Effective At: August 15, 2026
Last Updated: August 15, 2026
This page is for law enforcement officers, courts and lawyers who need information from Secret Chat, and for users who want to know in advance what could ever be produced about them. It is written to be useful to both, so it says plainly what we hold and — more often — what we do not.
Secret Chat is operated by Opossum DOO, Herceg-Novi, Montenegro. See Company Details.
1. How to reach us
- Legal and law enforcement requests:
- Abuse reports (threats, harassment, child safety, fraud):
- Emergencies involving a risk to life: mark the subject line
EMERGENCYand say so in the first line. See Section 6.
We aim to acknowledge a request at these addresses within 5 business days, and an emergency request as quickly as we are able. We are a small company in a single time zone; we do not operate a 24-hour desk and will not pretend otherwise. If a matter is genuinely time-critical, say so explicitly rather than assuming it will be read that way.
2. What we require
We disclose non-public information only in response to a valid legal request — one issued under Montenegrin law, or one from another jurisdiction that is enforceable against us through mutual legal assistance or an equivalent route. Please include:
- The issuing authority, the case or reference number, and a contact who can verify the request.
- The specific identifier you are asking about (see Section 3) and the time period.
- What you are actually trying to establish. This matters more here than at most services, because the answer is frequently "that record does not exist", and knowing your goal lets us say what — if anything — would help instead.
We will narrow or decline a request that is overbroad, that asks for material we do not hold, or that is not supported by valid legal process. Where we are permitted to notify the affected user, our default is to do so; we will not notify where the law forbids it or where doing so would create a risk to someone's safety.
3. What identifiers are useful
Accounts are email-only: we ask for an email address and nothing else — no name, no phone number, no address. The identifiers that mean anything to us are:
- An account email address.
- An order or transaction reference from a payment.
- A session identifier (a browser-generated token, if you have obtained one from another source).
We cannot look a person up by name, phone number or real-world identity, because we never collect those.
4. What we hold
The complete list. If it is not here, we do not have it.
- Account record: email address, registration date, email verification status.
- Payment and billing records: orders, transactions, amounts, credit grants and usage totals. Card numbers and crypto credentials are held by our payment providers, not by us.
- Credit usage totals: how many credits were spent on which model, and when. This is accounting data — it records that a model was used, never what was said to it.
- Server logs: IP addresses, request timestamps and error codes, retained for a maximum of 30 days.
- Visit attribution: for a first visit, the referring site, landing page, campaign parameters, country and browser user-agent string.
- Support correspondence.
- Safety-screening records: where a prompt was refused for sexual content involving minors or a threat of violence, the fact that it happened — category, model, timestamp, account or session identifier. Never the text of the prompt. Retained 90 days. See the Privacy Policy.
- Session Privacy Reports: the deletion-report documents generated when a user asks us to delete a response at the provider. They record model, provider, deletion status and provider response identifiers — metadata, not prompt text.
5. What we do not hold
This section is the reason most requests to us come back empty, so it is worth reading before drafting one.
- No chat history. Conversations are stored in the user's own browser, not on our servers. A prompt and its answer exist on our side only for as long as it takes to deliver the answer, and are deleted as soon as the user's browser collects them — within 24 hours in every case. There is no archive to search, no backup containing conversations, and no way for us to recover a past conversation. A request for "all messages sent by this account" cannot be answered, in any time period, however the request is worded.
- No uploaded files. Images and documents are processed in the moment and not retained.
- No stored IP address on the account record. IP addresses appear only in server logs, for at most 30 days, and are not linked to conversations — because the conversations do not exist.
- No names, phone numbers, addresses or identity documents. We never collect them.
- No behavioural profile. We do not build one.
- No payment card numbers.
A note on what this does and does not mean. Our design removes the link between a person and their queries; it is not a claim that a user cannot be identified by other means, and it is not a promise that no record of a request exists anywhere. Model providers operate their own systems under their own terms, and a provider's record of a request carries our gateway's credentials rather than the user's identity — which is a limit on what that record shows, not a guarantee about it.
6. Emergencies and threats to life
If you are a law enforcement officer and there is an imminent risk of death or serious physical injury, write to with EMERGENCY in the subject line, describe the risk, and say what you need. We will provide what we hold, to the extent the law permits us to do so without further process, and we will tell you honestly and immediately if the answer is that we hold nothing useful.
Where a law that applies to us requires notification of an authority — for example an obligation to report a suspicion of an offence involving a threat to a person's life or safety — we will comply with it.
Two things we will not do, and we say so here rather than let them be assumed. We do not monitor conversations, and we have nothing to monitor them with; our screening is an automated check applied before a message is sent, not surveillance of what people discuss. And we do not report users to authorities on the strength of a classifier score alone: an automated category flag is a probability, not a suspicion, and a service that escalated on one would report far more innocent people than guilty ones.
7. Preservation requests
We will honour a valid preservation request for the categories listed in Section 4, for 90 days, renewable once on request. Preservation cannot create data that does not exist — it cannot preserve conversations, because there are none, and a preservation request received after the fact cannot recover a prompt that has already been deleted.
8. Costs, and what we will not do
We do not charge for responding to valid requests. We will not build new logging, retention or interception capability in response to a request; where we are ordered to do so by a competent authority, we will challenge or comply as the law requires, and we will say publicly whatever we are permitted to say.
9. For users reading this page
Nothing on this page is a promise that using Secret Chat places you beyond the law. It does not create any privilege — only a lawyer can do that — it is not a way to hide or destroy evidence, and your own duty to preserve material relevant to a legal matter is unchanged by which tool you typed it into. What this page describes is narrower and, we think, more useful: there is very little about you here to ask for.
Questions about this page: . See also our Privacy Policy and Terms of Service.