Effective date: 24 September 2026

1. Who we are and what this policy covers

Reo Chat is operated by REO CHAT LIMITED, a New Zealand company (NZBN 9429053984852). In this policy, “Reo Chat”, “we”, “us”, and “our” mean REO CHAT LIMITED.

This policy covers the Reo Chat website, installable web app, and native iOS and Android apps, shared messages, direct and group conversations, guest replies, invitations, notifications, translation and feedback features, and learning features including the Reo Chat Learning Companion.

2. Information we collect

Depending on how you use Reo Chat, we may collect:

Basic shared messages and a first guest conversation reply can be used without an account. If information is required for a feature, not providing it may mean that feature cannot work.

During selected Reo Chat advertising campaigns, we may temporarily retain the latest text entered into the Send Anywhere composer, including when the visitor does not create a message. We use these captures to understand whether visitors recognise the purpose of the composer and where they stop in the process. Access is restricted to authorised administrators.

3. Where information comes from

We collect information directly from you, automatically when you use Reo Chat, from service providers acting for us, and sometimes from another Reo Chat user. For example, another user may enter your email address for an invitation, add your registered account to a group, or write a message that mentions you.

Where reasonably practicable, we provide notice through the invitation, shared-message, or conversation experience. A person who writes about somebody else must have an appropriate reason or permission and should not include unnecessary sensitive information. We may not have enough reliable contact information to notify every person merely mentioned in user-written content. Anyone can contact us about information Reo Chat may hold about them using the details in section 13.

4. How we use information

We use personal information where reasonably needed to:

We do not sell message content or personal information. We do not opt Reo Chat API content into training public general-purpose AI models.

5. Shared messages, conversations, and invitations

A shared message is available to anyone who has its unlisted link. A recipient can copy or forward the link. Do not treat an unlisted link as confidential or include information that would cause harm if forwarded.

A Reo Chat conversation is access-controlled to its current participants. Direct conversations may include an expiring guest participant. Registered group members added later can see the group’s complete earlier history. Removing somebody stops their future in-app access but cannot make them forget or delete material they already saw, copied, or captured.

“Private conversation” means that Reo Chat restricts in-app access to participants. It does not mean end-to-end encrypted. Reo Chat’s servers and relevant providers must process message content in readable form to translate, explain, moderate, store, and deliver it.

Invitation links expire after 14 days and acceptance is restricted to an account with the invited email address. Invitation email and delivery records may remain for security, support, and normal provider-retention purposes after the link expires.

6. AI and other service providers

Text, photos, and relevant context submitted for translation, explanation, moderation, review, or learning assistance may be processed by OpenAI. Conversation photos are automatically checked for harmful content after sending. We use OpenAI’s business API services, under which API inputs and outputs are not used to train OpenAI models by default unless the customer opts in. Limited data may be retained or processed for service operation, safety, abuse prevention, support, or legal compliance under OpenAI’s terms and privacy commitments.

If you use image search, your search terms and related technical information are sent to GIPHY, and selected media is supplied through GIPHY. An optional Patreon connection for the Learning Companion is handled under Patreon’s own privacy terms.

We also use providers for application, database, and private object storage hosting, email delivery and hosting, network services, error and security operations, and push delivery. Conversation photos are resized and re-encoded to remove embedded metadata such as camera location before the retained copy is stored. A conversation invitation is processed by our email provider and the recipient’s mailbox provider. A push notification may be routed through Expo and the push service used by your browser or operating system, including Apple Push Notification service or Firebase Cloud Messaging. Those services process notification content and subscription or delivery metadata needed to route the alert, while your device displays it.

When somebody arrives through one of our measured advertising campaigns, we may send the relevant advertising provider, such as Meta or Google, limited conversion information about later actions. This can include the conversion type and time, campaign or click identifiers, browser and network information, and hashed account or visitor identifiers. We do not send message text or conversation content for advertising measurement. Browser tags and server-side delivery may both be used, with matching event identifiers to avoid double counting.

Providers may process information outside New Zealand, including in the United States. We assess providers and use contractual, technical, and organisational protections where appropriate. Some optional services also process information for their own stated purposes under their own privacy terms.

7. Guest access, device storage, and push notifications

Guest conversation access is tied to an encrypted browser cookie and normally expires 30 days after it is issued. Clearing browser data or using another browser may end access sooner. Creating an account or logging in from that guest browser can transfer the conversation and its push subscription to the account. Guest access expiring does not delete the conversation or the other participant’s copy.

