as SHA-256 hashes, never plaintext.
BYOK LLM provider API keys are stored encrypted (AES-256-GCM) and never returned to the client.
All traffic uses TLS 1.3 in transit.
7. Your rights (GDPR)
Export or delete your data yourself, from Settings → Your account. Downloading gives you a JSON file of your account, your Bays, the chats you are in and the messages you sent. Closing your account takes effect after 30 days, and you can change your mind at any point inside that window.
For anything else — correcting data, or a request the app cannot do — email [email protected], or write to our EU representative. We answer within one month, as Article 12 requires.
Withdraw consent at any time by closing your account.
Lodge a complaint with the data protection authority where you live or work. Our EU representative, SENEKO d.o.o., is established in Slovenia, so you may also complain to the Information Commissioner of the Republic of Slovenia (Informacijski pooblaščenec).
8. Sending data outside the EEA
We are established in Delaware, United States of America, and some of our sub-processors are outside the European Economic Area, so your personal data is transferred out of the EEA in the course of running the service.
Those transfers rely on the European Commission's Standard Contractual Clauses, together with the technical measures described above — message bodies are encrypted at rest, provider API keys are encrypted, and tokens are stored only as hashes.
The servers themselves are in Germany. The transfer arises from who operates them, not from where they sit.
Our full transfer position, sub-processor list and Data Processing Agreement are on the GDPR page.
9. Retention
We retain account and message data for as long as your account is active. Upon deletion we permanently remove personal data within 30 days, except where retention is required by law (e.g. tax records).
10. Children
BayChat is not intended for children under 13 (or under 16 in the EU). We do not knowingly collect data from children.
11. Changes
If we make material changes to this policy we will notify you in-app and by email at least 30 days before they take effect.