Privacy Policy
Version 1.0 · Effective 22 September 2026 · Last reviewed 22 September 2026
In short
ChatNow is operated by Skyline Online LLC, which is the controller of your personal data. Guests give us a username, gender, age and city; members also give an email address, a password and a date of birth. Guest content is deleted 24 hours after you leave, connection logs are kept for 12 months for security, and messages are moderated by human moderators and an automated classifier. We never see the documents or images used for your age check, and we never see your card number. We do not sell personal data. You can access, correct or delete your data by emailing privacy@chatnow.fr, and you can complain to us or to the Information Commissioner's Office.
1. Who we are and how to contact us
The controller of your personal data is Skyline Online LLC, a Limited Liability Company registered in the State of New Mexico, United States of America, with its registered office at 1209 Mountain Road Place NE, Ste N, Albuquerque, NM 87110, USA. Skyline Online LLC trades as ChatNow and operates the service at https://chat-now.uk/. Its legal representative is the Managing Member of Skyline Online LLC. Full company details are on our Company information & legal notice page.
Because Skyline Online LLC is established outside the United Kingdom, it has appointed a representative in the United Kingdom under Article 27 of the UK GDPR. You may address any question, request or complaint about this policy either to us or to our UK representative: DataRep, 107-111 Fleet Street, London EC4A 2AB, United Kingdom.
Skyline Online LLC is registered with the Information Commissioner's Office (ICO) under registration number [[ICO REGISTRATION NUMBER]]. You can check this entry on the ICO public register.
Our data protection contact is privacy@chatnow.fr. This address handles all data protection matters, including rights requests and complaints. You can also write to the registered office above or use our web contact form.
2. Who this policy applies to
This policy explains how we process personal data about:
- visitors who read the pages of chat-now.uk without entering the chat;
- guests who enter the chat with a username and no account;
- members who hold a registered account, including members who buy ChatNow Premium;
- people who contact us by email or through the contact form, including people who report content without being users;
- people who are the subject of a report, a moderation decision or a request from an authority, whether or not they use ChatNow (for example, a person whose image has been shared without consent).
Three organisations process data about you as independent controllers under their own privacy notices, which this policy does not cover: AgeVerif for your age check, Google LLC if you sign in with Google, and our payment processor when you pay for Premium. Sections 3 and 7 say what each passes to us. Read this policy with our Terms of Service, Cookie Policy and Your Data Rights page.
3. What we collect and where it comes from
3.1 Guests
To enter as a guest you give us a username (3 to 20 characters), your gender (Man, Woman, Trans, CD or Couple), your age and your city. The city is chosen from a list built from the GeoNames geographical database; we do not use GPS. Guests give no email address or password. These four fields are required to open a session. Guest data, including messages and media, is deleted automatically 24 hours after the guest leaves.
3.2 Members
To open an account you give us an email address, a password of at least 12 characters, your date of birth and your gender. Your password is stored only as a PBKDF2-SHA512 hash; we cannot read it. You may add an optional profile bio and up to 10 gallery photos, and we keep your friends and contacts list and the users you have blocked or muted. If you choose to sign in with Google, Google confirms your identity to us and passes us the email address of your Google account; we never receive your Google password.
3.3 Content you create
We process the public messages you post in rooms, the private messages you exchange, the images you upload and the voice notes you record. Private messages are stored on our servers so that they can be delivered and are subject to the moderation described in section 6.
3.4 Webcam and voice
Live webcam and voice are real-time WebRTC streams relayed through ChatNow's own media servers. Streams are not recorded or stored by ChatNow. Our connection logs record that a stream took place and when, but not its content. We do not perform facial recognition or any other biometric identification on webcam images. Anyone watching a stream can, however, capture it with their own device.
3.5 Technical data
When you connect we record your IP address, a device identifier stored in a cookie, your session ID and connection timestamps. From your IP address we derive whether you are connecting through a VPN or proxy, which we use only for spam and abuse prevention.
3.6 Age check
Before any room, private message, image or webcam is accessible, every visitor completes a highly effective age check operated by the independent provider AgeVerif. AgeVerif does not learn which site you are visiting, and ChatNow receives only a yes/no result: no identity document, photo, facial image or age estimate is ever transmitted to or stored by ChatNow. The result is held for the current session only and the check is repeated at each new session. Details are in our Age Assurance Policy.
3.7 ChatNow Premium
If you buy Premium we record the transaction ID, amount, currency, plan and date. Card data is handled solely by a PCI-DSS certified payment processor; ChatNow never sees your card number. The charge appears on your bank statement as "SKYLINE-ONLINE".
