Privacy Policy
Last updated August 4, 2026
This Privacy Policy is issued by [Legal entity name, registered address — insert before publishing] ("Bisiq," "we," "us"), the operator of the Bisiq application and related services (the "Service"). It explains what information we collect, why, and — just as importantly — what our architecture makes it impossible for us to collect. This draft is a starting point; have it reviewed by qualified counsel in your operating jurisdiction before publishing.
1. The short version
Bisiq is built so that message content never reaches our server. Two devices talk to each other directly, end-to-end encrypted; our server's job is limited to identity, matchmaking, connection signaling, and waking a sleeping device. We collect the account and operational data described below to run that service — we do not, and architecturally cannot, read your conversations.
2. Information we collect
2.1 Account information
- Username, display name, and profile photo you choose to set.
- Phone number, if you link one — used for password recovery and account notifications via SMS.
- Password (stored as a salted hash, never in plaintext) and, if you set them, hashed answers to account-recovery security questions.
- Public identity, signed prekey, and one-time prekey material — published so other users can encrypt messages to you. The corresponding private keys never leave your device.
- Device push token, device type, and app version, to route notifications and pushes.
- Account tier/level and subscription status.
2.2 Payment information
Paid tiers are processed by our payment partner (currently Midtrans). Card, e-wallet, and QRIS payment details are collected and processed by that partner under its own privacy policy — we receive only a transaction reference, status, and amount, which we use to activate or manage your subscription.
2.3 Connection & operational metadata
- That you and a contact connected, and roughly when — needed to route signaling and deliver push wake-ups. We do not log the content or subject of that connection.
- Coarse location, only while you have Near Me turned on — used solely to show you nearby, discoverable users. Off by default; you can disable it at any time, including a ghost mode and a precision dial that limits how exact the shared location is.
- Diagnostic and crash data (device model, OS version, error traces) used to fix bugs and keep the connection layer (WebRTC/TURN) reliable.
2.4 Content you choose to share with us directly
Feedback or support messages you submit through the in-app Feedback screen, and anything you include in an email to us, are stored so we can respond to you.
3. Information we do not collect
- Message content, in transit or at rest — messages are end-to-end encrypted on your device before they leave it.
- Your private keys, which are generated on-device and stored in your OS's secure hardware (Keychain/Keystore).
- A readable history of your conversations. In the pure peer-to-peer delivery model, message bodies are never written to a server-side inbox.
- Precise location, or any location at all, unless you have explicitly turned Near Me on.
If Bisiq's optional store-and-forward relay is enabled for reliability (to redeliver a message if the sender goes offline before the recipient wakes), the server temporarily holds an encrypted, unreadable ciphertext blob with a short time-to-live and deletes it once delivered or expired. It is never able to decrypt that blob.
4. How we use information
- To create and secure your account, and authenticate your device.
- To let other users find and connect to you (identity broker & key directory).
- To establish peer-to-peer connections (presence, signaling, NAT traversal via TURN).
- To wake your device with a silent push when a contact is trying to reach you.
- To process subscription purchases and manage your account tier.
- To power Near Me discovery, only while you have it enabled.
- To respond to feedback and support requests.
- To detect abuse, maintain security, and comply with legal obligations.
5. Who we share information with
- Payment processor (Midtrans) — to process purchases; they receive payment details directly.
- Push notification providers (Firebase Cloud Messaging, Apple Push Notification service) — to deliver wake-up pings, which never contain message content.
- Connectivity infrastructure (TURN/STUN relay) — sees only encrypted, DTLS-wrapped transport packets it cannot read.
- Hosting and infrastructure providers — to run our servers and database.
- Law enforcement or regulators — only where legally compelled, and limited to the account/metadata described above, since we hold no message content to disclose.
We do not sell your personal information.
6. Data retention
We retain account data for as long as your account is active. If you delete your account, we delete or anonymize account data within a reasonable period, except where retention is required for legal, security, or fraud-prevention purposes. Message content is never retained by us in the first place. Relay ciphertext (§3) is deleted automatically on delivery or after its time-to-live expires.
7. Security
Messages are encrypted end-to-end with modern authenticated encryption before leaving your device. Locally, your message history is stored in an encrypted database, and cryptographic keys live in your device's hardware-backed secure storage. We use industry-standard transport security (TLS) for all account-related API traffic. No system is perfectly secure, and we encourage you to keep your device and app up to date.
8. Your rights and choices
- Access, correct, or delete your account information from within the app, or by contacting us.
- Turn Near Me on or off, and control its precision, at any time in Settings.
- Unlink your phone number, subject to keeping a working account-recovery method.
- Request a copy of the account data we hold about you.
- Withdraw consent for any processing that relies on consent, without affecting processing already carried out.
Depending on where you live, you may have additional rights under local law — for example, Indonesia's Personal Data Protection Law (UU PDP No. 27/2022) or other applicable data protection regulations. Contact us to exercise any of these rights.
9. Children's privacy
The Service is not directed to children under 13 (or the minimum age required by your country). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will take appropriate action.
10. International data transfers
We may process and store data in countries other than your own. Where required, we rely on appropriate legal safeguards for such transfers.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date above and, for material changes, provide additional notice in-app.
12. Contact us
Questions about this policy or your data? Reach us at privacy@bisiq.app.