Privacy Policy

MixTalk · Version 2026-10-08 · Updated 2026-10-08

1. What this policy covers

MixTalk ("the app") is a cross-language chat and language-partner social app. This policy states item by item what we actually collect, why, which third parties receive it, how long we keep it, and how you can turn it off. This policy ships with the app and matches the version shown in the app.

2. Account and profile data

Account data: email address and phone number; if you sign in with Apple or Google, also the account identifier and (where you allow it) the email address returned by that platform; if you sign in with Apple, also a token our server obtains from Apple, kept only so that we can revoke your Sign in with Apple authorization when you delete your account (section 16). Profile data: nickname (if you sign in with Google, or sign in with Apple and choose to share your name, the name that platform returns may be used as the nickname; otherwise, until you set one, a neutral default such as "MixTalk1234" — we never use your email address or phone number as a nickname), avatar, gender, date of birth, country, city, native and learning languages, speaking and writing levels, usual active hours, bio, phone-verification status and notes; your phone's system language (to choose the interface and translation language); and your Assistant reply-style settings (including any note you write yourself). Match: the people you like or pass on in Match and your mutual matches, used to show you new people and your matches. Social connections: the people you follow, your followers and your block list. Used to create and sign in to your account, display your profile, and match language partners. Kept until you delete your account.

3. Content you send

Your one-to-one messages, group messages, voice messages, images and videos, moments and comments, and text messages posted in voice rooms are stored on our servers so they can be delivered to the recipient and shown as history on your devices. Before photos and videos you send in chats and moments are stored, our servers remove the location metadata embedded in them (such as the GPS tags a camera adds). Photos in a format our servers cannot re-encode (for example HEIC sent by older app versions) are stored as received. After you delete a message or view-once item in the app, it is no longer shown in either party's chat; whether the server immediately destroys the original depends on whether the conversation involves a user in China, as explained in section 18. Apart from the features you actively trigger (see sections 8, 9 and 10), one-to-one chat passes through a single prohibited-content rule match before delivery. That match runs entirely on our own servers, is not sent to any third party, and keeps no intermediate data. Staff review: when a user reports a message, account or conversation, authorised staff review the reported content and the context needed to decide whether to remove content, mute or suspend an account. Before staff can view any user's one-to-one or group messages, a case must be recorded (a report review or a lawful request from an authority) together with a reason, and every view is logged with the staff member, the time, the case and the account viewed. Word book: when you look up a word from a one-to-one or group message and save it to your word book, we store, along with the word and its meanings, the chat sentence it came from and its translation, the nickname of whoever wrote it and the message time, so review cards can remind you where you saw it. This stays in your own word book, is visible only to you and is not sent to any third party. The sentence follows the original message: when a message is deleted for both sides, a conversation is cleared, group messages are deleted or cleared, a group is dissolved, or the person who wrote it deletes their account, we remove that sentence, its translation and the writer's nickname from everyone's word books, while the saved word itself stays. Deleting a message only on your own side does not affect the word book. You can also remove the word from your word book at any time. If you delete your account, your whole word book is deleted.

4. Location: what we collect and when

We collect a coarse latitude and longitude, rounded to roughly one kilometre, plus the city and country name derived from them and the time of collection. In current versions of the app (iOS, and Android build 1059 or later) the rounding happens on your phone: our servers, the reverse-geocoding service and map services only ever receive the rounded coordinates, and the full-precision GPS reading never leaves the device; our servers also store only the rounded value. There are only two triggers, and both require you to tap: (a) you tap "Update location" on your profile page; (b) you choose to send a location from the "+" panel in a chat. The system permission prompt always comes first and you can decline. Declining does not affect chat, matching or other core features.

5. Location: how it is used and what others see

Your rounded coordinates are kept on our servers; other users see these coordinates only as the map pin and bucketed distance described below, and the city and country on your profile are shown according to your privacy settings. We use them for three things: to derive the city and country shown on your profile; to display a map pin on your profile whose coordinates have been rounded to two decimal places (roughly a 1 km grid square); and to weight the "nearby" list and recommendation ranking by straight-line distance, where the distance other users see is bucketed (under 1 km shows as <1km, up to 10 km keeps one decimal, beyond that it is rounded to whole kilometres). For your profile we keep only the most recent fix; a new fix overwrites the old one, and it is deleted when you delete your account. A location you send in a chat is a message: the other person sees its coordinates (rounded to about 1 km before sending in current versions; versions from before mid-August 2026 sent them unrounded) and its city or country, and it is kept and deleted like your other messages (sections 3 and 18).

