01Who we are and what this policy covers
City of Hats Inc. is an Ontario, Canada corporation. It is responsible for personal information it controls through cityofhats.com, the City of Hats web, iOS, Android and Windows experiences, APIs, secure communication features, CHECK Intelligence, paid plans, support channels, venue products and integrations (together, the Services).
For most direct-to-user Services, City of Hats determines why and how personal information is processed. When an organization uses a venue, clinic, school, hospitality, law-firm, intake or unified-inbox product to handle information about its own users, patients, students, guests, clients or contacts, that organization may be the controller or accountable organization and City of Hats may process the information for it. Contact that organization first for requests about records it controls.
Back to top ↑02Information we collect
The categories depend on how you use the Services. You do not need to use every feature or provide every category.
- Account and sign-in data: username, password or passphrase hash, recovery-key hash, account identifier, plan and role. If you choose email, Apple or Google sign-in, we may receive an email address, display name and provider identifier or token needed to authenticate you.
- Hat, channel and relationship data: Hat identifiers and type, channel or pair identifiers, public cryptographic material, device registrations, delivery state, timestamps, bookmarks, blocks, allow-lists, privacy preferences, group membership and feature settings.
- Encrypted content and attachments: ciphertext, encrypted files and the technical values needed to store, route, retrieve or expire them. The server may retain ciphertext for the lifecycle selected by the feature; this is different from being able to read it.
- Content submitted to processing features: queries and results sent to CHECK Intelligence, Agent or another bot; text submitted for translation; venue workflow records; forms; official-Hat details; public profile information; event registrations; support messages; and content routed through LINE, WhatsApp, Facebook Messenger or other enabled integrations.
- Call and delivery data: caller and recipient Hat identifiers, call identifiers, type, status, timing, room or relay information, short-lived credentials, quality or failure diagnostics, and push-notification tokens. City of Hats does not intentionally record call audio or video unless a clearly labelled feature and the participants authorize it.
- Device, network and security data: device identifiers and labels, app version, platform, language, session and refresh-token records, IP address or a hash derived from it, approximate country, login history, request timestamps, server logs, crash or error details, rate-limit events and suspected abuse or compromise signals.
- Permissions and sensor data: notification permission and, only when you choose a relevant feature, camera, microphone, files, NFC, contacts you deliberately select, or location. GeoLock and venue features may process location or geofence data to evaluate a rule; the interface should tell you when permission is requested.
- Payment and transaction data: plan, price, currency, transaction or receipt identifier, purchase status, renewal and entitlement details. Stripe, Apple, Google or Microsoft processes the payment credentials it needs; City of Hats normally does not receive your full card number.
- Website and inquiry data: pages viewed, referral and campaign information, browser and device information, approximate location derived from IP, Google Analytics identifiers, cookie data, and the name, email, phone, organization, role, country, inquiry type and message you choose to send through our contact form.
- Business and integration data: organization, domain, authorized users, configuration, API credentials or secrets you provide for an integration, audit and operations records, and data an organization instructs us to process through its configured workflows.
Back to top ↑03Where information comes from
We receive information directly from you; automatically from your browser, app, device and use of the Services; from the organization that gives you access; from Apple, Google, app stores and payment providers; from communication or venue integrations you enable; and from security-intelligence sources when you submit a CHECK query.
CHECK can query third-party cyber-intelligence and breach-data services using an email, username, domain, address, name, password or other indicator you submit. Do not submit someone else's personal information unless you have a lawful reason and appropriate authority.
Back to top ↑04Why we use information
We use personal information only for identified, reasonable purposes connected to the Services, including the purposes below.
- Provide accounts, Hats, channels, encrypted storage and delivery, calls, notifications, recovery and device linking.
- Run requested features such as CHECK, translation, Agent, Events, GeoLock, official Hats, venues, integrations and support.
- Process purchases, maintain entitlements, provide receipts and administer subscriptions.
- Secure the Services, authenticate users, enforce limits, prevent spam, fraud and misuse, investigate incidents and maintain reliability.
- Respond to inquiries, troubleshoot, provide service and policy notices, and administer customer relationships.
- Measure and improve the public website and Services using aggregated or de-identified analysis where practical.
- Comply with law, respond to valid legal process, enforce our agreements and protect users, the public, City of Hats and third parties.
Back to top ↑05Legal bases and consent
Depending on the law and context, we rely on performance of a contract, your consent, compliance with legal obligations, and legitimate interests such as securing, operating and improving the Services, preventing abuse and supporting users. We assess legitimate interests against the impact on individuals.
