Privacy Policy
Last updated: August 13, 2026
This document is available in English and Portuguese. The English version is the reference for people using the app outside Brazil.
Nimo Chat is operated by Leonardo Mondaine, an individual, established at R. Presidente João Goulart, 675, Cascavel, Paraná, Brazil ("we").
This policy explains, without the runaround, what the app collects, why, who it is shared with, and what you can demand from us.
We follow the Brazilian General Data Protection Law (Law 13.709/2018 — LGPD). For those who use the app in Europe and the United Kingdom, we also follow the GDPR; for California residents, the CCPA/CPRA.
By using Nimo Chat you agree to this policy and to the Terms of Use. If you do not agree, do not use the app.
Language. This policy is published in eleven languages. The English version is the reference version for users outside Brazil. If you are in Brazil, this text in Portuguese is the one that applies — it is your right under the Consumer Protection Code, and we do not waive it.
1. What Nimo Chat does not collect
We start here because this is what sets this app apart the most:
- We do not ask for your email or phone number. There is no sign-up with an email address.
- We do not ask for a password. There is no password to leak.
- We do not ask for your age or date of birth. You declare that you are 18 or older when you accept the terms, and we stop there.
- We do not ask for your real name.
- We do not collect your location. More than that: we strip the EXIF metadata from every photo before sending it, which erases the coordinates of where it was taken. It is a piece of data that almost every app forgets to clean up.
- We do not access your contact list.
- We do not use advertising or ad trackers. There is no advertising SDK in the app.
2. What we collect
2.1 Account identification
When you open the app for the first time, we create an anonymous account with a random identifier generated by Firebase Authentication. That identifier is not linked to you, to your device, or to any external service.
2.2 Profile data, provided by you
| Data | Required | Who sees it |
|---|---|---|
| Nickname | yes | anyone you chat with |
| Gender (male/female) | yes | used in matching; visible in the chat |
| Interests | no | whoever chats with you |
| Intro line (bio) | no | whoever chats with you |
| Profile photo | no | only people who have accepted your friend request |
The profile photo deserves emphasis: the server does not deliver your photo to strangers. It only becomes visible after both people accept the friendship. Before that, everyone sees an avatar drawn by the app.
2.3 Content you create
Text messages, photos, videos, audio, stickers, feed posts, 24-hour Status and wall messages. We store this content in order to deliver it to the other person and so that you can find it again later.
View-once photos and videos are handled differently: the file is deleted from our server as soon as it is opened, and deleted automatically after 24 hours if it is never opened.
2.4 Operational data
- Presence: the time of your last access, so we can show how many people are online. This information is aggregated — no one can look up who specifically is online.
- Matching queue: while you are looking for someone, your identifier, gender and interests sit in a temporary queue, deleted as soon as the match happens or you give up.
- Notification token: a Firebase Cloud Messaging code so we can notify you of new messages. You can turn notifications off at any time in the settings.
- Friendships, blocks and reports.
- Recovery code hash: when you generate a recovery code, we store only a fingerprint of it — never the code itself. Not even we can find out what your code is.
2.5 Voice calls
This point is important: call audio does not pass through our servers and is not recorded. The conversation goes directly from one device to the other (WebRTC technology).
We store only the data needed for the call to happen and for you to see your history: who called whom, when, whether it was answered and how long it lasted. The technical connection data is deleted as soon as the call ends.
On some networks a direct connection is not possible, and the audio needs to pass through an intermediate server (TURN). That server only relays the packets: it does not record, does not store and cannot read the content.
2.6 Diagnostics
When the app crashes, Firebase Crashlytics logs the error, the device model and the system version. It is used solely so we can fix failures.
3. Why we process your data (legal bases)
| Purpose | Legal basis (LGPD) |
|---|---|
| Create your account and deliver your messages | performance of a contract (art. 7, V) |
| Match you with another person | performance of a contract |
| Prevent abuse, spam and harassment | legitimate interest (art. 7, IX) |
| Analyze app failures | legitimate interest |
| Send notifications | consent (art. 7, I) — revocable |
| Comply with a court order | compliance with a legal obligation (art. 7, II) |
4. Who we share with
We do not sell, rent or trade your data. Sharing is limited to providers that run the service on our behalf:
| Provider | What for | Where it processes |
|---|---|---|
| Google Firebase (Google LLC) | authentication, database, files, notifications and crash reports | United States and others |
| Apple App Store / Google Play | distribution and, where applicable, subscription payments | as per each store |
| RevenueCat | validate subscription receipts, when subscriptions are active | United States |
| TURN server | relay call audio when the direct connection fails | to be defined — we have not contracted a TURN server yet |
All of them are contractually required to use the data only to provide the service to us.
