Skip to main content
Chesly Logo
Chesly
FeaturesFAQG2Plus
Download CheslyDownload
Back to home

Privacy Policy

Last updated: August 19, 2026

This Policy describes how Chesly collects, uses, and shares your information across the Chesly mobile apps, the website at chesly.app, and related services (the "Service").

1. Who we are

Chesly, Inc., a Delaware corporation ("Chesly," "we," "us"), operates a unified messaging inbox that bridges third-party messaging and email providers (such as Slack, WhatsApp, Telegram, Discord, Gmail, Outlook, Messenger, Signal, LinkedIn, Google Chat, Instagram, and X) into a single client. For the GDPR/UK GDPR, Chesly is the controller of personal data described below. Privacy questions: privacy@chesly.app.

2. What we collect

  • Account. A cryptographic identity you control (recovery phrase derived from BIP-39 wordlists), an optional display name, profile picture, and email.
  • Connected providers. When you link a provider, we receive the access tokens, account identifiers, contact lists, group memberships, and message data needed to keep that connection active. Depending on the provider and connection method, this can include browser session cookies, session tokens, or an app-specific password that you enter. Chesly transmits and stores those credentials on its infrastructure while the connection is active. Disconnect the provider in Chesly and revoke the session or app password with the provider to end that access.
  • Messages and content. Messages, attachments, photos, and voice notes you send or receive through the Service.
  • Contacts. If you allow contact access, saved names and contact photos from your device address book are used on that device to label conversations and show people you know. Contact photos stay on your device and are not uploaded. Contact access alone does not upload saved names either. Only if you separately enable the off-by-default Sync Contact Names setting does Chesly encrypt the saved names on your device and upload the encrypted blob so your other devices can show the same labels. Phone identifiers are hashed before they are included in the encrypted payload. We do not use contacts for advertising or share them with the providers you connect.
  • Sender avatar lookup. For email senders, Chesly may send a SHA-256 identifier derived from the normalized sender email to Gravatar and Libravatar to check for a public avatar. Although the raw address is not sent in that request, the identifier can still be associated with an email address and is treated as personal data. For business addresses, Chesly may also use the sender's email domain to request a published BIMI logo or website favicon. These image requests are proxied through Chesly so the app does not expose your device network information to those avatar services. A saved device contact photo, when available, takes priority locally.
  • Precise location — only when you share it. If you send a location message or start sharing live location in a chat, we process your device's precise location to deliver it to that conversation. We never track your location in the background or use it for any other purpose.
  • Device and usage. Device model, OS version, app version, language, timezone, country (derived from IP), crash logs, push notification tokens, IP address, and timestamps.
  • Forms. If you sign up for early access or contact us, we collect the email address, optional name, and message you provide.
  • GIF search. When you open GIF search, Chesly requests trending GIFs from GIPHY. If you type a GIF search, the search terms are sent directly to GIPHY so it can return matching results.
  • Optional Android recovery backup. If you affirmatively choose recovery-phrase backup on Android, Chesly stores the phrase through Google Play services Block Store so it can be restored on another Android device signed in to your Google Account. Chesly enables cloud backup only after Block Store confirms end-to-end encryption is available on that device. You can delete this backup from Chesly's recovery settings or by signing out.

We do not collect browsing history, advertising identifiers, biometric templates, health data, or financial account numbers.

3. How we use it

  • To operate the Service — relaying messages, syncing devices, sending notifications, providing support.
  • To secure the Service — fraud and abuse prevention, rate limiting, incident response.
  • To improve the Service — diagnosing crashes and measuring aggregated usage. We do not profile you for advertising.
  • To comply with the law and enforce our Terms.

Where the GDPR applies, we rely on the performance of our contract with you, our legitimate interests in operating and securing the Service, your consent (where requested), and legal obligations.

4. Optional AI features

Chesly uses OpenAI only when you choose an AI feature or enable Smart Notifications. Before the first use of any of these features, the app identifies all data listed below, explains why it is sent, names OpenAI as the recipient, and asks for one shared permission covering these three features. If Smart Notifications is used first, the complete disclosure appears immediately below its off-by-default toggle and turning that toggle on is the permission action. Otherwise, Translation or Voice Transcription presents the disclosure in an Allow / Not now sheet before the first OpenAI request:

  • Translation: the selected message text and your target language, sent to OpenAI to return a translation.
  • Smart Notifications: each incoming message's text, the sender's display name when available, whether it is a group chat, and any custom notification rules you create, sent to OpenAI to decide which notifications should alert you.
  • Voice transcription: the selected voice-message audio, sent to OpenAI to return a transcript.

OpenAI processes this data to provide the requested result. OpenAI states that API data is not used to train its models. Chesly does not train models on your message content. If permission is not granted, whether by leaving Smart Notifications off or tapping Not now, none of the listed data is sent to OpenAI. You can revoke permission in the app under Settings, Privacy Settings, AI.

5. Sharing

  • Providers you connect — to deliver the messages you send through them.
  • Service providers — companies that host the Service, deliver email or push notifications, process analytics, and provide cloud infrastructure; Google Firebase for Android push delivery and crash diagnostics; Google Block Store for the optional Android recovery backup; GIPHY for trending GIFs and GIF search; and OpenAI for the optional AI features described above, all under written agreements (including SCCs where required). Every service provider with which Chesly shares personal data, including OpenAI, is contractually required to provide the same or equal protection of user data as stated in this Privacy Policy and required by applicable app-store privacy guidelines.
  • Public avatar sources — Gravatar and Libravatar receive the hashed sender identifier described above solely to check for a public avatar; public BIMI and favicon services receive the sender's email domain solely to retrieve a published company image.
  • Legal reasons — when required by law or to protect rights, property, or safety.
  • Business transfers — in a merger, acquisition, or sale of assets.

We do not sell or share personal information for cross-context behavioral advertising.

6. Retention

  • Account and message data: while your account is active.
  • Backups: up to 30 days.
  • Security and abuse logs: up to 12 months.
  • Tax and billing records: up to 7 years where required.

To delete your account at any time, see Delete your account.

7. Your rights

Subject to applicable law, you may access, correct, delete, port, or restrict the processing of your information, and withdraw consent. EEA, UK, and Swiss residents may lodge a complaint with their local data protection authority. California residents have the rights described under the CCPA/CPRA, including the right to know, delete, correct, and limit the use of sensitive personal information; we respect Global Privacy Control signals. To exercise rights, email privacy@chesly.app.

8. International transfers

Personal data may be processed outside your country, including in the United States. Where we transfer data out of the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses or other lawful mechanisms.

9. Children

The Service is not directed to children under 13 (or under 16 where required by law). We do not knowingly collect personal information from children.

10. Security and cookies

We use TLS in transit, encryption at rest, and least-privilege access. No system is 100% secure. The website uses minimal first-party storage (a flag for the early-access gate and an HttpOnly cookie set if your IP is blocked for abuse) and aggregate page-view analytics. No advertising cookies, no third-party trackers. To report a vulnerability, email security@chesly.app.

11. Changes

We may update this Policy. Material changes will be notified in-app or by email. The "Last updated" date reflects the latest revision.

12. Contact

privacy@chesly.app.

Chesly Logo
Chesly

All chats. Less noise.

Product

  • Unified inbox
  • Features
  • Chesly Plus
  • Even Realities G2
  • FAQ
  • Roadmap

Support

  • Help center
  • Contact

Company

  • Vision

Legal

  • Privacy
  • Terms
  • Delete account

© 2026 Chesly, Inc. All rights reserved.

Privacy PolicyTerms of Service