Privacy Policy
Publication date: 11 May 2022. Last update: 27 August 2026.
এটা কেবল জায়গা ধরে রাখার লেখা। এটা চূড়ান্ত আইনি টেক্সট নয় এবং এর উপর ভরসা করা যাবে না।
1. Definitions
1.1. Account - is a software part in which the User places files and confidential information and performs anonymous communication with another User.
1.2. Messenger Cryptico (hereinafter Messenger or Cryptico) - is software designed for the anonymous exchange of messages, calls and content between Users.
1.3. Cryptico Site (hereinafter Site) - means a web page or group of web pages on the Internet, which are located at: https://cryptico.chat/ 1.4. Cryptico Application (hereinafter Application) - is a type of software through which Users communicate anonymously and/or share content, available for Android and iOS and as a web version in a browser.
1.5. Controller - an entity which independently determines the purposes and means of processing of Personal Data.
1.6. Cookies - a small piece of information in the form of text or binary data stored by the browser at the request of a site.
1.7. Personal Data - means any information that directly or indirectly allows identifying the User. The Messenger has no phone numbers, no email addresses and no real names; the technical data that may identify a User indirectly is listed in clause 3.5.
1.8. Processor - an entity which processes Personal Data on behalf of a Controller.
1.9. Recovery Phrase - a sequence of 12 words from the standard BIP39 English word list, generated on the User device, from which all keys of the Account are derived. The Recovery Phrase is never transmitted to us and we never store it.
1.10. Services - an algorithm of actions that the Messenger provides the User in the field of anonymous messaging, calls and file exchange.
1.11. Third Party - means a natural or legal person, government agency, institution, or body other than the User, Controller, Processor, and persons authorized by the Controller or Processor under their direct supervision to process Personal Data.
1.12. User - an individual who creates an Account and uses the Application or the web version of the Messenger.
1.13. User Consent (hereinafter Consent) - means a voluntary, specific, informed, and unambiguous expression of will in which the User, using a statement or a clear positive action, agrees to the processing of the data described in this Privacy Policy.
2. General Provision
2.1. The processing of data follows the principles of Article 5 of the General Data Protection Regulation (GDPR): legality, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality.
2.2. For residents of the United States, the Messenger follows the California Consumer Privacy Act of 2018.
2.3. For residents of Ukraine, the Messenger follows the Law of Ukraine On Protection of Personal Data.
2.4. Cryptico acts as a Controller in respect of the limited technical data listed in clause 3.5 and as a Processor of the encrypted content which it transports on behalf of Users and cannot read.
2.5. Cryptico bears no responsibility for the processing of data by Third Parties outside its control, including the operators of the networks and devices used by the User.
3. Personal Data
3.1. The Messenger does not require Personal Data in order to create an Account. A User is a random identifier (UUID) and, optionally, a username chosen by the User.
3.2. Cryptico does not store the content of messages, calls, files, profiles, group names or contact lists in a readable form. Message content is stored only as encrypted data which we cannot decrypt; audio and video of calls is not recorded by us.
3.3. In connection with the Account, we hold:
3.3.1. the random identifier of the Account and of each of its devices;
3.3.2. the optional username;
3.3.3. the public keys published by the device of the User;
3.3.4. encrypted data blobs (messages awaiting delivery, encrypted attachments, and the encrypted private storage of the Account, whose record names are cryptographic hashes rather than readable text);
3.3.5. the list of members of the groups in which the Account participates;
3.3.6. the list of identifiers blocked by the User, which is stored in readable form and is automatically deleted 180 days after it was last confirmed. We do not hold the Recovery Phrase, private keys or session state, and we cannot restore access to an Account.
3.4. The Messenger does not collect special categories of data such as racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, data concerning health, sex life or sexual orientation.
3.5. Data processed automatically for the purpose of operating and protecting the Services:
3.5.1. the IP address of the connecting device, used to deliver traffic and to apply rate limits against abuse;
3.5.2. the routing data of each envelope, namely which Account and device sent it, which Account and device is to receive it, the time it was queued and the size of the encrypted payload;
3.5.3. the technical data needed to deliver push notifications, namely the push token of the device;
3.5.4. the fact and time of connection of a device to the Services. We do not collect the time zone, the browser and operating system fingerprint of the User, the country of the User, mouse movements, scrolling, clicks, page dwell time or any similar behavioural data, and we do not use web beacons or tracking pixels.
3.6. No Personal Data is collected for payment purposes, because the Services are provided free of charge and no payment data exists.
3.7. Data collected through the Site:
3.7.1. the Site does not use any third party analytics, advertising or tracking services;
3.7.2. the web server keeps short-lived technical logs which contain the IP address, for the purpose of security and rate limiting;
3.7.3. if the Site offers a waiting list form, the email address entered by the User and the time of submission are stored for the sole purpose of sending a single notification about the release, in a database which is kept separate from any messenger data, are never transferred to any third party marketing service, and are deleted at the request of the User sent to the address in clause 15.1.