6. Location: how to turn it off

You can decline or revoke the app's location permission in your device settings. In the app's privacy settings you can also turn off "Show country/region" or "Show city", which hides that information from other users, including in the header of your profile map and in same-city or same-country matching; and you can turn on "Hide profile location map", which removes the map pin from your profile and stops your location being used for the Nearby list, distance labels and distance ranking. If you have never shared a location, your profile shows an approximate pin based on your city and country only while both are shown.

7. Geocoding and map services (third parties, some outside your country)

Turning coordinates into a city name is done by the BigDataCloud reverse-geocoding endpoint (api.bigdatacloud.net). The request is made directly by your device, so that provider receives the rounded coordinates, your interface language and your IP address; BigDataCloud may also use that pairing of coordinates and IP address, without identifying you, to improve its IP-geolocation data. The map image at the top of a profile is produced by Yandex Static Maps (static-maps.yandex.ru, operated from Russia): every time you open a user's profile, your device requests a map image centred on that user's rounded coordinates, so the provider receives those rounded coordinates and your IP address. If it fails to load, an OpenStreetMap (openstreetmap.org) embed is used as a fallback. When you open the full-screen map or tap "open in maps": on iPhone the built-in Apple Maps is used; on Android and the web, Baidu Maps is used when the viewer is in mainland China, Yandex Maps in CIS countries, and Google Maps otherwise, and that provider receives the rounded coordinates of the location and your IP address. These map and geocoding services are public endpoints that your device contacts directly; we have no separate data-protection agreement with them and cannot guarantee their level of protection. They process data under their own privacy policies.

8. Third-party AI services: what is sent, to whom, and your consent

Several features are powered by third-party AI services. Before any of your content is sent to these providers for the first time, the app shows a notice that lists what is sent and to whom; nothing is sent unless you tap "Agree and continue", and you can review or withdraw this at any time in Me → tap your profile card → Settings → AI features & data. We record on our server the version of this notice you agreed to and the time you agreed, so that our server can check it before anything is sent to these providers; when you withdraw, that record is cleared and we keep the time of your withdrawal, so that up-to-date versions of the app ask you again instead of restoring your earlier agreement; a device on which you agreed earlier can still record your agreement again the next time you use an AI feature there, so withdraw on each device you use; these records are deleted when you delete your account. What is sent, by feature: (a) Text translation — message translation, translate-on-send (once it is on, drafts are translated in advance while you type), translation of moments and comments, the Assistant's translate mode, and typed text in face-to-face translation: the text being translated and the target language. (b) Grammar check on moments and AI writing help: the text you enter; writing help also includes the last few text messages of that conversation, your reply-style note if you wrote one, and, only if you turn on "Write like I usually do", a sample of your own recent sent messages as style examples. (c) Assistant chat: your message and the recent turns of that Assistant conversation, plus your nickname, city, country, native language and, if you set one, your reply-style note, so replies fit you. If you ask about the weather, your city or country name (or rounded coordinates) is sent to the Open-Meteo weather service (open-meteo.com), which is not an AI service. (d) Images and files: the image or document you add in the Assistant, and an image in a chat that you choose to translate, to read and translate its text. (e) Voice: see section 9. (f) Read-aloud: see section 10. (g) Companions: see section 11. (h) Dictionary: the word or phrase you look up and the language pair, to generate a summary, modern meanings and example sentences; for "Ask AI", the word, your question and the last few follow-ups about that word. (i) Profile photos and photos in moments: before a photo you choose as your profile picture or add to a moment is posted, it is sent to the Volcengine Ark vision model for an image safety check (whether it contains sexual, violent or other prohibited content); if you have not agreed, you cannot add such photos, and text-only moments are not affected. Content you send to others: the people you chat with can choose to use these features on what you send them — translating your messages, moments or comments, translating an image you sent them, or using AI writing help, which includes the last few text messages of that conversation. In that case your content is sent to the providers below on the basis of their agreement, not yours. Who receives it: text translation goes to DeepSeek (api.deepseek.com, operated by Hangzhou DeepSeek Artificial Intelligence Basic Technology Research Co., Ltd., China), and automatically to Volcengine Ark (ark.cn-beijing.volces.com, operated by ByteDance, servers in Beijing, China) if DeepSeek fails or returns an unusable result; if our server is configured to use Doubao first, the order is reversed (Volcengine Ark first, DeepSeek if that fails). Grammar check, writing help, Assistant chat, images (including an image in a chat that you choose to translate), and the photo safety check in (i) go to Volcengine Ark (Doubao models). The text of a document (PDF or text file) you add in the Assistant is extracted on our server and translated like other text: DeepSeek first and Volcengine Ark if that fails, or the reverse order as described above. Assistant Search: when an answer needs current information, Volcengine Ark uses your question to search the web, and the source pages are listed under the answer. Dictionary summaries, meanings and examples go to DeepSeek first and to Volcengine Ark if that fails; "Ask AI" goes to Volcengine Ark first and to DeepSeek if that fails. AI-generated dictionary content is labelled "AI-generated" and cached as a dictionary entry so other users looking up the same word can reuse it; the cache contains no account information. We never send your email address, phone number, password or precise location to these providers, and content you do not choose to process is not sent. Use: only to produce the result you requested; it is not sold, not used for advertising, and not used to train models of our own. Protection: apart from the map and geocoding services in section 7, Google's avatar image servers in section 16, and the public STUN servers in section 18 (which your device contacts directly) and the Open-Meteo weather service in (c) (which our server contacts as a public service, without an account, sending only your city or country name, or rounded coordinates) — with which we have no separate agreement and which process data under their own privacy policies — the third parties with whom we share this data provide the same or equal protection of that data as described in this policy.

