Privacy Policy

Last updated 3 August 2026

Chatly is a workplace messaging service. Most of the data in it is put there by your employer's team and is controlled by them, not by us. This page explains what is collected, who can see it, and how long it is kept. It is written to be read, not to be survived.

1. Who we are

Chatly (“Chatly”, “we”, “us”) provides a workplace messaging service at chatly.team and on customer-specific instances. Our registered entity is [LEGAL ENTITY NAME], [REGISTERED ADDRESS].

For privacy questions, data requests, or anything in this policy, contact privacy@chatly.team.

2. Who controls your data

This matters more than it sounds, because it determines who you ask when you want something changed or deleted.

  • Your workspace content — messages, direct messages, files, channels, and everything else created inside a workspace — is controlled by the organisation that runs that workspace. They decide who has access, how long it is kept, and when it is deleted. We process it on their instructions. If you want your messages deleted, ask your workspace administrator first; we generally cannot act against the instructions of the organisation that owns the workspace.
  • Our own website and business records — the chatly.team marketing pages, access requests you send us, and billing records — are controlled by us, and you can come to us directly about those.

3. What we collect

Everything below is data the service actually stores. There is no separate hidden collection.

CategoryWhat specificallyWhy
AccountEmail address, display name, avatar image, time zone, and the status you set (including any custom status text and emoji)To create your account, show you to colleagues, and display times in your local zone
Messages and contentChannel messages, direct messages, thread replies, reactions, polls, tasks, reminders, saved items, scheduled messages, unsent drafts, and the previous versions of messages you editTo deliver the service. Edit history exists so a message cannot be silently rewritten
FilesAnything you upload: documents, images, voice notes, and video messagesTo deliver the service
Security and audit recordsIP address, browser user agent, and approximate location on sign-in — including failed sign-in attempts — plus a log of administrative actionsTo detect unauthorised access, enforce IP restrictions your organisation sets, and give administrators an audit trail
Two-factor authenticationHashed one-time codes and hashed backup codes, and a signed cookie marking a device as verified for 30 daysTwo-factor authentication is mandatory on every account
NotificationsYour browser's push subscription and its user agent, plus your notification preferencesTo deliver notifications when the app is closed. Only if you grant permission
PresenceWhen you were last active, and whether you are online, away or do-not-disturbTo show colleagues whether you are available
Optional integrationsIf you connect Google or Spotify, we store access and refresh tokens for those accountsOnly if you explicitly connect them. Disconnecting deletes the tokens
Crash reportsWhere error monitoring is enabled for your instance: the error and the code path that caused it, the page you were on with search terms and identifiers removed, your browser version, and your account idTo find and fix faults without waiting for someone to report them. Never includes message content or a recording of your screen
Marketing site analyticsAggregate page view data via Vercel Analytics on our public pagesTo understand which pages people read. It is cookieless and does not build a profile of you

4. What your employer can see

Chatly is a workplace tool, and workplace tools are not private from the workplace. We would rather you learned this here than discovered it later.

Workspace administrators can read your messages. Administrators of your workspace can view channel content, export message archives, apply retention rules that automatically delete messages after a set period, and place legal holds that prevent deletion. Administrators can also see sign-in history including IP addresses, deactivate accounts, and view an audit log of administrative activity.

Direct messages are not visible in the ordinary product interface to other members, but they are stored on your organisation’s instance and can be reached through administrative export and legal-hold tooling. Treat Chatly as company property, because it is.

5. Security, stated honestly

What is true:

  • Data is encrypted in transit using TLS, and encrypted at rest by our hosting provider.
  • Every database table enforces row-level security, so access is checked per row on every query rather than trusted from the application.
  • Two-factor authentication by email code is mandatory on every account, with recovery codes.
  • Organisations can restrict access to specific IP addresses, and administrative actions are written to an audit log.

Chatly is not end-to-end encrypted. Messages are stored in a form the server can read. This is a deliberate trade-off: search, message exports, retention policies, and legal holds are all features that require it. Anyone with administrative access to your organisation’s instance, and our own personnel with database access, could technically read message content. If you need end-to-end encrypted messaging, Chatly is the wrong tool and we would rather say so.

No system is perfectly secure. If you believe you have found a vulnerability, please report it to security@chatly.team.

6. Cookies and local storage

We do not use advertising cookies or third-party tracking cookies. The cookies we set are:

NamePurposeLifetime
sb-…-auth-tokenKeeps you signed in. Essential.Until you sign out or it expires
chatly-2faMarks this device as having passed two-factor authentication. Essential. Not readable by scripts.30 days
google_oauth_state / spotify_oauth_stateShort-lived security token used only while connecting an optional integrationMinutes

We also use your browser’s local storage for interface preferences — theme, time format, sidebar layout, accessibility settings, and unsent message drafts. This stays on your device. Clearing your browser data removes it.

7. Who else touches your data

We do not sell personal data, and we do not share it for advertising. We use a small number of service providers to run the service. Each one, what it does, and where it runs is listed on our subprocessors page.

We may disclose data if legally required to do so, or to protect the rights and safety of users. Where we are permitted to tell you, we will.

8. How long we keep it

  • Messages and files are kept until deleted by you, deleted by an administrator, or removed by a retention policy your organisation configures. If a legal hold applies, deletion is blocked until the hold is lifted.
  • Sign-in history and audit logs are retained for security and accountability purposes.
  • Two-factor codes expire within minutes and are stored only as hashes.
  • Deactivated accounts keep their message history by default, so that conversations remain intelligible to colleagues. Full deletion is available on request through your administrator.
  • When an organisation ends its use of Chatly, its instance and data are deleted in accordance with its agreement with us.

9. Your rights

Depending on where you live, you may have the right to access, correct, delete, export, or restrict use of your personal data, and to object to certain processing. You may also have the right to complain to your data protection authority.

For anything inside a workspace, start with your workspace administrator — they control that data and can act faster than we can. For data we control, or if your administrator cannot help, contact privacy@chatly.team and we will respond within [30 days].

We do not sell or share personal information as those terms are defined under California law, and we do not use it for cross-context behavioural advertising.

10. Where your data is held

Chatly is hosted in the United States. Database and file storage run in the [us-west-1] region, and application servers run in [sfo1]. If you access Chatly from outside the United States, your data is transferred there. Where required, we rely on Standard Contractual Clauses for such transfers. [Confirm transfer mechanism with counsel before relying on this sentence.]

11. Children

Chatly is a workplace product and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has an account, contact us and we will remove it.

12. Changes to this policy

We will update this page when the service changes. If a change materially affects how we handle personal data, we will notify workspace administrators before it takes effect. The “last updated” date at the top always reflects the current version.