3.8. Cryptico does not transfer Personal Data to Third Parties for any purpose, except to service providers strictly necessary to operate the Services and except to enforce court decisions or to comply with any legal obligations. Such necessary service providers are: the cloud provider Amazon Web Services, in whose data centres in Ireland our servers run and which therefore physically holds the encrypted data and the connection metadata described in clause 3.5 (see clause 4.5); the network provider which terminates connections to our servers and therefore observes IP addresses and connection times; and the push notification services of Apple and Google, which are used to wake a device and which do not receive the content of messages.
3.9. We can only disclose what we hold. Because we do not hold the content of communication, no legal request can compel us to produce it.
4. Personal Data Protection
4.1. The Messenger uses the necessary security measures for the protection of data and confidential information.
4.2. Protection is provided against loss and against illegal use, transfer, disclosure, modification, deletion and/or destruction.
4.3. Security measures in accordance with Article 32 of the GDPR:
4.3.1. pseudonymisation and encryption. Communication between Users is end-to-end encrypted with the Signal Protocol using the libsignal library, so that the encryption keys exist only on the devices of the Users; the key agreement includes a post-quantum component; data stored on the device is encrypted with a key derived from the Recovery Phrase;
4.3.2. the ability to ensure the ongoing confidentiality, integrity, availability and resilience of the systems;
4.3.3. regular testing and evaluation of the security measures, including automated checks which prevent a release if the server is changed in a way that would let it read message content.
4.4. The Recovery Phrase is generated on the device of the User, is never transmitted to us, and is derived into keys using deliberately slow and memory-hard computations so that guessing it is impractical.
4.5. The Messenger does not own the hardware on which it runs. The servers of the Messenger are hosted in the data centres of Amazon Web Services in Ireland, that is, on the territory of the European Union. Amazon Web Services acts as a Processor and physically holds the encrypted data and the connection metadata described in clause 3.5; it has no means of reading the content of communication, which is encrypted end to end. Should the place of processing change, this Privacy Policy will be updated before the change takes effect.
4.6. We do not claim that the fact, time or size of a communication is hidden from us. Content is protected cryptographically; the metadata described in clause 3.5 is not.
5. Basis for Processing Personal Data
5.1. The Messenger processes only the limited technical data described in clause 3.5, which is necessary for the performance of the Services requested by the User and for our legitimate interest in keeping the Services secure and available.
5.2. Where processing is based on Consent, that Consent is given by the User by creating an Account and using the Services, and, in the case of the waiting list described in clause 3.7.3, by submitting the form.
5.3. The User may withdraw Consent by deleting the Account in the Application or the web version, or by writing to [email protected].
5.4. The Messenger undertakes to cease the provision of the Services within 10 (ten) business days of the withdrawal of Consent.
6. Jurisdiction of the European Union and the European Economic Area
6.1. Residents of the EU and the EEA have the following rights:
6.1.1. Right of access, in accordance with Article 15 of the GDPR. On request, the User is informed of what we hold in respect of the Account, as listed in clause 3.3; the content of communication is encrypted and is not accessible to us.
6.1.2. Right to erasure, in accordance with Article 17 of the GDPR. The User exercises it by deleting messages and chats and by deleting the Account, after which the data associated with the Account is deleted from our systems.
6.1.3. Right to rectification, in accordance with Article 16 of the GDPR. The User updates, corrects and supplements the data independently in the Application, since we have no access to it.
6.1.4. Right to data portability, in accordance with Article 20 of the GDPR. The data of the User is held on the device of the User and can be transferred by the User; we can only provide the data listed in clause 3.3.
6.1.5. Right to object, in accordance with Article 21 of the GDPR, exercised by deleting chats, messages and the Account.
6.1.6. Right to lodge a complaint with the supervisory authority of the state of residence of the User.
6.2. Requests must contain accurate information; a request which does not allow us to understand what is asked may be refused.
6.3. The Messenger responds within 21 (twenty-one) business days.
7. US Jurisdiction
7.1. This section applies to residents of the United States under the California Consumer Privacy Act of 2018 (Cal. Civ. Code sections 1798.100-1798.199).
7.2. The Messenger does not respond to Do Not Track browser signals within the meaning of CalOPPA, and it also does not perform the tracking that such signals are intended to prevent.
7.3. Residents of the United States have rights comparable to those of residents of the EU:
7.3.1. right of access, as described in clause 6.1.1;
7.3.2. right to erasure, as described in clause 6.1.2;
7.3.3. right to rectification, as described in clause 6.1.3;
7.3.4. right to data portability, as described in clause 6.1.4;
7.3.5. right to object, as described in clause 6.1.5.
7.4. We do not sell and have never sold personal information, and we do not share it for cross-context behavioural advertising.
7.5. Requests must contain accurate information; a vague request may be refused.
7.6. The Messenger responds within 21 (twenty-one) business days.
8. Jurisdiction of Ukraine
8.1. This section applies to residents of Ukraine in accordance with the Law of Ukraine On Protection of Personal Data.
8.2. Users who are residents of Ukraine have the right:
8.2.1. to know about the sources of collection, the location of their data and the purposes of its processing;
8.2.2. to receive information about the conditions of access to their data, including information about Third Parties to whom it is transferred;
8.2.3. to receive a response within thirty calendar days on whether their data is processed;
8.2.4. to submit a reasoned request objecting to the processing of their data;
8.2.5. to submit a reasoned request for the change or deletion of their data;
8.2.6. to protection against unlawful processing and against accidental loss, destruction or damage of their data, and against the provision of inaccurate information;
8.2.7. to make complaints to a court regarding the processing of their data;
8.2.8. to use legal remedies in case of violation of data protection law;
8.2.9. to make reservations restricting the right to process their data;
8.2.10. to withdraw consent;
8.2.11. to know the mechanism of automatic processing of their data;
8.2.12. to protection against an automated decision which has legal consequences for them.
8.3. Requests must contain accurate information; a vague request may be refused.
8.4. The Messenger responds within 21 (twenty-one) business days.
9. Jurisdictions of Other Countries
9.1. The Messenger provides the Services in accordance with international standards.
9.2. This Privacy Policy addresses the main legislation on the processing of data.
9.3. We cannot specify the law of every jurisdiction in the world.
9.4. This Privacy Policy describes the basic rights of the User arising from the leading legal acts on data protection.
9.5. If the User has any concern regarding this Privacy Policy, the User may write to [email protected], and the Messenger will address the issue within a reasonable time.
10. Responsibility
10.1. The Services are provided without the collection of Personal Data, and the absence of such data is a property of the design of the Messenger.
10.2. The User must not access, modify, distribute, transfer or exploit the Services in an unauthorized or harmful manner. In particular, the User must not gain unauthorized access to the Services, disrupt their performance, create Accounts by unauthorized automated means, collect information about other Users by unauthorized means, or sell or rent the Services.
10.3. The Messenger is not responsible for:
10.3.1. the loss of data as a result of hacker attacks, the hacking of software, the illegal actions of Third Parties, the illegal actions of the User, or the violation of this Privacy Policy;
10.3.2. the accuracy of the information transferred between Users;
10.3.3. the content of the messages exchanged between Users;
10.3.4. insults which Users inflict on each other during anonymous communication.
10.4. The Messenger does not record audio or video, does not take screenshots, and does not view the information shared by Users.
10.5. Transmission over the Internet cannot be guaranteed to be completely secure; the User bears responsibility for the transfer of data from the device of the User, and the Messenger implements technical measures of security on its side.
10.6. The loss of the Recovery Phrase makes the Account permanently inaccessible, and the disclosure of the Recovery Phrase to another person gives that person full control of the Account. In both cases the Messenger cannot intervene.
11. User Consent
11.1. Consent is given by the User:
11.1.1. by creating an Account and using the Services;
11.1.2. where a form is submitted on the Site, by submitting that form.
11.2. By accepting this Privacy Policy, the User agrees to:
11.2.1. the processing by Cryptico of the technical data described in clause 3.5;
11.2.2. the transfer of that data to the necessary service providers listed in clause 3.8;
11.2.3. the transfer of encrypted content to the Users with whom the User chooses to communicate.
11.3. Consent may be withdrawn as described in clause 5.3.
12. Cookies
12.1. Cookies are small files stored by the browser of the User which allow a site to remember a preference.
12.2. The Site uses cookies only where they are strictly necessary for a function requested by the User. At present this is a single cookie which stores the interface language chosen by the User on the Site, so that the chosen language is used on the next visit.
12.3. The Site does not use analytics cookies, advertising cookies, third party cookies, web beacons, tracking pixels or any other tracking technology, and it does not load content from third party hosts for such purposes.
12.4. Because only a strictly necessary cookie is used, no cookie consent banner is displayed. The User may refuse or delete cookies in the settings of the browser; the only consequence is that the Site will not remember the chosen language.
12.5. Cookies do not transmit viruses and do not affect the operation of the device of the User.
12.6. The Application and the web version of the Messenger store data on the device of the User in order to work, including the encrypted local database of the Account. This data is not a cookie, is not transmitted to us in readable form, and is removed when the User deletes the Account or the application data.
13. Age Policy
13.1. The Services are intended for Users who have reached the age of sixteen. We do not knowingly provide the Services to a person under that age.
13.2. Since the Messenger does not collect real world identifiers, it cannot verify the age of the User. Where we are made aware that an Account belongs to a person under the age of sixteen, we may terminate the provision of the Services to that Account and delete the data associated with it without warning.
13.3. The use of the Services by a person under the age of sixteen may be reported to [email protected].
14. Changes to the Privacy Policy
14.1. The Messenger may modify this Privacy Policy in order to preserve the security of data and to comply with legislation. The current version of this Privacy Policy was published on 11 May 2022 and last updated on 27 August 2026.
14.2. The User is obliged to familiarise himself or herself with the new terms; the Messenger is not responsible if the User has not read them.
14.3. Copies of this Privacy Policy retained by us are considered authentic and valid in the version in effect at the time of the visit of the User to the Site or the Application; the continued use of the Services implies agreement with the new terms.
15. Contacts
15.1. The User may contact the support service of the Messenger at [email protected] in order to exercise his or her rights, to report a violation of those rights, or to ask a question.