MixTalk ("the app") is a cross-language chat and language-partner social app. This policy states item by item what we actually collect, why, which third parties receive it, how long we keep it, and how you can turn it off. This policy ships with the app and matches the version shown in the app.
Account data: email address, phone number, password hash; if you sign in with Apple, Google or WeChat, also the account identifier and (where you allow it) the email address returned by that platform. Profile data: nickname, avatar, gender, date of birth, country, city, native and learning languages, bio, verification status and notes. Used to create and sign in to your account, display your profile, and match language partners. Kept until you delete your account.
Your one-to-one messages, group messages, voice messages, images and videos, moments and comments, and text messages posted in voice rooms are stored on our servers so they can be delivered to the recipient and shown as history on your devices. Apart from the features you actively trigger (see sections 8 and 9), one-to-one chat is not keyword-scanned and no topics are restricted. Kept until you delete the content or delete your account.
We collect a coarse latitude and longitude, rounded to roughly one kilometre, plus the city and country name derived from them and the time of collection. Your device's full-precision GPS reading is used on your phone only to look up the city name; only the rounded value is uploaded, and we do not store precise coordinates on our servers. There are only two triggers, and both require you to tap: (a) you tap "Update location" on your profile page; (b) you choose to send a location from the "+" panel in a chat. The system permission prompt always comes first and you can decline. Declining does not affect chat, matching or other core features.
Your precise coordinates stay on our servers and are never handed to other users as-is. We use them for three things: to derive the city and country shown on your profile; to display a map pin on your profile whose coordinates have been rounded to two decimal places (roughly a 1 km grid square); and to weight the "nearby" list and recommendation ranking by straight-line distance, where the distance other users see is bucketed (under 1 km shows as <1km, up to 10 km keeps one decimal, beyond that it is rounded to whole kilometres). We keep only the most recent fix; a new fix overwrites the old one, and it is deleted when you delete your account.
You can decline or revoke the app's location permission in your device settings. In the app's privacy settings you can also turn off "show location on profile", "show city", "show country" and "auto-update location". With these off, no map pin is shown on your profile and you are not ranked by distance.
Turning coordinates into a city name is done by the BigDataCloud reverse-geocoding endpoint (api.bigdatacloud.net). The request is made directly by your device, so that provider receives your coordinates, your interface language and your IP address. The map image on a profile is produced by Yandex Static Maps (static-maps.yandex.ru, operated from Russia): every time you open a user's profile, your device requests a map image centred on that user's rounded coordinates, so the provider receives those rounded coordinates and your IP address. If the static image fails to load, an OpenStreetMap (openstreetmap.org) embed is used as a fallback. When you tap "open in maps", the app opens Baidu Maps (for users in mainland China or the Chinese interface) or Google Maps (otherwise) with the coordinates in the link. These services process data under their own privacy policies.
When you use message translation, translate-on-send, or translation of moments and comments, the text being translated is sent to DeepSeek (api.deepseek.com); if the server is configured to use Doubao instead, it is sent to Volcengine Ark (ark.cn-beijing.volces.com, operated by ByteDance, servers in Beijing, China). We send only the text to be translated and the target language — never your email, phone number, password or location. Messages you do not translate are not sent anywhere.
When you send a voice message with the translate-on-send switch on, our server transcodes that recording to mp3 and sends it to the Volcengine Ark audio model to detect the language, transcribe it word for word and translate it. The result is written back to that message and shown to you and to the recipient. Voice messages sent with the switch off, and recordings longer than 60 seconds, are not sent to that provider.
Identity documents, passports, education or income proofs that you voluntarily upload are compressed on our server and sent as images to the Volcengine Ark vision model, which judges only whether the material is relevant to the verification type you chose. Text you enter into grammar-correction and writing-assistance features is sent to the same provider. We send only what those features need. How these providers further process and retain data is governed by their own terms and privacy policies; we cannot make promises on their behalf.
In groups with 6 or more members, keyword rules flag clearly pornographic or solicitation signals and show a warning. This check runs entirely on our own servers, is not sent to any third party, and does not delete messages or ban accounts.
In one-to-one chat, group chat and the mutually agreed "trust material exchange" screen, if we detect that your device took a screenshot or started a screen recording, we send the other party (or the other group members) an alert containing your nickname and the time. This applies to every user, including to you.
When you open another user's profile, we record a visit (for the same pair of users, a repeat visit within 2 minutes only updates the timestamp and is not counted again). That user can see your avatar, nickname and visit time in their visitor list. Nothing is recorded between users who have blocked each other. Your online status and last-active time are also shown to others and can be turned off in privacy settings. Visitor records are deleted when you delete your account.
Push identifiers: the device token issued by Apple Push Notification service (APNs) or Google Firebase Cloud Messaging (FCM), used to deliver notifications; notification content passes through the corresponding platform. Device identifier: the app generates a random string locally for statistics and to limit duplicate registrations; it changes if you reinstall. Network and security logs: your IP address is recorded when you register, claim an invitation reward or request an SMS code, for anti-abuse and rate limiting. Usage statistics: sign-in method taps and successes, registration, first message, next-day return, plus crash and front-end error reports. All of this is stored on our own servers; the app contains no third-party analytics or advertising SDK.
SMS verification codes are sent through Aliyun SMS or Twilio, which receive your phone number and the code. When you sign in with Apple, Google or WeChat, the app passes your sign-in credential to that platform for verification (appleid.apple.com, oauth2.googleapis.com, api.weixin.qq.com) and receives the account identifier and email address it returns. When an invitation poster QR code is generated, the invitation link is sent to the QR generation service api.qrserver.com.
Identity documents, passports, education and income proofs are sensitive personal information. Verification is entirely voluntary and we recommend the "lightweight verification" path, which requires no document upload. If you do upload an original document image, it is used for the AI-assisted first pass described in section 10, for our human review, and for the "trust material exchange" when both sides explicitly agree. Document images are never shown publicly, are never used for advertising, and are kept until you delete your account.
Data is stored on servers we rent. Because the providers listed in sections 7, 8, 9, 10 and 15 are located in mainland China, Russia, the United States and elsewhere, the relevant data is transferred between those jurisdictions. Retention: account and profile data, chat and moments content, and document images are kept until you delete your account; only the most recent location fix is kept; visitor records, device tokens and error logs are deleted together with the account. Deleting your account removes your messages, moments, comments, likes, follows, blocks, notes, verification records, voice room and call records, referral records and visitor records.
We do not sell your personal information, we do not run advertising targeted using your personal information, and we do not use your chat content to train models of our own. Please note: the third-party providers listed in sections 7 to 10 and 15 do receive the data described there, and we cannot make commitments about how they use it internally — please read their privacy policies as well.
You can view and correct your profile at any time; revoke location, notification, photo library, microphone and camera permissions in your device settings; turn off location display, online status, being searchable and being recommended in the app's privacy settings; withdraw consent to optional verification; and delete your account and data from Settings. Users in the EU, the UK and other regions have the rights of access, rectification, erasure, restriction of processing, portability and objection, which you can exercise through the contact in section 21.
The app is intended for users aged 16 and over. If we find that a minor has registered without guardian consent, we take steps to delete that account and its data.
When this policy changes materially we raise the version number and ask you to agree again; the version and update date appear at the top of this page.
For any privacy question, contact us through in-app feedback or by email: [email protected].