Русский · English

Privacy Policy

Qidra · web-qidra.com · updated 31 August 2026

In short: we cannot access the content of your conversations. It is encrypted on your device and decrypted only on the recipient’s device. We store the encrypted form and cannot read it — not on request, not by mistake, not on demand.

One exception you should know about: a meeting summary produced by the secretary is stored in the conversation as an ordinary message and is not encrypted — that text is readable by the server. ⚠️ The secretary works: any participant can start it, butrecording begins only once everyone in the call has agreed. Who declined is never disclosed, and one refusal cancels the recording for everyone.

What we store

To make sign-in work: your email address. Without it an account cannot be recovered, and we have no other way to give a person their access back.

What you entered yourself: first name, last name, @username, photo, profile background, phone number. All of it is optional except the name, and any of it can be hidden — the app has a separate “who sees what about me” section.

Your conversations: encrypted messages and attachments, who belongs to which conversation, and send times. Content — in encrypted form only.

A backup copy of your message key — if you enabled one. When you set a PIN, your device locks the key with that PIN and sends us the locked form. We keep it so you can restore your conversations on a new phone, and we cannot open it without your PIN — neither we nor anyone else. If you never set a PIN, no copy exists at all. You can remove it in the app, together with the PIN.

Your devices: device name, internet address and the approximate city derived from it. This exists so that you can spot someone else signing into your account and end that session. The city is resolved on our own server from a built-in table — nothing leaves us for that.

The “online” flag and last-seen time — unless you hid them in settings.

If you reported a problem to us: your text, optionally a screenshot, and the device details you agreed to attach.

What we do NOT do

We do not read your messages. We technically cannot: the key belongs to the person, not to us. The only thing we may hold is a copy of that key locked with their PIN, and without the PIN it does not open.

We do not upload your phone contacts and do not match them against our database.

We show no ads and sell no data — in any form, to anyone.

We do not track you outside Qidra: we run no analytics counters and no advertising identifiers.

We do not track your location ourselves — you send it, from a conversation. But when you do, the phone determines your location precisely, not approximately. A single point stays in the conversation as an ordinary message and is stored with it; live location travels through our server to the people in that conversation and is not stored by us.

We never ask for your twelve words. Neither our server nor our support knows them. Anyone asking for them in our name is an impostor.

The crypto wallet

The wallet key is derived on your device from your twelve words and never leaves the device. The server stores only the public address — the one people use to send you funds; it can be hidden in settings.

Transfers go directly over the Tron network. We do not hold your funds, do not act as an escrow, and promise no income of any kind.

Who we share data with

We do not sell or share data for advertising. Sharing happens only where the service would not work without it, and only to the extent required:

  • DigitalOcean — servers, database and file storage (Germany). Everything stored there is encrypted.
  • Backblaze B2 — a second copy of backups, encrypted with our own key (USA).
  • Resend — sign-in code emails.
  • Twilio — phone number verification and a fallback path for calls.
  • Google Firebase and Apple — push notifications. A notification carries only what you allowed to be shown: the message preview can be turned off.
  • LiveKit — audio and video relay in group calls of three or more participants, and from two in a channel broadcast. The frames are locked with a key known only to the participants’ phones: the node forwards them sealed and cannot open them.Switched on 27 September 2026 and tested in a real three-way call — with cameras, microphones and speakerphone. ⚠️ Before that (4–27 September) the frames travelled in the clear, and that was stated here honestly. ⚠️ The lock is lifted while the meeting secretary is running — it needs the audio of the conversation — and a standing notice says so during the call. Channel broadcasts have no encryption at all and never will: a thousand viewers would not be possible otherwise.
  • DeepL and OpenAI — message translation, speech transcription and meeting summaries. These are started by a tap, but one person taps and the content of the whole conversation leaves: turning on the meeting secretary sends the audio of the entire call — yours and the other person’s — for transcription. Translating someone else’s message or document sends their text there too. ⚠️ That is why the two are handled differently: the secretary asks everyone, before recording starts; speech translation does not ask — the speaker is warned during the call («your words are sent as text to an outside service») and can stop it with one tap; the refusal is remembered and can be undone in settings. This is how it works since 25 September 2026: before that we asked for consent, but a question in the middle of a call was unclear to people and almost nobody used the feature.

If a government authority demands data, we can hand over only what we have: the email address, sign-in times and encrypted data. We do not hold the content of conversations and are not able to produce it.

How long we keep it

Messages and files — until you delete them. Delete for everyone and they disappear both from us and from the recipient. A chat can be set to self-destruct, and then messages go away on their own.

Database backups are kept for up to 30 days in encrypted form. Deleted data disappears from them as the backups rotate.

You can delete your account at any time: app → profile → scroll to the bottom → “Delete account”. Your sign-in, name, photo, phone, contacts, devices and keys are removed. Messages you sent to other people stay in their conversations: that copy belongs to them and we may not erase it — you appear there as “Deleted user”. The full procedure is on the account deletion page. You can also switch on automatic deletion after a long period of inactivity — it is off by default.

Children

Qidra is not intended for children. The app is declared as 18+ in the app stores: it contains a crypto wallet, and the rules for those are not addressed to children. We deliberately do not collect age information and make no assumptions about it.

Your rights

You can view and change your data in the app, hide any field from others, take your conversations with you, and delete the account entirely. A separate “Privacy check-up” screen in the app shows, on a single page, what is visible about you and to whom.

How to reach us

You can write to us straight from the app: profile → help. That way your message reaches us inside Qidra, without a single email and without exposing your contacts. If the app is not at hand — [email protected].

If we change this page, the update date at the top changes with it. We will announce material changes in the app.