Why we built this, and what it means for your data
Effective narrative · 2026-05-11 · Android / Google Play · Controller: CHOW SHEELY LIMITED · Reach us: order@chowsheelyco.com · DPO: Zhang Shilian <dpo@chowsheelyco.com> · Letters: Rm 701, Unit 108, 7/F, Twr B, New Mandarin Plaza, 14 Science Museum Rd, Tsim Sha Tsui, Hong Kong
We wanted a lightweight place for adults to talk face-to-face and in text without forcing yet another password vault. That product bet—no registration, no login—shapes every privacy tradeoff below: we carry less account-shaped data, but we also have fewer obvious keys when someone emails “delete everything about Tuesday.”
We still refuse to fund the product by selling what you say or show.
You open SereneChat from Google Play, accept age and legal surfaces, then tap into a meditation-themed character to chat or start a Voice Call. The OS may flash permission sheets — but only at the three precise moments described below. Bits move through our media fabric and message store. If something breaks, a diagnostic breadcrumb might ping an analytics endpoint. If someone behaves badly, you might open a report sheet. That is the lived timeline this policy tracks.
SereneChat is a small app with three places — and only three — where Android can prompt you for a runtime permission:
android.permission.CAMERA) — fires the first time you tap Profile → Edit portrait → Take Photo to capture a new avatar. Decline and the in-app camera capture is blocked; you can still pick from the gallery.READ_MEDIA_IMAGES on API 33+; READ_EXTERNAL_STORAGE on older Android) — fires the first time you tap Profile → Edit portrait → Choose from Library to pick an existing photo as your avatar. Decline and the gallery picker is closed; in-app capture remains.android.permission.RECORD_AUDIO) — fires the first time you tap AI Voice Call on a character so we can capture your speech for the round-trip conversation. Decline and Voice Call is unavailable; text chat still works.That is the entire list. We do not request gallery-write, contacts, calendar, location, SMS, or call-log permissions for this build.
Technical reality: audiovisual frames exist while the codec path is hot; chat bodies rest in storage policies we tune for delivery and safety; diagnostics aggregate; safety tickets persist when investigations need them; correlators ride along with diagnostics so crash deduplication works.
We do not layer a targeted-advertising marketplace on top of those signals. We do not sell personal and sensitive user data.
No in-app purchase of digital goods in the scope of this notice. No stealth background camera feed “just because.” No repurposing safety screenshots for ad creative.
Flip Android permissions off. Stop using block/report if you do not want those artefacts. Email order@chowsheelyco.com to ask for access, correction, deletion, or portability where law allows. Expect about fifteen business days once we trust the request. Include innocent context (approximate time, device family) because we cannot look up a username—we never issued one.
California: “California Privacy Request” subject. Virginia: sale/ad/profiling opt channels even though we do not model those revenues here. Europe: GDPR rights and SCC-backed transfers—same mailbox coordinates intake.
Eighteen and up, attested once in-app. No document checks.
We change the date and, when the delta is big, we mirror the news beside Terms / Privacy Notice entry points.
Privacy: order@chowsheelyco.com. Formal DP channel: dpo@chowsheelyco.com.
Reports create case files. Moderation may combine automation with humans. Appeals, when offered, re-open the case file—we cannot describe a universal timeline because severity spans pranks to illegal content, but we document internally what we did and why.
Android + optional Play services, RTC stack, moderation HTTP surfaces, analytics SDKs—only as deep as the story above requires.