3.8 Support and correspondence
We keep the emails and contact-form messages you send us, our replies, and the reports, complaints, appeals and rights requests you submit.
3.9 Moderation records
We keep reports made by or about you, flags raised by our automated tools, moderator decisions and their reasons, sanctions applied, ban records (account, IP address and device identifier) and evidence snapshots of content that was reported or removed.
3.10 Where the data comes from
Most of this data comes directly from you or automatically from your device. Some comes from other sources: other users, when they report you or mention you in a message; our providers, in the form of the age-check result from AgeVerif, the outcome of the Cloudflare bot-protection challenge, and hash-match results from Project Arachnid and StopNCII.org; and public authorities, when they send us a request about an account.
4. How we use your data and our lawful bases
The UK GDPR requires us to have a lawful basis under Article 6 for each purpose. The table below sets them out. "Recognised legitimate interest" refers to Article 6(1)(ea) and Annex 1 of the UK GDPR, inserted by the Data (Use and Access) Act 2025 and in force since 5 February 2026, which covers purposes such as preventing and detecting crime and safeguarding vulnerable individuals without a separate balancing test.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Running the chat: guest sessions, accounts, rooms, private messages, images, voice notes, webcam relay, profiles, contacts, block and mute | Guest and member data, content, technical data | Contract, Article 6(1)(b) |
| Selling and managing ChatNow Premium | Account data, transaction records | Contract, Article 6(1)(b) |
| Keeping tax and accounting records for Premium sales | Transaction records | Legal obligation, Article 6(1)(c) |
| Age assurance before access to any room, message, image or webcam | Yes/no result, age-check session token | Legal obligation, Article 6(1)(c): duties under Part 3 of the Online Safety Act 2023 |
| Moderating content, handling reports, complaints and appeals, and enforcing the Terms and Community Rules | Content, moderation records, technical data | Legal obligation, Article 6(1)(c): sections 10 and 20 to 21 of the Online Safety Act 2023; and legitimate interests, Article 6(1)(f) |
| Detecting child sexual exploitation and abuse content and reporting it to the National Crime Agency | Images, content, account data, connection logs | Legal obligation, Article 6(1)(c): section 66 of the Online Safety Act 2023 and the Online Safety (CSEA Content Reporting by Regulated User-to-User Service Providers) Regulations 2026; and recognised legitimate interest, Article 6(1)(ea) |
| Security, spam and fraud prevention: rate limiting, flood and duplicate detection, VPN and proxy detection, one session per account, enforcing bans by account, IP address and device | Technical data, ban records | Legitimate interests, Article 6(1)(f); where the conduct is criminal, recognised legitimate interest, Article 6(1)(ea) |
| Responding to valid requests from law enforcement, courts and regulators | Whatever the request lawfully covers | Legal obligation, Article 6(1)(c); recognised legitimate interest, Article 6(1)(ea) |
| Answering your emails and support requests | Correspondence, account data | Contract, Article 6(1)(b), or legitimate interests, Article 6(1)(f) |
| Improving the service using aggregate statistics that do not identify you | Technical data, usage counts | Legitimate interests, Article 6(1)(f) |
| Analytics cookies (Google Analytics 4) and advertising cookies | Cookie identifiers, pages visited | Consent, Article 6(1)(a), and regulation 6 of PECR |
| Marketing emails to members who have opted in | Email address | Consent, Article 6(1)(a), and regulation 22 of PECR |
| Establishing, exercising or defending legal claims | Whatever is relevant to the claim | Legitimate interests, Article 6(1)(f) |
4.1 Our legitimate interests
Where the table relies on legitimate interests, the interests are: keeping the service, its network and its users secure; preventing spam, fraud and abuse; making sure a person who has been banned cannot simply return; enforcing our Terms of Service and Community Rules so that the rooms remain usable; answering the people who write to us; understanding, in aggregate, how the service is used so that we can improve it; and protecting our legal position. We have balanced each of these against your interests and rights: the processing uses the minimum data, for limited periods, and users of a public chat reasonably expect it to be moderated and protected against abuse. You can object to any processing based on legitimate interests (section 11).
Providing the data marked as required in section 3 is a condition of using the service. Everything else, including the profile bio, gallery photos and Premium, is optional.
5. Special category data and your explicit consent
Some of what you share on ChatNow is special category data under Article 9 of the UK GDPR. Choosing "Trans" or "CD" in the gender field is information about gender identity, which we treat with the same care as special category data. Joining a room set aside for adult or sexual conversation, or describing your preferences in a profile or message, reveals information about your sex life or sexual orientation.
