Privacy Policy — Chat On Mars
Effective date: June 28, 2026 Last updated: June 28, 2026
Who we are
Chat On Mars ("Chat On Mars," "we," "us") is a chat service that uses AI to translate messages in real time, so people who don't share a language can talk — each person reads and writes in their own language. This policy explains what information we handle and why.
Operator: Chat On Mars (based in British Columbia, Canada) Contact: contact@chatonmars.com
The short version
- To translate your messages, your message text is sent to a third-party AI provider (Anthropic). Please don't share sensitive information in chats.
- Guests don't need an account. You can join a room by scanning a QR code or opening a link, choose a display name and a language, and start talking.
- The person who created a room can read its conversation and reset it.
- We keep only what's needed to run the service, and we delete it on the schedules below.
- We measure how the product is used with our own event counts — never your message content, and never to build a profile of you or follow you across sites.
Information we collect
We collect only what's needed to deliver and translate conversations.
Room data. Room id and join code, room name, room kind (temporary "ephemeral" rooms vs. persistent "venue" rooms), and timestamps.
Participant data. The display name and language you choose, a session token stored in your browser to keep you in the room, and presence/activity timestamps. Guests are not required to provide any real identity.
Messages. The text you send, its detected source language, and the AI-generated translations of it. We do not collect message content beyond what's needed to deliver and translate your messages.
Account data (optional — only if you sign in). Your email address, a securely hashed password, and the rooms you own. An account is optional and exists only to keep your owned rooms across devices; guests never need one.
Usage data (product measurement). A small, fixed set of our own product events — that an invite was opened, that someone joined a room, that a message was sent, that a prompt was shown or acted on — each recorded as an event name from a fixed list, a timestamp, sometimes the room it happened in, and sometimes one short label such as the room type. These events never include message content, translations, display names, or email addresses, we do not use them to build a profile of you or to follow you across sites, and they are not shared with any advertising network. See How we measure use of the service.
We do not sell personal information, and we do not use your messages to show you advertising.
How we use information
- To deliver messages to the people in a room in real time.
- To translate messages into the languages people in the room read.
- To generate an AI assistant's replies, in venue rooms that have one attached.
- To create, run, reset, and expire rooms.
- To let account holders manage the rooms they own across devices.
- To keep the service secure, prevent abuse, and enforce rate limits.
How translation works (third-party AI processing)
When you send a message, its text is transmitted to our AI translation provider, Anthropic (www.anthropic.com), to produce translations for the languages present in the room. We use Anthropic's commercial API. Under Anthropic's Commercial Terms, Anthropic does not use the inputs or outputs we send through the API to train its models by default, and we retain ownership of that content. See Anthropic's Commercial Terms and Privacy Center.
AI assistants in venue rooms
A venue that owns a room may attach an AI assistant to it — an assistant that answers a customer's questions from information the venue wrote for it, such as a menu or opening hours.
In a room with an assistant attached, your message text is sent to Anthropic for a second purpose: to work out whether the assistant can answer it and, if it can, to generate that answer. This is generation, not only translation, and it is the only place in the service where message content is sent to a model to produce new content rather than to render existing content in another language. The same Anthropic commercial terms described above apply, including the no-training default.
What the assistant says is a message in the room. It is stored, translated, and deleted on exactly the same schedule as any other message in that room — see How long we keep information below. An assistant's reply is always labelled as coming from an AI, next to the name its owner gave it.
Rooms without an assistant attached are unaffected: their message text is sent for translation only.
To reduce cost and latency, translations are cached (keyed by the source text and the language pair) so that identical text isn't re-translated. Because an entry is keyed by the text itself and shared across rooms, it isn't tied to any one room's lifetime: a cached translation can outlive the messages it came from, and the deletion schedules below don't remove it.
Service providers (sub-processors)
We rely on a small number of providers to run the service. They process data only to provide their service to us:
| Provider | Purpose | Data involved |
|---|---|---|
| Anthropic | AI translation, and AI assistant replies in rooms that have one | Message text + detected language |
| Ably | Real-time message delivery / presence | Messages and presence in transit |
| Neon | Database hosting | Room, participant, message, and account data at rest |
| Vercel | Application hosting / delivery; cookieless analytics on our public pages | Requests to the app; standard server logs; public-page visit and performance events |
Some of these providers may process data on servers outside your country, including the United States. Where required, we rely on appropriate safeguards (such as the providers' standard contractual clauses) for international transfers.