Where consent is required, you may withdraw it, subject to legal or contractual limits and reasonable notice. Withdrawing a required permission may prevent the associated feature from working. An organization using City of Hats for its own workflows is responsible for establishing an appropriate legal basis for the personal information it asks us to process.
Back to top ↑06Encryption boundaries and honest limitations
Ordinary Hat-to-Hat messages and files are designed to be encrypted on the user's device so our servers store and route ciphertext rather than readable content. Cryptographic claims, current audit status and known limitations are described in our Security Evidence Center and Technical Transparency page; those pages form the most current technical explanation.
End-to-end encryption does not hide everything. We may still process Hat and channel identifiers, public keys, delivery and expiration state, timestamps, notification tokens, call signaling, IP or security logs and other operational metadata. A recipient can copy, photograph, record or otherwise preserve content after receiving it, even when a feature limits viewing or retention.
A feature cannot remain opaque to City of Hats if it asks our server or another provider to interpret, search, translate, moderate, automate or deliver the content outside the encrypted Hat-to-Hat path. This includes CHECK queries, Agent interactions, optional translation, some system and venue messages, public pages, contact forms and third-party inbox integrations. The interface and this policy describe those exceptions; do not use them for content you do not want processed within that feature's stated boundary.
Back to top ↑07AI, translation and cyber-intelligence features
If you request message translation, the text and target language are sent transiently through our server to OpenAI for translation. Our application is designed not to store the submitted translation text in its translation endpoint, but OpenAI's processing is governed by our provider arrangement and its applicable terms. You can choose not to use translation.
CHECK sends the indicator needed for your requested search to relevant intelligence providers, such as breach-data services, and returns an automated report. Results may be incomplete, outdated, false-positive or about a different person. CHECK and Agent outputs are informational and should not be the sole basis for a legal, employment, credit, insurance, housing, medical or similarly significant decision.
City of Hats does not currently use solely automated processing of your personal information to make a decision that produces legal or similarly significant effects about you.
Back to top ↑08When information is shared
We do not sell personal information and do not share personal information for cross-context behavioural or targeted advertising. We disclose only what is reasonably needed for the purpose. Depending on the feature, recipients may include:
- Infrastructure, hosting, database, storage, content-delivery, email, monitoring and security providers that operate the Services.
- Apple, Google and related identity services when you choose social sign-in; Firebase or platform push services when you enable notifications.
- Stripe, Apple App Store, Google Play or Microsoft Store for payments, receipts, entitlement validation and subscription administration.
- LiveKit and network relay infrastructure for supported call transport, signaling and connection establishment.
- OpenAI when you invoke translation, and cyber-intelligence providers when you invoke CHECK.
- LINE, WhatsApp, Facebook Messenger or another integration when you or an organization deliberately routes communications through it.
- The organization that provides your venue or managed account, according to its role and instructions.
- Professional advisers, auditors, insurers, transaction counterparties and authorities when reasonably necessary for advice, a corporate transaction, safety, fraud prevention, legal claims or valid legal process.
Back to top ↑09Website cookies and analytics
The public website uses essential browser storage for functions such as language or session state and currently uses Google Analytics through Google Site Kit to measure page visits, referrals, device and browser characteristics and site performance. Google may set or read analytics identifiers and process IP-derived information according to its services and our configuration.
We do not use message content for analytics or advertising. You can restrict cookies with browser controls or supported privacy tools, although disabling essential storage may affect language, sign-in or other functions. Where applicable law requires opt-in consent for non-essential analytics, we will seek it before activation.
Back to top ↑10How long we keep information
Retention depends on the data, feature, user settings, security need and legal obligation. We keep information no longer than reasonably necessary for the purposes described here, then delete, de-identify or isolate it, subject to backup cycles and legal holds.
- Account, profile, Hat ownership and entitlement records: while the account or Hat is active, then deleted or de-identified following a verified deletion request except for records we must keep.
- Access and refresh sessions: until they expire or are revoked; limited records may remain to prevent replay, abuse or unauthorized access.
- Messages, files, Dead Drops, Tease content and channel records: according to the feature's selected duration, burn, retrieval, deletion and lifecycle settings. Some encrypted channel history is persistent until deletion; ephemeral controls do not guarantee that a recipient has not made a copy.
- Call state and diagnostics: for the operational period needed to connect, troubleshoot, secure and account for calls; media is not intentionally recorded by City of Hats unless a separately disclosed feature is used.