Disclosure due to legal obligation: we may disclose data in the face of a court order or a request from a competent authority. We review each request, refuse those that are generic or disproportionate, and hand over the minimum necessary.
Business transfer: in the event of a merger, acquisition or sale, your data may be transferred to the successor, which will be bound by this same policy.
5. International transfer
Our providers keep servers outside Brazil, mainly in the United States. The transfer takes place under art. 33 of the LGPD and, for data coming from Europe, under Standard Contractual Clauses approved by the European Commission. Data always travels encrypted.
6. How long we keep it
| Data | Retention |
|---|---|
| Profile and chats | for as long as the account exists |
| View-once photo/video | until opened, or 24 hours |
| Status | 24 hours |
| Wall message | 24 hours |
| Matching queue | minutes |
| Technical call data | deleted when the call ends |
| Reports | up to 2 years, for repeat offenses and legal defense |
| Records required by law | as per the legal period |
7. How to delete your account
Go to Profile → Account → Delete my account. We do not ask for a reason and there is no waiting period: deletion starts at that very moment.
What happens: your profile and your photo are deleted immediately; the database on your device is wiped; and an automatic process then removes your messages, posts, statuses and files from our servers.
Two honest things about this:
- Messages you sent to another person may remain in their chat, as happens in any messaging app.
- If someone took a screenshot or saved something you sent, that is beyond our reach.
Deleting your account does not cancel subscriptions. Cancellation is done in the App Store or on Google Play.
8. Your rights
Under the LGPD (art. 18), you may at any time: confirm whether we process your data; access it; correct incomplete or outdated data; request anonymization, blocking or deletion; request portability; find out who we share it with; withdraw consent; and object to a processing activity.
In Europe and the United Kingdom, the GDPR guarantees the same rights, plus the right to lodge a complaint with your country's authority. In California, the CCPA/CPRA guarantees the right to know, delete, correct and not be discriminated against for exercising these rights — and we record here that we do not sell and do not share personal data in the sense given by that law.
How to exercise them: write to suporte@chatnimo.com. We reply within 15 days (LGPD) or 30 days (GDPR). To protect your account, we may ask you to prove that you control it — for example, by providing the recovery code or by sending the request from inside the app. We do not charge for this.
You may also complain directly to the ANPD (gov.br/anpd).
9. Minimum age
Nimo Chat is intended for people 18 and over. We do not allow accounts for minors, and the declaration is made when accepting the terms.
We do not process data of children and adolescents. If we find out that a minor is using the app, we delete the account and all data immediately. If you are responsible for a teenager and want their account removed, write to abuso@chatnimo.com — we act the same day, without requiring a reason and without asking for documents.
Reports of profiles that appear to belong to minors receive top priority and enter an immediate suspension flow.
Why 18 and not 16. The app combines random conversation with strangers, gender filtering, photos, video, voice calls and anonymity. Each piece on its own is defensible; added together, they create an environment in which the presence of teenagers multiplies the risk. And a guardian's consent would not really solve this: in an anonymous app, neither side has any way of knowing the other's real age.
10. Security
We use encryption in transit (HTTPS/TLS) across all communication, encryption at rest on Firebase's servers, and access rules that limit, on the server itself, what each person can read.
One architectural decision is worth explaining: your friends list cannot be read by anyone other than you — not even by your own friends. The feed works the opposite way from the obvious one: instead of asking "who are this person's friends", each post asks "does this person have me as a friend". The result is that there is no way to map who knows whom.
About what we cannot promise: no system is impenetrable. We do not offer end-to-end encryption on text messages — they are encrypted in transit and at rest, but technically we could access them to comply with a court order. We would rather say this than sell you a security we do not deliver. Voice calls, those really do not pass through us.
In the event of a security incident, we will notify those affected and the ANPD within the legal deadlines.
11. Other people's content
Nimo Chat connects strangers. We do not read your conversations or pre-screen them. You are responsible for what you write and send.
There are reporting and blocking tools in every chat. We review every report within 24 hours and remove anyone who breaks the rules. Serious cases — suspected minors, non-consensual nudity, violence — result in automatic and immediate suspension.
12. Advertising
Today Nimo Chat does not display advertising and has no ad library installed. This is a product decision about the app's current state, not a permanent promise. If we ever change that, we will update this policy and give notice beforehand.
Your data will never be sold to advertisers or data brokers.
13. Changes
We may update this policy. Relevant changes will be announced inside the app at least 15 days in advance. The date at the top indicates the latest revision.
14. Contact
Leonardo Mondaine R. Presidente João Goulart, 675 — Cascavel, Paraná, Brazil
| Subject | |
|---|---|
| Questions, personal data and account | suporte@chatnimo.com |
| Reports and safety | abuso@chatnimo.com |
Data Protection Officer (DPO): Leonardo Mondaine — suporte@chatnimo.com
We reply within a few business days.