9. Voice transcription and translated voice messages (third-party AI provider)

When you send a voice message with the translate-on-send switch on, or record voice in the Assistant (including face-to-face translation), the recording is sent to Volcengine (operated by ByteDance, servers in Beijing, China): while you are still recording, the audio is streamed to Volcengine speech recognition (openspeech.bytedance.com) so the text is ready sooner; the recording may also be transcoded to mp3 and sent to the Volcengine Ark audio model to detect the language, transcribe it word for word and translate it. The transcript is translated as described in section 8 (DeepSeek, with Volcengine Ark as a fallback). The result is written back to that message and shown to you and to the recipient (in the Assistant and face-to-face translation, only to you; face-to-face translations can be read aloud as described in section 10). Because the audio is streamed while you record, a recording you then cancel has already been sent up to that point; at most the first 61 seconds of a recording are sent. Each speech request carries an identifier that we generate from your account with a secret key; the provider cannot trace it back to your account. Voice messages sent with the switch off are not sent to these providers.

10. Tap-to-speak cloud fallback (third-party speech synthesis)

When you tap text in chat to hear it spoken, we first use the speech engine already on your phone; that text does not leave the device. Only if the system has no voice for that language, the engine fails to start, or the language is Uzbek or Kazakh (these two are always sent, even if your phone has a voice for them) do we send the tapped line (at most 4,000 characters) to a speech-synthesis service: Arabic, Uzbek and Kazakh go to Microsoft Azure Speech (*.tts.speech.microsoft.com, operated by Microsoft); all other languages, and these three if Azure is not set up on our server, go to Volcengine Doubao speech synthesis (openspeech.bytedance.com, operated by ByteDance, servers in Beijing, China). This is not the same product as the Volcengine Ark chat/audio models in sections 8 and 9. If you turn on "Read aloud" in face-to-face translation, translations in a language your phone has no voice for (and in Uzbek and Kazakh always) are synthesised the same way automatically, without a tap. Apart from that, text you do not tap, and text the system can already speak (other than Uzbek and Kazakh), is not sent. We do not keep a long-term library of the synthesised audio.