- Push tokens: while registered to a Hat or device, until unregistered, replaced, expired or no longer needed.
- CHECK, Agent, translation and integration data: according to the requested workflow and the provider involved. Translation text is designed to be transient at our endpoint; CHECK or Agent messages and reports may remain in the relevant channel history.
- Payment, tax and transaction records: for the period required by tax, accounting, fraud-prevention and payment-dispute rules.
- Contact, support, legal and security records: while a request, relationship, investigation or claim is active and for a reasonable follow-up or limitation period afterward.
- Backups: protected and removed on the normal backup rotation; deletion from active systems may occur before all backup copies age out. Restored backups are subject to the same deletion rules.
Back to top ↑11International processing
City of Hats is based in Canada. We and our providers may process information in Canada, the United States and other countries where the Services, integration or provider operates. Those countries may have different privacy laws and may permit lawful access by courts, governments or law-enforcement agencies.
Where required, we use recognized safeguards for restricted transfers, such as adequacy decisions, contractual protections or another lawful mechanism. You may contact us for information about safeguards relevant to your information.
Back to top ↑12Your privacy rights
Rights vary by location and are subject to exceptions. You may have the right to know whether we process your information; access it; learn its sources, uses and recipients; correct it; request deletion; restrict or object to processing; receive portable information; withdraw consent; and complain without retaliation. You may also have rights concerning sensitive information, automated decisions and direct marketing.
Use the in-app deletion controls where available or contact privacy@cityofhats.com. Describe the account, Hat or interaction involved without sending passwords, recovery keys or message plaintext. We may ask for information needed to verify identity and authority. We generally respond within 30 days, or within the period required by applicable law, and will explain any extension or refusal.
You may complain to the Office of the Privacy Commissioner of Canada or the privacy authority where you live. If an organization controls the record, we may direct your request to that organization. Authorized agents must provide proof of authority.
Back to top ↑13Regional disclosures
Canada: City of Hats applies the accountability, identified-purpose, consent, limiting-collection, limiting-use, accuracy, safeguard, openness, access and challenge principles that apply under Canadian private-sector privacy law. Provincial law may also apply.
European Economic Area, United Kingdom and Switzerland: where their privacy laws apply, the legal bases and rights above apply, including the right to lodge a complaint with a supervisory authority. City of Hats is a Canadian company; contact us to identify the appropriate representative or transfer safeguard for your situation.
California and other U.S. states: subject to statutory thresholds and exemptions, residents may have rights to know, access, correct and delete information and to opt out of sale, sharing or targeted advertising. City of Hats does not sell personal information or use it for cross-context behavioural advertising, so we do not offer a sale/share opt-out link. We do not discriminate for exercising applicable rights.
Back to top ↑14Children and age limits
The general-audience Services are not directed to children under 18, and you must be at least 18 to create an account or buy a plan unless a separate written customer agreement and age-appropriate experience says otherwise. We do not knowingly collect personal information directly from a child through the general-audience Services.
A school, clinic or other organization using a managed venue is responsible for lawful authority, notices, consent and age-appropriate safeguards for records it asks City of Hats to process. If you believe a child has provided information without proper authorization, contact us.
Back to top ↑15Security and breach response
We use administrative, technical and physical safeguards selected for the sensitivity and risk of the information, including access controls, encryption where appropriate, authentication, monitoring, backups, incident response and software maintenance. Our Security Evidence Center distinguishes implemented, externally evidenced and planned controls.
No system, device, provider or transmission is completely secure. Security features reduce particular risks; they do not guarantee anonymity, confidentiality, delivery, deletion, device integrity or protection from a recipient. If a breach creates a reporting or notification duty, we will act in accordance with applicable law.
Back to top ↑16Your controls and responsibilities
You can choose a pseudonymous Hat, decline optional permissions, avoid social sign-in, disable notifications, choose channel lifecycles, block or allow Hats, stop using translation or CHECK, and delete content or your account where controls are available.
Protect your passphrase, recovery key, devices and Hat identifiers. City of Hats cannot protect content after it is displayed on a compromised device or captured by a recipient. Do not include unnecessary sensitive information in support, public profiles, event forms, CHECK queries or third-party integrations.
Back to top ↑17Changes to this policy
We may update this policy as the Services, providers or law change. We will post the new version and effective date. For a material change, we will provide additional notice reasonably suited to the change, such as an in-app, website or account notice, and seek consent where required. Earlier versions may be requested from us.
Back to top ↑