⚡ Quick summary (TL;DR)
ID and face data: identity verification is collected and processed by industry provider Sumsub. MPChat does not receive or store raw ID images or biometric templates — only verification outcomes and structured identity fields.
Chat content: MPChat Chat uses end-to-end encryption (E2EE). Decryption keys live only on your and your contacts’ devices — MPChat servers cannot decrypt private conversations.
Funds and card secrets: MPChat Pay balances are ledgered by MP PAYMENT INC, with underlying on-chain USDT held in licensed partner Cobo and HashKey custody solutions. MPChat Web3 is self-custody with Turnkey infrastructure. Card number / expiry / CVV are not stored locally — viewing them loads live data from the card issuer API.
📖 Overview
When you are asked to complete KYC, deposit, or open a card, the usual worry is: who can see my ID, chats, and money — and who can move them? This article explains five custody chains in plain language and introduces our main partners.
Below you will find a summary table, then separate sections on chat, KYC, MPChat Pay, MPChat Web3, card secrets, and the security steps you should take yourself.
📊 One table: who holds which data and assets
Direct answer: different data and assets are held by different parties. What MPChat can access has clear boundaries — plaintext chat and full card secrets are outside them.
Type | Who holds / processes | Can MPChat access it? |
Private chats & files | E2EE; keys on your and contacts’ devices | Cannot decrypt private conversation content |
ID images / face biometrics | Identity provider Sumsub | Does not receive or store raw images/templates; only outcomes + structured fields |
MPChat Pay balance (USDT) | Ledgered by MP PAYMENT INC; underlying on-chain assets in Cobo / HashKey custody solutions | Staff cannot unilaterally move funds; freezes/holds may apply under the agreement (compliance & risk) |
MPChat Web3 wallet assets | Self-custody; keys generated & signed inside Turnkey TEE | Cannot obtain your private keys; you are the sole signing authority |
Card number / expiry / CVV | Card issuer; loaded live via API when you view | Full card secrets are not persisted on MPChat servers or locally |
💬 Chat & social data: E2EE with keys on device
Direct answer: private conversations in MPChat Chat use end-to-end encryption (E2EE). Decryption keys live only on your and your contacts’ phones. MPChat servers do not hold those keys, so they cannot technically read your private chats or encrypted files.
Social data such as local chat history mainly stays on your device. After changing phones, history may not restore automatically — a common sign that E2EE is working, not that “the platform deleted your chats.”
For more detail, see What is end-to-end encryption (E2EE)? and Can MPChat staff read my chats?.
🆔 ID & KYC: Sumsub verifies; MPChat receives outcomes only
Direct answer: during KYC, ID photos and face checks are collected and processed by identity provider Sumsub. MPChat does not receive or store raw ID images or biometric templates — only verification outcomes and structured identity fields (such as name, document type, and status) needed for compliance and card issuance.
Why this is safer: sensitive images stay with a specialized verification provider under industry compliance standards, reducing the risk of MPChat keeping a store of ID photos.
When you apply for a card, verification results are submitted to the card issuer through compliance flows and APIs for issuance review — not by handing raw ID images to arbitrary third parties.
Upload only inside the official App: go to Me → Identity verification. Official support will never proactively ask you to send ID photos by email, SMS, or chat.
ℹ️ About Sumsub
Sumsub is a widely used electronic identity verification (eKYC) provider that offers document OCR, liveness checks, and anti-fraud verification for financial and internet platforms. MPChat partners with Sumsub for identity verification.
💰 MPChat Pay funds: ledgering plus licensed custody layers
Direct answer: the USDT balance you see in MPChat Pay is ledgered and managed on the account side by MP PAYMENT INC. The underlying on-chain assets sit in custody solutions provided by licensed partners Cobo and HashKey. MPChat staff cannot unilaterally transfer those funds. Under the user agreement, the platform may still freeze or stop payment on balances when required for compliance, AML, or risk control.
Cobo: a digital-asset custody and wallet infrastructure provider, certified to ISO 27001 for information security management.
HashKey: a licensed digital-asset services institution involved in compliance and risk screening for deposit crediting (including AML/KYT).
Suspicious or high-risk withdrawals go through multiple layers of internal and external risk review to reduce abnormal outflow risk.