How we measure use of the service
We measure the product in two separate layers. Neither uses advertising, cross-site tracking, or any identifier that follows you between sites.
On our public pages only — the home page and the About, Privacy, and Terms pages — we use Vercel Web Analytics and Vercel Speed Insights to count visits, see which referrers and entry points bring people in, and measure page performance. Both are cookieless: they set no cookies and use no cross-site identifier, and they are never loaded inside a room, on a room poster, in room creation, in the join flow, on your rooms list, or on our admin dashboard — so nothing from this layer can be attached to a room, a conversation, or a participant.
Inside the product we record our own first-party events — the usage data described above. This is how we answer questions like how many people who open an invite go on to join a room and say something, which is the difference between a product being used and merely being visited. Unlike the layer above, this one does run on room pages. What it records is an event, never content: a name from a fixed list, a timestamp, sometimes the room, and sometimes one short label. The invite events deliberately record no room at all, so a scan cannot be linked to the room that produced it, or to any other scan. We report these as aggregate counts over a time window; nothing here identifies you, and nothing links your activity across rooms, devices, or sites.
How long we keep information
Two rules govern message content. When a room ends, its messages and translations are permanently deleted 7 days later. When a conversation is cleared but the room stays in service, they are deleted 48 hours later. Deleting a room removes its content immediately. In every case the room record itself — its code and QR — can outlive its messages.
After a purge we keep a summary of the room: how many people took part, how many messages were sent, which languages were used, and which days it was active. We do not keep the messages themselves, and the summary cannot be used to reconstruct them.
- Temporary (ephemeral) rooms: the room ends after 24 hours of inactivity, with a 7-day hard cap; its content is permanently purged 7 days after that.
- Persistent (venue) rooms: content persists while the room is in service. It is purged 48 hours after the owner resets the room (clears the current conversation), and 7 days after the owner closes it. Idle venue rooms auto-reset after about 2 hours of inactivity to limit exposure between customers. With per-customer session isolation on — the default — each visitor's session is separate and is purged 48 hours after it ends.
- Translation cache: not tied to a room's schedule. A cached translation is keyed by the text and shared across rooms, so it can persist after that room's content is purged.
- Accounts: kept until you delete your account, after which your account data and the rooms you own are removed.
- Usage data: the product events above are counts about the service, not conversation content, so they are not deleted on the message schedules — a purge removes what was said, not the fact that a room was used. We do not currently delete them on a fixed schedule; we keep them only for aggregate reporting on how the product is used.
What the host (room creator) can see
The person who created a room can read the conversation in that room and reset it for the next person. In a venue room used by strangers (e.g. a restaurant table), assume the host — and anyone they let view the room — can see what you send.
Your choices and rights
- Stay anonymous. Guests can use rooms without an account; choose any display name.
- Don't share sensitive information. Because messages are processed by AI and visible to the room host, avoid sending anything you wouldn't want translated or seen.
- Access, correct, or delete. Depending on where you live (e.g. under Canada's PIPEDA and British Columbia's PIPA, the EU/UK GDPR, or California's CCPA/CPRA), you may have the right to access, correct, delete, or port your personal information, and to object to or restrict certain processing. Account holders can delete their account and owned rooms. For other requests, contact us at contact@chatonmars.com and we'll respond as required by applicable law.
- Complaints. EU/UK users may also lodge a complaint with their local data protection authority.
Cookies and local storage
We use a session token stored in your browser to keep you in a room and, if you sign in, to keep you signed in. We don't use third-party advertising or cross-site tracking cookies.
Security
We take reasonable measures to protect information, including hashed passwords, encrypted transport (HTTPS/WSS), and server-only handling of provider API keys. No method of transmission or storage is perfectly secure, so we can't guarantee absolute security.
Children
Chat On Mars is not directed to children under 13, and we don't knowingly collect personal information from them. If you are in the EU/EEA or another region with a higher digital-consent age, you must meet your local minimum age to use the service. If we learn we have collected a child's personal information without the required consent, we will delete it. Venue rooms can be joined by anyone with the QR code; hosts are responsible for how they deploy rooms in their space.
Changes to this policy
We may update this policy as the product evolves. We'll post the new effective date here and, for material changes, provide a more prominent notice. Continuing to use Chat On Mars after a change means you accept the updated policy.
Contact
Questions or privacy requests: contact@chatonmars.com.