11. Writing assistance and companion pets (third-party AI provider)

Text you enter into grammar-correction and writing-assistance features is sent to the same provider. Profile photos and moment photos go through the safety check described in section 8 (i). When you choose a photo to create or redraw a MixTalk companion, that photo is first sent to the Volcengine Ark vision model for a safety check (whether it contains sexual, violent or identity-document content; if it does, nothing is generated), and then to the Volcengine Ark Seedream image model (ark.cn-beijing.volces.com, operated by ByteDance, servers in Beijing, China) to generate a 3D collectible-figure style multi-frame image; if the generation fails, the point is returned. When you have new clothes drawn for a companion, draw a family portrait or make a "Walk together" animation, the companions' existing images are sent to the same image model. Short companion animations (walking, family portraits) are made by the Volcengine Ark Seedance video model from the companion images that were already generated, never from your original photo. We send only what those features need, and only after asking for your consent as described in section 8; these providers (Volcengine Ark) give that data the same or equal protection as described in this policy.

12. Group content warnings

One-to-one chats, group chats, moments, voice-room text messages, and profile fields such as nickname and bio are all matched against prohibited-content keyword rules: matching content is rejected outright. In groups with 6 or more members, weaker adult-content signals additionally raise a warning. These text checks run entirely on our own servers and are not sent to any third party; photos used as profile pictures or in moments are checked as described in section 8 (i).

13. Screenshot and screen-recording alerts

In one-to-one chat and group chat, if we detect that your device took a screenshot or started a screen recording, we send the other party (or the other group members) an alert containing your nickname and the time. This applies to every user, including to you.

14. Profile visitors and online status

When you open another user's profile, we record a visit (for the same pair of users, a repeat visit within 2 minutes only updates the timestamp and is not counted again). That user can see your avatar, nickname and visit time in their visitor list. Nothing is recorded between users who have blocked each other. Your online status and last-active time are also shown to others and can be turned off in privacy settings. Visitor records are deleted when you delete your account.

15. Device, log and usage data

Push identifiers: the device token issued by Apple Push Notification service (APNs) or Google Firebase Cloud Messaging (FCM), used to deliver notifications; notification content (the sender's name and a preview of the message) passes through the corresponding platform (Apple or Google). Device identifier: the app generates a random string locally for statistics and to limit duplicate registrations and verification-code requests; it changes if you reinstall. Network and security logs: your IP address is recorded when you register or request an SMS code, for anti-abuse and rate limiting; each time you sign in we record the IP address, device model, app version and install channel, kept for 90 days, to protect your account and investigate abuse. Server logs: our server's operating logs may contain your IP address and account ID and are kept for at most 90 days; entries written before October 7, 2026 may also contain your phone number or email address, and those entries will be deleted by November 1, 2026. Usage statistics: sign-in method taps and successes, registration, sending a first message (without recording who it was sent to), next-day return, app start-up language loading (language and load time), kept for 180 days; crash and front-end error reports, kept for 90 days. Search records: when you search for a user by MixTalk ID, we record the search term and the time, only to prevent harassment and abuse; these records are deleted automatically after 30 days. For the sign-in records, error reports, usage statistics and ID search records described in this section, the scheduled deletion is paused while an investigation or complaint freeze (see section 18) applies to them, and resumes when the freeze ends. All of this is stored on our own servers; the app contains no third-party analytics or advertising SDK.

16. SMS, email, third-party sign-in and QR codes

SMS verification codes are sent through Twilio, which receives your phone number and the code. Email verification codes (registration, sign-in and adding an email address) are sent first through the email provider Resend (api.resend.com), which receives your email address and the code; if Resend fails, the code is sent instead through our Tencent QQ Mail SMTP account (operated by Tencent, China), which then also receives your email address and the code. The code, together with the email address or phone number it was sent to, is stored on our server only to check it, and is deleted one day after it expires. When you sign in with Apple or Google, our server checks your sign-in credential with that platform (appleid.apple.com, oauth2.googleapis.com) and receives the account identifier and email address it contains (and, from Google, your name). Some users who signed in with Google have avatars stored on Google's image servers; to show such an avatar, the viewer's device loads it directly from Google (lh3.googleusercontent.com), which sees that device's IP address. For Sign in with Apple, our server also exchanges the one-time authorization code with Apple for a token, kept only so that we can revoke your Sign in with Apple authorization when you delete your account, and deleted then. If you buy a VIP subscription or a points pack in the app, the app store you downloaded MixTalk from processes the payment; we only receive the purchase receipt, transaction identifier and expiry needed to turn VIP on or add the points, never your card number. Your "My QR code" is generated on your device; its content is not sent to any third party.