If a deposit stays on Pending for a long time, common causes include the minimum amount, confirmations, or AML/KYT review — see Deposit Pending & AML/KYT guide.
🔑 MPChat Web3: self-custody on Turnkey infrastructure
Direct answer: assets in MPChat Web3 follow a self-custody model: you are the sole signing authority. Keys are generated and used for signing inside the trusted execution environment (TEE) of wallet infrastructure provider Turnkey. MPChat cannot obtain your private keys.
No seed-phrase display: the current product does not show a traditional 12/24-word seed phrase, reducing risks from screenshots, phishing, or social engineering.
Export is not available today: exporting private keys or seed phrases to external wallets (such as MetaMask) is not currently supported. Rely on in-app capabilities; until export is available, do not trust third parties who claim they can “help you export a seed phrase.”
ℹ️ About Turnkey
Turnkey provides wallet infrastructure based on trusted execution environments so key generation and signing happen in a controlled hardware environment, without exposing full private keys to app servers or ordinary client storage.
💳 Card secrets: not stored; viewing loads live data
Direct answer: full card secrets (number, expiry, CVV) are not persisted on MPChat servers or locally. When you tap the eye icon in the App to view them, the system requests live data from the card issuer API — so a short loading state is normal and intentional, to shrink the exposure of card secrets.
If card details stay blank or fail to load, see card blank screen / Loading troubleshooting and retry on a stable network.
⚠️ Anti-scam reminder
Official support will never proactively ask for full card numbers, CVV, wallet seed phrases, or SMS codes. Treat any request to “send card secrets for verification” as a scam.
📜 Compliance & disclosed financial licenses
Direct answer: MPChat-related entities hold financial and digital-asset operating qualifications in multiple jurisdictions. The table below lists only items already disclosed in the help center; see the dedicated licenses article for the full statement.
Region | Jurisdiction | License / qualification |
Americas | United States | MSB (Money Services Business Registration) |
Americas | El Salvador | BSP + DASP dual license |
Asia-Pacific | Hong Kong | TCSP (Trust or Company Service Provider) |
See the full Statement on Compliant Operations & Financial Licenses.
✅ Four things you should do yourself
Enable a passkey for hardware-backed protection on login and fund actions. See Passkey overview.
Bind 2FA (e.g. an authenticator app) to reduce account takeover if a password leaks. See two-factor authentication.
Complete ID and face verification only inside the official App under Me → Identity verification. Never send ID photos to email, social apps, or unknown links.
If a fake “support” agent asks for ID photos, seed phrases, full card numbers, or CVV, stop and verify via in-app official support. See the anti-fraud guide and emergency help.
❓ FAQ
Is it safe to upload my ID to MPChat?
Upload only inside the official App under Me → Identity verification. ID images and face checks are handled by Sumsub; MPChat does not receive or store raw images or biometric templates — only outcomes and structured fields. Never comply with proactive requests for ID photos by email or chat.
Can MPChat staff read my private chats?
No. Private chats use end-to-end encryption. Decryption keys stay on your and your contacts’ devices. MPChat servers do not hold those keys and cannot decrypt private chat content.
Are my Pay funds simply “held by MPChat alone”?
A more accurate description is layered: account balances are ledgered by MP PAYMENT INC, while underlying on-chain USDT sits in Cobo and HashKey custody solutions. Staff cannot unilaterally move funds; freezes or payment stops may still apply under the agreement for compliance and risk.
Why does the Web3 wallet have no seed phrase? Can I export to MetaMask?
MPChat Web3 is built on Turnkey: keys are generated and signed inside a TEE. The product does not display a seed phrase today, and export to external wallets is not currently available. This reduces seed-phrase phishing risk; rely on in-app capabilities for the current feature set.
Why does viewing the card number need to load? Does that mean it leaked?
The opposite: full card secrets are not persisted locally or on MPChat servers. Viewing them triggers a live API call to the card issuer, so a short load is expected. A failed load is usually a network or API issue — not proof that secrets leaked.
📚 Related articles
💬 Still concerned? Contact official support
For any request involving ID photos, card secrets, or seed phrases, first verify inside the App that it comes from official support.
Contact us through in-app customer support in the MPChat App. Do not send ID photos to unknown links or unofficial channels.
This guide is for help-center reference only and is not legal advice. Account and fund rules follow the current User Agreement, Card Terms, and in-app notices.