We process this data on the basis of your explicit consent, Article 9(2)(a). Consent is given by a clearly worded affirmative step at the point of collection: a separate confirmation you click when you select "Trans" or "CD", and a separate confirmation you click the first time you enter an adult-themed room. Nothing is pre-selected. Without that step the field stays blank and the room stays closed to you; the rest of the service remains available.
You can withdraw consent at any time by changing the gender field, leaving the room, or, as a member, deleting the field in your settings. Withdrawal takes effect immediately for future processing and does not affect the lawfulness of processing before it. Free-text messages and voice notes may also contain data about your health, beliefs or sexuality; we process such content only to transmit, store and moderate it, because you have chosen to share it. When our moderators or automated tools review content that contains special category data in order to protect other users or prevent unlawful acts, we rely in addition on the substantial public interest conditions in Schedule 1 to the Data Protection Act 2018.
Special category data is never used to build advertising profiles, never shared with advertising partners, and never used to take automated decisions about you.
6. Moderation, safety and automated decisions
ChatNow is a regulated user-to-user service under the Online Safety Act 2023. To meet our duties and keep the rooms safe, we moderate content in the following ways.
6.1 Human review
Human moderators and administrators are present in the rooms daily. They review reported content, including reported private messages, images and voice notes, and are on call around the clock for intimate-image and child-safety reports. Access to moderation tools is restricted and logged.
6.2 Automated tools
- Text classifier. The text of public and private messages is analysed asynchronously by an AI classifier run through the OpenAI API (model GPT-4o-mini) for illegal content and breaches of our rules. Only the message text is sent; your email address, IP address and username are never sent. Content flagged as prohibited is removed automatically and the removal is logged. Profile bios are checked by the same classifier before they go live.
- Image hash-matching. Every uploaded image is converted into a digital fingerprint (a hash) and compared with the hash lists of known child sexual abuse material held by Project Arachnid (Canadian Centre for Child Protection) and of intimate images registered with StopNCII.org.
- Anti-spam rules. Duplicate and flood detection, cross-room spam detection, banned-word lists, rate limiting, VPN and proxy detection and a one-session-per-account rule operate automatically.
6.3 Consequences
Depending on the breach, we may remove the content, mute you temporarily, reduce the visibility of your messages for a limited time, suspend or permanently ban you by account, IP address and device, or terminate your account. A match against known child sexual abuse material results in an immediate permanent ban, preservation of evidence and a report to the National Crime Agency (section 14).
6.4 Automated decisions and your right to human review
Automatic removal of a flagged message and temporary anti-spam measures such as a short mute or rate limit are applied without a human looking first. No permanent ban is ever applied on a purely automated basis without human review. Every moderation decision is notified to you with the reason, the rule or law relied on, whether automation was involved and how to appeal. You have the right to ask for a human to review any automated outcome, to put your point of view and to contest the decision, as provided by Articles 22A to 22D of the UK GDPR; appeals are decided within 14 days by a different human reviewer through our Complaints & Appeals procedure. We do not take solely automated decisions with significant effects on the basis of special category data.
7. Who we share your data with
We do not sell personal data. We share it only with the organisations below, each of which is bound by contract or by law to use it solely for the stated purpose.
| Recipient | Role and data received | Country | Transfer safeguard |
|---|---|---|---|
| Contabo GmbH, Aschauer Straße 32a, 81549 München | Processor. Hosts the chat platform and all stored user data | Germany | UK adequacy regulations (EEA) |
| Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen | Processor. Serves the website pages; sees IP addresses in server logs | Germany | UK adequacy regulations (EEA) |
| AgeVerif | Independent age-assurance provider. Receives the data you choose to give it for the check; returns only a yes/no result and does not learn which site you are visiting | Europe | UK adequacy regulations (EEA) |
| OpenAI, L.L.C. | Processor. Automated text classification; receives message text only | USA | UK Extension to the EU-US Data Privacy Framework; IDTA where a service is not covered |
| Canadian Centre for Child Protection (Project Arachnid) | Hash-matching of uploaded images against known child sexual abuse material; receives image hashes | Canada | UK adequacy regulations (Canada) |
| Google LLC | Optional sign-in with Google (independent controller for your Google account); Google Analytics 4 in aggregate mode with IP anonymisation, only after your consent | USA | UK Extension to the EU-US Data Privacy Framework |
| Resend, Inc. | Processor. Sends transactional emails (sign-in links, confirmations, moderation notices); receives your email address and the message | USA | UK Extension to the EU-US Data Privacy Framework; IDTA where a service is not covered |
| Cloudflare, Inc. | Processor. Bot-protection challenge and DDoS protection; sees IP addresses and connection metadata | USA | UK Extension to the EU-US Data Privacy Framework |
| Stripe Payments Europe, Ltd. and Stripe, Inc. | PCI-DSS certified payment processor for Premium; independent controller for card data. ChatNow never receives card numbers | Ireland / United States | UK adequacy regulations (Ireland); UK Extension to the EU-US Data Privacy Framework (United States) |
| National Crime Agency, UK police forces, courts and regulators | Recipients under a legal obligation or a valid legal request (section 14) | United Kingdom | Not applicable |
| Internet Watch Foundation; StopNCII.org | Image hashes only, for matching and, where relevant, reporting | United Kingdom | Not applicable |
Advertising partners. Third-party advertising partners may set cookies on chat-now.uk only after you have consented in the cookie banner. They receive only what their cookies collect, as described in our Cookie Policy; they never receive your messages, profile fields, age-check result or special category data. The current list of partners is in the cookie preference centre, reachable from the "Cookie settings" link in the footer of every page.