17. Sensitive personal information

We do not collect identity documents, passports, education or income proofs, and we do not offer identity verification; the "phone verified" mark on a profile only means the phone number passed SMS verification.

18. Storage, cross-border transfer and retention

Where data is stored: our main server is in Singapore. Account and profile data, messages, moments and the other records described in this policy are kept in its database. Uploaded photos, videos and voice messages are stored on that server and in Cloudflare R2 object storage (operated by Cloudflare, Inc., United States, on its global network), from which they are delivered to the app. Connections between the app and our server normally pass through Cloudflare's network. Calls: to connect a voice or video call, your device contacts public STUN servers operated by Google, Cloudflare, Tencent and Xiaomi, which see your IP address; when a direct connection is not possible, the encrypted call audio and video are relayed through our own relay servers (in Singapore, and in Beijing for users in mainland China or when a user's country cannot be determined), which do not record it; in a direct connection the other person's device can see your IP address. Voice rooms: people on the mic connect in the same peer-to-peer way with everyone else in the room (other people on the mic and listeners; listeners do not connect to each other), so in a direct connection their devices may see each other's IP addresses. We do not copy your messages or files to any server or storage service in mainland China; our servers in mainland China only provide a call relay and a website. Because our servers and the providers listed in sections 7, 8, 9, 10, 11, 15, 16 and this section are located in Singapore, mainland China, Russia, the United States and elsewhere, the relevant data is transferred between and processed in those jurisdictions. After you delete or burn an item, both chats stop showing it. If the conversation includes someone who registered or bound a mainland China +86 phone number (Hong Kong +852, Macao +853 and Taiwan +886 do not count) or who installed our Android app from an app store in mainland China (only the Android app reports which store it was installed from), the original text and files are kept on our server for 183 days (about six months), as required by Chinese law, for audit and to comply with lawful requests from authorities; if an investigation or complaint freeze applies, they are not deleted when that period ends. In all other conversations the original text and files are destroyed on the server, leaving only destruction metadata. After a deletion, a burn or account deletion, cached copies of photos and other files in Cloudflare's network are not removed at once; they lapse when the cache expires. Retention periods: for your profile only the most recent location fix is kept (a location sent in a chat is kept like other messages); your dictionary word book (including sentences saved from chats with their translation and the sender's nickname, visible only to you) is kept until you delete it or your account; dictionary lookup counts are kept only as a keyed hash (we do not store the word itself) for at most 30 days, so that looking up the same word again within 30 days does not use up your free lookups again; sign-in records and error reports are kept for 90 days and usage statistics for 180 days (section 15); ID search records for 30 days; purchase receipts (store transaction identifier, product and dates; for Google Play purchases, also the purchase token issued by Google) are kept as financial records for as long as your account exists; after you delete your account they are still kept and are deleted once 3 years have passed since the purchase. Deleting your account immediately deletes, for every account including +86 accounts: your profile and account identifiers (including the Apple or Google account identifier, so the same Apple ID can be used to sign up again); your one-to-one messages on both sides and both chat-list previews; group messages you sent and groups you own; moments, comments, likes, follows, blocks, notes, Match likes and passes, and matches; your word book, review and streak records and lookup counts (chat sentences of yours that others saved to their word books are removed too); companions you created, their images and files, your points and quotas, the companion families you created and the family portraits and walks you made (a companion you gave to someone who accepted it now belongs to them and stays with them); voice room and call records, referral records, visitor records, device tokens, sign-in records, usage statistics and error reports. Your photos, videos and voice messages are deleted from our server and from Cloudflare R2; a photo or video that you forwarded to someone is kept as part of that person's message, so when you delete your account or delete for everyone, a file is deleted only if no other message still uses it. What is kept: purchase receipts (after account deletion, until 3 years after the purchase) as above; records of a subscription moving between accounts (the store transaction identifier, the internal IDs of both accounts and the date of the move), kept as purchase records until 3 years after the move; and reports other users filed about your content, as the record of moderation decisions; the copy of the reported content saved with a report is deleted 30 days after the report has been handled (a report that has not been handled yet keeps its copy until it is handled), also when you delete your account. Backups: to recover from failures, our main server keeps backup copies of its database. Routine copies are deleted automatically: daily copies within 15 days and weekly copies within 5 weeks. Additional copies made during maintenance between July and October 2026 and the daily backups made before October 7, 2026 (on that server), and copies of a July 31, 2026 database kept offline by our developer, are kept only for recovery and will be deleted by November 5, 2026. Until a copy is deleted, it can still contain data that was deleted, or whose retention period ended, after the copy was made; that data is removed when the copy is deleted. Backups are not used for any other purpose.

