Ajyal app privacy
Data processed by the Ajyal app, access controls, retention, deletion and their limits.
Account and profile
We use email, a derived password hash, nickname, date of birth, gender, account ID and public number for account access, eligibility, permissions and attribution. Date of birth is private. Email confirmation or declaring an age of 18 or over is not identity verification.
You can control age, gender, presence, last-seen, read-receipt and contact-request settings. A photo is optional: choose a library avatar, upload a photo or add no photo. Biography, country and interests are fields the account holder chooses to share. The app does not obtain your geographic location from the device.
An uploaded profile photo is checked and re-encoded as a 512×512 JPEG with unnecessary metadata removed. Replacement or removal changes the active copy; it does not instantly erase backups or a copy another person saved.
Conversations and access
Text, images and voice messages you choose to send are stored with their author, ordering, time and reading state needed for conversation and duplicate-safe retries. Membership, room history policy and blocking govern room access; a private conversation is available to its authorized participants.
Conversations are not end-to-end encrypted. External connections use HTTPS, WSS and encrypted WebRTC transport. Infrastructure and database operators can technically access stored data. Moderation does not provide a general browser for private conversations: authorized reviewers access specific reported evidence within its retention period, with access auditing.
Blocking overrides friendship and prevents new contact and requests; unblocking does not restore friendship. Earlier private text may remain for both participants, while retrieving private attachments is denied during a block. Ajyal cannot erase an independent copy someone saved outside the app.
Live voice and stored voice messages
Listening does not turn on your microphone. Speaking requires an explicit action, and media is transmitted to authorized participants through the voice service. Ajyal does not create automatic recordings or hidden transcripts of live conversations.
A voice message you explicitly record and send is stored as an attachment. This differs from broadcasting a selected local file or sharing playback from an eligible Android app with system consent: these are live audio sources, and the server retains no copy of the file or capture recording. Local filenames and the app selection list and icons remain on the device; the server stores temporary reservation and permission state.
Selecting or previewing a source does not start broadcasting. Losing permission stops the source, and reconnecting does not automatically resume a microphone or source. Device acceptance is separate from implementation.
Phone notifications, Expo and Firebase
The Android notification integration uses Expo Push and Google Firebase Cloud Messaging. Device routing tokens, installation identifiers and technical connection data are processed to route notifications. Using FCM does not mean Firebase stores Ajyal conversations or passwords.
Ajyal sends the push provider two random, short-lived delivery and account-binding identifiers, without message text, sender names or room names. The device checks its current account, and the server rechecks blocking, muting, membership and subscription before display and on opening. Message content is hidden from lock-screen notifications by default; opting into content and system settings may change presentation.
Logout and account deletion invalidate the session binding. A local installation identity may remain to protect account switching. Detaching Ajyal is not a verified request to erase all Firebase identifiers, Expo logs or provider backups; immediate erasure is not promised. Actual notification delivery is tested separately.
Operations, providers and measurement
Accounts, conversations, attachments and voice run on the project's private hosting. Connection information such as IP addresses and operational logs are processed to provide and protect the service. Final operator, processing country, contractual and log-retention details are not yet approved.
The support@ajyal.love mailbox at Porkbun is the approved contact channel. Privacy requests you email are also processed by email providers. Automated account confirmation and recovery mail is temporarily disabled while permission under the provider's plan remains unresolved; annual renewal alone does not establish permission. Account availability is shown on the download page.
Limited measurements are linked to account IDs and are not anonymous: successful voice joins, mutual sending, returning within a week, sending failures, reports and handling time. Message text and audio are not copied for analytics. The behaviour described here uses no advertising, address book or payment data.
Expo and Google may process service data outside the hosting country. Recipients, agreements, transfer arrangements, operator details and an appropriate lawful basis for each purpose require completion and review; they are not inferred from an SDK or developer account.
Actual retention and erasure limits
The author may delete a private message for both participants before 60 seconds have elapsed under server time; the operation is refused at 60 seconds. A deletion marker prevents replaying an old send. This deadline does not remove account-deletion or privacy requests.
After 30 days without a new private message, maintenance targets the whole conversation history and ordinary attachments for both participants; friendship and request rejection remain independent. It targets rooms after 30 inactive days; connected or unresolved voice conservatively prevents deletion.
Specific reported evidence and its attachment remain protected until 90 days after the report was submitted, without copying the rest of the conversation. Reading permission expires at that boundary, followed by maintenance removal. Active sanctions and open appeals have separate reason-retention rules and do not extend the reported snapshot's lifetime.
Detailed measurement events and activity days expire after 14 days. Account sessions last 7 days and an account-deletion status receipt lasts 24 hours. Some ID, protected-number, block, rejection and audit references do not yet have approved final retention periods; this is a defined gap, not a promise to erase every trace.
Deleted attachments become inaccessible in the database before physical removal. Failures and scheduled cleanup may delay erasure. No confirmed erasure schedule covers all existing backups; one must be approved and previous erasure decisions reapplied after restoration. Instant deletion from backups or another offline device is not promised.
Export, account deletion and contact
Open the Account tab and select Export data or delete account. The flow asks for your current password and remains available during a platform sanction. Export includes your details, settings, authored text and media you are authorized to download; it excludes other people's text, credentials and protected moderation evidence.
Account deletion removes profile and login details, revokes sessions, closes rooms you founded, redacts your messages and removes ordinary media within the policy scope. The other participant's messages remain until conversation inactivity expiry; permitted evidence and the references above may remain. Deletion is final and is not performed by uninstalling the app.
You can request deletion or ask about your data without reinstalling the app through the account-deletion page and approved email address. Execution requires account-ownership verification. Do not send a password, verification code, identity document or other people's conversations in the initial request. Operator details and legal and operational handling deadlines remain incomplete; no deadline or authority is invented here.
Behaviour last reviewed: