Privacy Policy

Last updated: 28 July 2026

This policy explains how VEYON SOLUTIONS INC (“we”, “us”) handles personal data on this website and in our ichat mobile app.

ATHelper is not covered here. It has its own privacy policy at www.at-helper.com.

Who we are

VEYON SOLUTIONS INC is a California stock corporation (entity number B20260002939) and is the controller of the personal data described below.

We will provide our registered postal address on request, and to any supervisory authority that asks for it.

We operate from the United States, and the data described in this policy is processed on servers in the United States. If you use our products from outside the US, your data is transferred to and processed there.

This website

This website uses no analytics, no advertising, and no tracking cookies. It sets no cookies of its own.

The only personal data we collect here is what you type into the contact form: your name, your email address, and the content of your message. We use it to read your message and reply to you. It is delivered to our support mailbox by email and is never used for marketing unless you separately ask to hear from us.

Our web fonts are served by Google Fonts, so your browser requests them from Google’s servers and Google receives your IP address as part of that request. If you would prefer this did not happen, ask us and we will self-host them.

ichat

What we store on our servers

Deliberately very little. Our database holds:

  • Your account — the pseudonymous subject identifier issued by Apple or Google when you sign in, the date your account was created, and your subscription status and expiry. We do not receive or store your name, your email address, or your profile photo from those sign-in providers.
  • A daily usage counter — one row per account per UTC day, recording how many replies you generated that day. This exists to enforce the free-tier allowance.
  • Replies you have reported — only ever created when you tap Report on a suggestion. This is the one place message content is stored on our servers; see Reporting a reply below.
  • A short-lived deletion record — written when an account is deleted and removed within 48 hours. It contains no content and cannot be reversed into your identity; see Deleting your account.

What stays on your device

Your reply history never leaves your phone. The text you asked about, the suggested replies, the detected language, and their timestamps are stored in a local database on the device only. We cannot read it, and uninstalling the app or deleting your account erases it.

Your session token is held in encrypted storage on the device.

The text you send for a reply

When you ask ichat for a suggested reply, the text you provide is transmitted to our server, forwarded to Microsoft Azure OpenAI (East US 2 region) to generate the suggestions, and returned to your phone.

We do not store that text, and we do not store the generated replies — with one exception: a suggestion you choose to report, described next. Apart from that, the text is held in memory only for as long as the request takes and is never written to our database.

Microsoft processes this text on our behalf. It may retain prompts and outputs for a limited period for abuse monitoring under its own terms for the Azure OpenAI Service. We do not control that retention, and we mention it so our statement that we do not store your messages is not mistaken for a claim that no processor ever handles them.

Language detection runs on your device: the model that works out which language a message is written in never sends your text anywhere.

It does, however, report to Google what it decided. ichat uses Google’s ML Kit for this, and Google’s own disclosure for that library says it collects the identified language along with a per-installation identifier, performance figures and error codes, for its own diagnostics and usage analytics. Google encrypts it in transit and does not pass it to anyone else, and there is no setting we can flip to switch it off. So: the language label leaves your device, your message does not. We mention it because “detection happens on your device” could otherwise be read as “nothing at all is sent”, which would not be true.

Reporting a reply

Suggestions are generated by a language model, so occasionally one comes back offensive or inappropriate. Every suggestion therefore has a Report action, and the app tells you what will be sent before anything leaves your phone.

Submitting a report sends the message you were replying to, both generated suggestions, the detected language, which of the two you reported, and the optional note you write, together with your account identifier so we can spot patterns of abuse. Nothing is sent unless you tap Report and confirm.

Reports are kept for 90 days and then deleted automatically, and they are deleted immediately if you delete your account. We use them to review problem output and improve filtering — not for advertising, and not to train models.

Logs

Our servers write operational logs recording your internal account number, your tier, your quota limit, and your usage count after each request. Message content never appears in our logs.

Permissions

The Android app requests two permissions, both granted automatically and neither of them sensitive: internet access, and permission to read the network connection state. It does not request access to your contacts, storage, camera, microphone, or location.

The browser extension

ichat is also a Chrome and Firefox extension. It signs in to the same account and talks to the same server, so everything above applies — and a few things are narrower.

It cannot read the pages you visit. There is no content script and no permission for any site other than our own API. The only text it ever receives is what you select and then explicitly send by choosing ichat: generate a reply, or what you paste into its popup yourself.

Language detection sends nothing. The extension uses the browser’s own built-in detector, which runs locally. This is a real difference from the Android app, where ML Kit reports the detected language to Google, as described above.

Your session is held in memory only. The extension keeps its sign-in token in session storage, which the browser discards when you close it — browser extensions have no encrypted store equivalent to the one the Android app uses, so nothing is written to disk.

Its permissions are: the right-click menu entry, session storage, the browser’s sign-in helper, and network access to our API. Nothing else.

Deleting your account

You can delete your ichat account at any time from within the app, or by requesting deletion here. Deletion is immediate, permanent, and never delayed or rate-limited. It removes your account row, every usage row, and every reply you had reported from our servers, and wipes the reply history and session from your device.

One thing survives, briefly and by design. When you delete an account we write a short-lived record containing a one-way HMAC-SHA256 hash of your sign-in identifier, that day’s usage count, and the deletion time. It exists only to stop the daily free allowance from being reset by deleting and re-creating an account, and it is deleted within 48 hours. The hash is not reversible and cannot be linked back to you without our server key.

Where the GDPR applies, we rely on:

  • Contract — operating your ichat account, enforcing quotas, and providing the replies you request
  • Legitimate interests — replying to enquiries you send us, and preventing abuse of the free tier
  • Consent — anything you have explicitly opted into

Who else processes your data

We do not sell personal data. We share it only with providers that operate our systems on our behalf:

Provider Role
Microsoft Azure Hosting and databases for ichat and this website (United States)
Microsoft Azure OpenAI Generating reply suggestions from the text you submit (East US 2)
Apple and Google Sign-in identity providers; they tell us only your pseudonymous subject identifier
Stripe Payment processing for subscriptions bought on the web, including the browser extension. Your card details go to Stripe and never to us; we receive only a customer reference and the subscription’s status
Apple App Store and Google Play Subscription billing and receipt validation. Your payment details go to them, never to us
Google (ML Kit) On-device language detection. Google receives the detected language plus diagnostic identifiers — never your message text
Hostinger Email delivery for our support mailbox

How long we keep things

  • Account and usage data — until you delete your account, then immediately, apart from the 48-hour deletion record described above
  • Messages and generated replies — not retained on our servers at all, unless you report a suggestion
  • Reported suggestions — 90 days, or until you delete your account, whichever comes first
  • Contact form messages — kept in our support mailbox for as long as we need them to handle your enquiry and keep a record of our correspondence
  • Operational logs — retained for a short period for debugging and abuse prevention, and they contain no message content
  • ML Kit diagnostics — held by Google under its own terms, not by us, and not something we can delete on your behalf

Your rights

Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict processing, and to complain to your local data protection authority. California residents have rights under the CCPA/CPRA, including the right to know and the right to delete; we do not sell or share personal information as those terms are defined there.

The fastest route to deletion is in the app. For anything else, email support@veyon.solutions and we will respond within 30 days.

Children

ichat is not directed at children. You must be 16 or older to create an account. If we learn that we hold data from someone younger, we delete it.

Changes

We will update this page when our practices change and revise the date above.

Contact

Questions about this policy: support@veyon.solutions.