1. Overview
GBFCIP team LLC (“we”, “us”) operates SomeChat. This Privacy Policy explains what information we process when you use somechat.net and how we use it. We design chat to minimize retention; member and payment data are processed only as needed to provide the Service.
2. What we collect
2.1 Casual chat (no member account)
- Temporary session identifier and nickname you choose
- Chat messages and metadata for delivery, subject to short TTL deletion (see PolicyTech)
- Technical data: IP address, browser/device type, timestamps (for abuse prevention and operations)
2.2 Member account (recharge / wallet)
- Email address or phone number and hashed PIN
- Some balance, expiry, and transaction history tied to your member record
- Emails provided at recharge are stored without personal identification as a public profile (contact is hashed/pseudonymized for membership and payment matching)
2.3 Invite email address book (room owner)
- Room owners may store invitee email addresses solely to send a SomeChat room invite link
- Invitee emails are stored in plaintext on our server only for SMTP delivery; owner-only list/add/remove, rate limits, and ResidualCleanup TTL (about 90 days) apply
- Logged-in member address books are keyed by the member account (not by chat room). Guest owners (nickname only) may keep a session-scoped book for manual add and invite send
- Google Contacts import remains a logged-in member privilege (free). Manual Add does not consume Some. Invite send deducts 45 Some per email from the same Some pool as chat (guest session bonus or member wallet)
- If the room owner opts in (checkbox next to My email), that owner email may be shown in the invite message as “Inviter.” If unchecked, the owner email is not shown in the invite body
This section is the product-specific disclosure for Google user data obtained through OAuth / the Google People API. App: SomeChat (https://somechat.net/). Operator: GBFCIP team LLC.
- Owners may connect their Google account via OAuth to import email addresses from Google Contacts
- We request only these Google scopes:
https://www.googleapis.com/auth/contacts.readonly (My Contacts) and https://www.googleapis.com/auth/contacts.other.readonly (Other contacts / Gmail auto-saved emails). We do not use Gmail send, the Gmail API, or any other Google scope for this feature
- After Google authorization, contact names and email addresses are loaded temporarily into a selection UI in SomeChat for the room owner. We do not silently copy the entire Google address book into long-term storage
- Only emails the owner explicitly confirms (and, for select-all, only after an additional confirmation prompt) are saved to the invite address book described in §2.3
- Connecting Google, loading the picker list, disconnecting, and confirming selected emails into the invite address book are not billed (import requires member login). Sending invite emails deducts a fixed owner fee (currently 45 Some per successfully sent email) from the same Some pool as chat. Recipients are not charged. We do not sell Google user data
- Google OAuth tokens are stored on our Cafe24-hosted application server, linked to the owner’s session/member context (hashed session identifier), solely to call Google’s People API for this import feature; owners can disconnect Google from the invite Contacts modal (Disconnect Google), which deletes stored tokens and best-effort revokes them at Google. Unused token records are also pruned after about 7 days
- Outbound invite emails are sent from our Cafe24 SMTP mailbox (
some@somechat.net), not via the owner’s Gmail SMTP and not via the Gmail API
- We do not sell Google user data. We do not use Google Contacts or other Google user data for advertising, retargeting, or interest-based ads
- We do not use Google user data to develop, improve, or train AI and/or ML models (including non-personalized models). Google user data from this scope is not used for AI/ML training
- Google user data from
contacts.readonly / contacts.other.readonly is used only to provide the owner-facing invite picker described here (Limited Use: providing a user-facing feature in SomeChat)
Sharing / transfer / disclosure of Google user data
This clause states with whom we share, transfer, or disclose Google user data. We do not transfer or disclose your information to third parties for purposes other than the ones provided.
- Google — required to complete OAuth (token exchange / refresh / revoke) and to read the owner’s contacts via the People API under
contacts.readonly and contacts.other.readonly. See Google’s Privacy Policy.
- Cafe24 (hosting and SMTP) — SomeChat is hosted on Cafe24. Application data on that server, including OAuth tokens and the owner’s invite address book, is processed on Cafe24’s hosting infrastructure as needed to run the website. Invite emails that the owner actually sends are delivered through Cafe24 SMTP from
some@somechat.net. Cafe24 is not given a separate dump of the owner’s Google Contacts.
- Selected invite recipients only — if (and only if) the owner chooses specific emails and clicks send, Cafe24 SMTP delivers an invite to those addresses. The recipient sees the invite (room link and, if the owner opted in, the inviter’s email). Recipients do not receive the owner’s full Google contact list, unselected contacts, or OAuth tokens. Chat participants cannot access Google Contacts import (owner-only).