19. What we do not do

We do not sell your personal information, we do not run advertising targeted using your personal information, and we do not use your chat content to train models of our own. The third-party providers listed in sections 7, 8, 9, 10, 11, 15, 16 and 18 do receive the data described there so that those features can work. Of these, the map and geocoding services in section 7, Google's avatar image servers in section 16 and the public STUN servers in section 18 are contacted directly by your device, and the Open-Meteo weather service in section 8 is contacted by our server as a public service without an account; we have no separate agreement with them, and they process data under their own privacy policies; the other providers give that data the same or equal protection as described in this policy. You can also read their own privacy policies. Before anything is sent to a third-party AI service, the app asks for your consent as described in section 8. Android versions before build 1059 do not have this consent screen. On those versions, until November 15, 2026, the AI features that need consent keep working as before without it: translation, read-aloud, voice recognition and voice translation, the Assistant (including images and files), writing help and grammar check, dictionary AI, and creating, redrawing and dressing companions, family portraits and walking together; the photo you give for a companion is still sent to Volcengine for the safety check and for drawing, and companion images are still sent for drawing outfits, family portraits and walks. During this period, avatars and moment photos uploaded from those versions are not sent to the automatic image safety check; they are reviewed by our staff only when reported. After that date, those versions need to be updated before these features can be used. Until they are updated, Android versions before build 1059 also differ in two ways: when you tap a location button they send the full-precision GPS reading directly to the reverse-geocoding service (BigDataCloud) for that one lookup (our servers store only the rounded value), and they send English text you tap to hear to the cloud speech service in section 10 even when your phone has an English voice. Lawful requests: when a competent authority makes a lawful request (for example a written evidence-collection notice from the police), we provide the relevant account data and records to the extent the law requires; every such request is tied to a recorded case, and each access is logged with the staff member, the time, the account and the reason; we do not disclose data without a lawful basis. Apart from the cases above or with your separate consent, we do not share your personal information with any third party.

20. Your rights and choices

You can view and correct your profile at any time; revoke location, notification, photo library, microphone and camera permissions in your device settings; turn off location display, online status, being searchable and being recommended in the app's privacy settings; and delete your account and data from Settings (an account that is banned or frozen and cannot sign in can be deleted by contacting support). Users in the EU, the UK and other regions have the rights of access, rectification, erasure, restriction of processing, portability and objection, which you can exercise through the contact in section 23.

21. Minors

The app is only for users aged 18 and over; you may not register or use it if you are under 18. When signing up you confirm that you are at least 18, and the birthday or age in your profile cannot be set to under 18. If we find that an existing account belongs to a user under 18: accounts under 16 are suspended; accounts aged 16 or 17 are placed in a "restricted" state. "Restricted" is a protective measure for such accounts and does not mean that people under 18 are allowed to use the app: a restricted account no longer appears in recommendations, nearby, discovery or search by ID, cannot browse strangers, cannot start new conversations with strangers or be added to groups, can only interact with existing contacts (people you have already exchanged private messages with), cannot use voice rooms, and can be deleted by its owner at any time. If a birthday was entered incorrectly, the restricted state is lifted automatically once it is corrected to 18 or over (your "be recommended" and "be searchable" switches are not turned back on automatically; you turn them on again in privacy settings).

22. Policy updates

When this policy changes materially we raise the version number and update the date at the top of this page; the version you accepted when you created your account is recorded with your account. Where the law requires your consent for a change, we ask for it in the app before the change applies to you.

23. Contact us

For any privacy question, contact us by email: [email protected].