Push notifications are optional and require permission from your browser or operating system. By default, a conversation alert identifies the sender and may include a short Māori message preview, a photo indicator, or information about a reaction. You can turn notification content previews off for an individual browser or native-app installation. The message body then uses generic wording, although the notification title may still identify the sender or describe a reaction. Your device settings may display either kind of alert on a lock screen; use Reo Chat’s preview setting and your device notification settings to choose what is appropriate for that device. Reo Chat stops sending to removed or invalid subscriptions and to an expired unclaimed guest identity; subscription records may remain for a limited operational period until cleaned up.

8. Administration, safety, and moderation

Automated safety checks may assess submitted content and record classifications or actions. Authorised administrators can access messages, conversations, related activity, invitations, and feedback only when reasonably needed for support, translation-quality review, abuse prevention, security, legal compliance, or service operations. Access is restricted. Administrators do not routinely read every conversation, and automated checks may not detect every safety concern.

Conversation participants can submit a private in-app report for a conversation or a particular message. Authorised administrators review those reports, and the reported participants are not notified by the reporting action. In direct conversations, either participant can block messaging; this stops new messages and notifications in both directions while preserving the existing thread. Safety actions and administrator report-status changes are recorded for accountability. For urgent, account-wide, or privacy concerns, email privacy@reo.chat.

9. Retention, deletion, and account closure

We retain information only while reasonably needed for the purposes described in this policy, to keep an account, message, invitation record, or conversation operating, or for security, support, dispute, accountability, and legal requirements. Different records have different lifecycles. For example, invitation links expire after 14 days, guest-browser access after 30 days, campaign attribution cookies after 90 days, and anonymous visitor cookies after one year. Temporary campaign composer draft captures and translation-review audit records are removed after 30 days. Other product analytics events are normally removed after 13 months; conversation push-delivery diagnostics and revoked subscription records are normally removed after 30 days; and terminal invitation records are normally removed 180 days after expiry. Expiry of a link or browser credential does not necessarily delete the related server record.

Shared messages and conversation history currently have no automatic fixed deletion date. A signed-in creator can delete an eligible shared message from message history. A current conversation participant can download the conversation content available to them in Reo Chat; removed message bodies remain omitted. Whole-conversation deletion is not currently self-service because the same history may belong to other participants. You can request access, another available copy format, correction, or deletion using section 11.

Closing an account removes the account’s active identity and credentials, but does not automatically erase public shared messages or conversation history that other participants rely on. Reo Chat may retain the content with a “Deleted account” identity, de-identify it, restrict it, or delete it where appropriate after considering other participants, legal requirements, security, and reasonable verification.

Deleted information may remain temporarily in security logs, email records, and backups until normal rotation or overwrite. We may retain limited records where reasonably required by law, to resolve a dispute, document a privacy or safety decision, or protect users and the service.

10. Security and privacy breaches

We use reasonable technical and organisational safeguards, including TLS in transit, access controls, secure password hashing, encrypted or signed browser credentials, protected native-session credentials, rate limits, and restricted administrative access. No online service is completely secure, and Reo Chat conversations are not end-to-end encrypted. Use a strong password and avoid submitting information that is unnecessarily sensitive or confidential.

If a privacy breach has caused or is likely to cause serious harm, we will notify the New Zealand Privacy Commissioner and affected people as soon as practicable, subject to the Privacy Act 2020.

11. Access, correction, deletion, and copies

Under the New Zealand Privacy Act 2020, you may request access to personal information we hold about you and ask us to correct it. You may also ask us to provide an available copy in a reasonably usable form or to delete information. Copy-format and deletion requests are considered subject to the rights and privacy of other people, lawful withholding grounds, security and verification needs, technical limits, and records we reasonably need to retain.

Email privacy@reo.chat with enough detail to identify the relevant account, guest browser, invitation, shared message, or conversation. We may verify your identity and authority before releasing or changing information. We will respond within the time required by law, normally no later than 20 working days for an access or correction decision.

If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner.

12. Young people

Reo Chat is not designed to collect more information from young people than is needed for the same messaging and learning features. If you are under 16, use Reo Chat with the involvement of a parent, guardian, teacher, or other responsible adult where appropriate, and do not share sensitive information about yourself or another young person. Adults using Reo Chat with young people should choose age-appropriate content and respect their privacy.

13. Changes and contact

We may update this policy as Reo Chat changes. We will publish the updated policy and effective date here and provide reasonable additional notice before a material change where practicable.

For privacy questions or requests, contact the Privacy Officer at privacy@reo.chat, REO CHAT LIMITED, Wellington, New Zealand.

Send a bilingual message