- No other third parties. We do not sell, rent, or transfer Google user data to advertising platforms, data brokers, information resellers, or analytics/ads vendors. Payment processors (for example Lemon Squeezy) do not receive Google Contacts or Google OAuth tokens. We do not share Google contact dumps with Amazon SES or other mail vendors; room invites that use this feature are sent via Cafe24 SMTP as described above.
- Google user data never leaves SomeChat + Cafe24 except: (1) the OAuth/API calls back to Google needed to import contacts, and (2) the invite email sent to a recipient the owner selected. That is the complete list of sharing, transfer, and disclosure.
- We may disclose data if required by applicable law, or if needed to investigate abuse of the Service. We do not otherwise allow humans to browse owners’ Google contact lists.
Data protection mechanisms for sensitive data
This clause specifies data protection mechanisms for sensitive data (Google OAuth tokens and contact data obtained under contacts.readonly). Security procedures are in place to protect the confidentiality of your data. We use encryption to protect your information in transit (HTTPS/TLS between the user’s browser and SomeChat, and TLS when our server talks to Google and when Cafe24 SMTP sends mail).
- Access control: Google Contacts import, contact list load, and token disconnect require an authenticated room-owner session and a logged-in member account. Manual invite-book add/list/send is owner-session only (guest owners may use session Some). Participants cannot call these APIs.
- OAuth token storage: Access and refresh tokens are stored server-side only (not in the browser as the system of record). Tokens live in a server data directory that is blocked from public HTTP access (web-server deny rules /
.htaccess). Client secrets in *.local.php are likewise blocked from HTTP. Tokens are keyed to a hashed session identifier, not published at a public URL, and are not kept longer than needed for the owner’s import sessions (disconnect deletes them; unused records are pruned after about 7 days).
- No public contact dump: Unselected people from Google Contacts are not written into the long-term invite address book. Contact JSON and token files are not exposed as public website pages.
- Retention / deletion: Confirmed invite emails follow §2.3 and §4 (owner remove, ResidualCleanup TTL about 90 days, and room/TTL cleanup of related session context). Disconnect Google removes stored tokens and attempts revocation at Google.
- Logging: We do not publish contact lists in public logs. Operational error logs may contain technical messages; they are not a public contacts directory.
- We do not claim disk encryption-at-rest as a Cafe24 standard, and we do not claim SOC 2 or similar third-party certifications. Protections above are the mechanisms we actually operate.
2.4 Payments
- Order IDs, amounts, payment method type, fulfillment status
- For card payments: Lemon Squeezy processes card data; we receive transaction references and custom order metadata, not full card numbers
- For bank transfer: deposit memo, amount, and confirmation records
3. How we use information
- Provide chat, translation, video, and Some wallet features
- Send room invite emails that the owner initiates (including optional Google Contacts pick-list import)
- Process purchases and prevent duplicate or fraudulent fulfillment
- Respond to support requests and legal obligations
- Enforce Terms, block abuse (e.g. session/fingerprint blocks), and maintain security
4. Retention/Deleted
- Chat messages: Deleted per ephemeral policy (e.g. after read timeout, room idle destruction, link expiry).
- Invite email address book: Each stored invite email is deleted after about 90 days (ResidualCleanup TTL), or earlier when the room owner removes it.
- Google OAuth tokens (Contacts import): Kept only while needed to refresh access for the owner’s import sessions; removed when the owner disconnects or when associated session/token records are purged.
- Member and payment records: Retained as long as needed for accounting, disputes, chargebacks, and legal requirements.
5. Third-party processors
- Google — OAuth and Google People API when an owner imports contacts (Google Privacy Policy). See §2.3.1 for sharing and protection of Google user data
- Cafe24 — website hosting and transactional invite email (SMTP from
some@somechat.net)
- Lemon Squeezy — payment processing and Merchant of Record (Lemon Squeezy Privacy). Lemon Squeezy does not receive Google Contacts or Google OAuth tokens
6. Your rights
Depending on your jurisdiction, you may request access, correction, or deletion of personal data we hold about you, or object to certain processing. Use our Contact form. We may need to verify your identity via your registered contact.
Deleting a member account may not erase records we must keep for legal or payment dispute purposes.
7. International transfers
Our servers and processors may be located in the Republic of Korea and other countries. By using the Service, you acknowledge that data may be processed in those locations with appropriate safeguards where required.
8. Children
The Service is not directed at children under 14 (or the minimum age in your country). We do not knowingly collect data from children. Contact us to request deletion if you believe a child has provided data.
9. Changes and contact
We may update this Policy. The “Last updated” date will change when we do. Material changes may be announced in the app.
Data controller: GBFCIP team LLC · 340-15-02889 · Registered address and Contact form