8. International transfers
Your data is stored on servers in Germany. Transfers to Germany and to the rest of the European Economic Area, and to Canada, are covered by the UK adequacy regulations made under section 17A of the Data Protection Act 2018, so no further safeguard is needed.
Transfers to our processors in the United States (OpenAI, Google, Resend and Cloudflare) rely on the UK Extension to the EU-US Data Privacy Framework, also called the UK-US data bridge. Before relying on it we check that the recipient holds an active certification covering the UK Extension and the type of data involved. Where a particular service is not covered by that certification, we use the ICO's International Data Transfer Agreement (IDTA), or the UK Addendum to the EU standard contractual clauses, together with a transfer risk assessment. Because chat content may reveal sexual orientation, we have told these processors that the data may include sensitive information that must be treated accordingly.
Skyline Online LLC is itself established in the United States, and its staff access the systems in Germany under the access controls described in section 10. Wherever your data is accessed from, you keep the same rights under the UK GDPR. You can obtain a copy of the safeguards we rely on by emailing privacy@chatnow.fr.
9. How long we keep your data
We keep personal data only for as long as the purpose requires, and we have documented a retention schedule that we review regularly. The periods below are the periods we apply; the CSEA and tax periods are fixed by law.
| Data | Kept for | Why |
|---|---|---|
| Guest session data and content (username, gender, age, city, messages, images, voice notes) | 24 hours after the guest leaves, then deleted automatically | Long enough to act on a report about the session |
| Member content (messages, photos, voice notes, bio, contacts) | Until you delete it or delete your account; anonymised within 30 days of account deletion | Providing the service you asked for |
| Account data (email, password hash, date of birth, gender) | Life of the account; deleted or anonymised within 30 days of deletion | Running your account |
| Connection logs (IP address, timestamps, device identifier) | 12 months | Security, abuse investigation and the ability to include the three months of login IP addresses that a CSEA report must contain |
| Moderation records (reports, decisions, appeals, evidence snapshots) | 12 months | Handling appeals and repeat behaviour; evidencing Online Safety Act compliance |
| Ban records (account, IP address, device identifier) | 12 months; 3 years for permanent bans | Enforcing the ban |
| Reports of child sexual exploitation and abuse content to the NCA | Report reference: 5 years. Reported content and associated data: 12 months | The 2026 Regulations (statutory) |
| Age-check result | Current session only | Re-checked at each new session |
| Premium transaction records | 6 years | HMRC record-keeping requirements |
| Support correspondence, rights requests and complaints | 24 months | Following up and evidencing how we handled the matter |
| Cookie preference choice | 6 months | Remembering your choice, then asking again |
Where data is needed for a legal claim that has been raised, or is subject to a lawful preservation request from an authority, we keep it until the matter is closed and then delete it.
10. How we protect your data
All connections use TLS encryption. Passwords are stored as PBKDF2-SHA512 hashes. We validate all input, apply rate limiting, allow one session per account, and restrict and log every use of the moderator and administrator tools. Webcam streams are relayed, not stored. Payment card data never reaches our systems. If a personal data breach is likely to result in a risk to your rights and freedoms, we notify the ICO within 72 hours of becoming aware of it and, where the risk is high, we tell you directly. Security researchers can report vulnerabilities to security@chatnow.fr; see Security & Responsible Disclosure.
11. Your rights
Under the UK GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify data that is inaccurate or incomplete;
- erase your data; members can delete their account themselves from account settings;
- restrict processing while a dispute is resolved;
- portability: receive the data you gave us in a machine-readable format;
- object to processing based on legitimate interests, and to direct marketing at any time;
- human review of any automated moderation outcome, and to contest it;
- withdraw consent at any time, including consent to cookies and to the processing of special category data.
Requests are free and are answered within one month, extendable by two further months for complex requests. Email privacy@chatnow.fr. The Your Data Rights page explains each right, how we verify that a request comes from you, and what we cannot do (for example, after 24 hours we hold nothing that links a guest username to a person, other than connection logs and any moderation record about the session, which are kept for 12 months).
12. Children
ChatNow is for adults aged 18 or over and is not directed at children. Every visitor, guest or member, must pass the highly effective age check described in section 3.6 before any room, private message, image or webcam is accessible; self-declaration, tick-boxes and warnings are never treated as age assurance. We do not knowingly collect personal data from anyone under 18. If we discover that a session or account belongs to a minor, we terminate it and erase its data, subject only to any legal obligation to preserve evidence. If you believe a user is under 18, email safety@chatnow.fr. See our Age Assurance Policy and Child Safety & Safeguarding page.
13. Cookies and similar technologies
We use five strictly necessary cookies (session, device identifier, cookie-consent choice, age-check session token and the Cloudflare bot-protection challenge cookie) that need no consent, and, only if you accept them, analytics cookies (Google Analytics 4) and advertising cookies from third-party partners. "Reject" is as easy as "Accept", and the "Cookie settings" link in the footer of every page lets you change your choice at any time. The full list is in our Cookie Policy.
14. Disclosures to law enforcement and the CSEA reporting duty
We disclose personal data to the National Crime Agency, police forces, courts and regulators when we are legally required to do so, in response to a valid legal demand, or where disclosure is necessary to respond to an emergency involving a risk to life. Requests from authorities go to legal@chatnow.fr and are checked for validity and scope before anything is released. Our Law Enforcement & Authorities Guidelines describe the process and the data we are able to provide.
Child sexual exploitation and abuse (CSEA) content. Under section 66 of the Online Safety Act 2023 and the 2026 Regulations, in force since 7 April 2026, we must report all CSEA content we detect to the National Crime Agency through its CSEA Industry Reporting Portal. A report contains the content, how and when it was detected, the IP address and port used, the hash value, and the account data we hold, including the registration and login IP addresses for the previous three months. We keep the NCA report reference for five years and the reported content and associated data for twelve months, as the 2026 Regulations require. Where relevant we also report to the Internet Watch Foundation. These disclosures are made on the basis of legal obligation and the recognised legitimate interest in safeguarding and crime detection; your rights to object and to erasure do not apply to them.
15. How to complain
15.1 To us
Section 103 of the Data (Use and Access) Act 2025, in force since 19 June 2026, gives you a statutory right to complain to us about how we handle your personal data. Email privacy@chatnow.fr with the subject line "Data protection complaint", or write to the registered office. We acknowledge every complaint within 30 days of receipt, investigate it, keep you informed of progress and give you a written outcome without undue delay. Complaints about a moderation decision follow the separate Complaints & Appeals procedure.
15.2 To the Information Commissioner's Office
You can complain to the ICO at any time, although it generally expects you to have raised the matter with us first:
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
https://ico.org.uk/make-a-complaint/
You also have the right to seek a remedy through the courts.
16. Notices shown at the point of collection
This policy is complemented by short "just-in-time" notices displayed at the moment your data is collected, each linking to the relevant section of this policy.
- Guest entry form. Explains that your username, gender, age and city are shown to other users, that your IP address and device identifier are logged for 12 months for security, that messages are moderated by humans and automated tools, that webcam streams are not recorded by ChatNow, and that guest data is deleted 24 hours after you leave.
- Sign-up form. Explains what your email address is used for (sign-in, security and moderation notices, and marketing only if you opt in), that your password is stored as a hash, and why we ask for your date of birth.
- Gender field and adult rooms. Presents the separate explicit-consent confirmation described in section 5 before "Trans" or "CD" is saved or an adult-themed room is opened.
- First webcam or voice use. States who can see or hear the stream, that ChatNow does not record or store it, that other participants may capture it, and where the report button is.
- Photo upload. States who will see the image, that it is hash-matched against known child sexual abuse material and StopNCII.org hashes and may be reviewed by moderators, and how long it is kept (24 hours after a guest leaves; until deleted for members).
17. Changes to this policy
This is version 1.0 of the Privacy Policy, effective 22 September 2026. We review it at least once a year and whenever the service or the law changes; the "Last reviewed" date at the top is updated each time. If we intend to use your data for a new purpose, we will update this policy and bring the change to your attention before the new processing starts, by email to members and by a notice at guest entry. Earlier versions and a summary of what changed are kept on the Legal Documents Version History page.