Privacy Policy
Squeek is built with respect for personal space. Here, plainly and specifically: what data we keep, what of it we are technically able to see and what we are not, how long it is kept, and what you can do about it.
1. Who is responsible for the data
The data controller is Vladyslav Nesterov, a private individual and citizen of Ukraine (the “Developer”, “we”). Processing follows the law of Ukraine, including the Law of Ukraine “On Personal Data Protection”. For any question about your data, write to the email address at the bottom of this page.
2. Account data
Using Squeek requires an account. For it we store:
- your email address — it is your login; at sign-up we send it a confirmation code, and you cannot sign in until it is confirmed;
- your password — only as a cryptographic hash (bcrypt); we do not store the password itself and cannot see it;
- the name and username other users see, plus an avatar and a short profile description if you add them;
- your public encryption key and your private key encrypted with a twelve-word recovery phrase. Only you have the phrase; we can neither decrypt that key nor recover the phrase;
- your plan and the settings you change in the app (for example, hiding the typing indicator).
3. Sessions, devices and notifications
To keep sign-in secure and deliver notifications, we store technical data about your devices:
- for each sign-in — the IP address, device and app details (user agent), the time of sign-in and of the last activity; a session is kept until you sign out or it expires;
- the push notification token, platform and device name — so notifications reach your phone;
- confirmation codes sent by email are stored as a hash, are valid for a short time and are then deleted;
- if you add another device by scanning a code in the app, it receives your keys and full access to your conversations — the same as the main one.
4. Conversations: what we are technically able to see
Different kinds of conversations are protected differently, and that difference is what decides what the Developer can access.
- Private chats and groups are end-to-end encrypted: messages and files are encrypted on your device and decrypted only on the participants’ devices. The server holds only ciphertext and a key wrapped for each recipient, and has no technical means to read the content.
- Channels and the discussions beside them are encrypted on the server with a key held by the Developer. Their content, polls and message reports are technically accessible to the Developer. We do not read them as a matter of routine, but we cannot claim we are unable to.
- For every conversation the server sees service data: who is in which chat, who sent a message and when and how large it is, reactions (emoji), read marks, pins, edits and deletions, self-destruct timers, and system messages — who joined or left, calls and their duration. These are not encrypted.
- Bots. A bot is an account run by another user’s program. A bot added to a group or channel receives a copy of every message from the moment it is added, and in a private chat with a bot — everything you write to it. Its owner sees that, not the Developer. Participants get a system message when a bot is added.
- Messages sent to a bot through its webhook link reach the server in the clear from whoever called the link, and are encrypted for the recipient only after that.
5. Calls
Audio and video calls connect devices directly (WebRTC), and the stream between them is encrypted. The server only relays signalling — who calls whom, when, whether the call was accepted and how long it lasted — and has no access to the audio or video. Google STUN servers are used to discover network addresses; in a direct connection your IP address becomes known to the other party.
6. The copy on your device
So that chats open instantly, the app keeps a decrypted copy of your conversations and downloaded files in its protected storage on the device, and the keys in the system’s secure storage. That copy is as safe as the device itself: anyone with access to the unlocked phone can read it. Its size is shown in Settings, where it can also be cleared.
7. How long it is kept
The server is not an archive of your conversations. The periods are:
- messages and files stay on the server for a limited time that depends on the sender’s plan: 90 days from sending on the free plan, 180 on Premium, 365 on Premium Plus. After that they are deleted from the server for good; the copy on your device stays;
- if a chat has a self-destruct timer, messages are deleted from the server when it runs out;
- messages you delete by hand are emptied at once; only an empty record remains so that replies to them keep their link;
- account data is kept for as long as the account exists; the volume of files sent per month is counted to enforce the plan;
- server logs are kept for the limited time needed for security and troubleshooting.
8. Notifications and email
To get messages through, we rely on third-party delivery services:
- push notifications go through Expo Push Service (Expo, USA) and on through Google Firebase Cloud Messaging or Apple Push Notification service. Message text never goes into a notification — only the sender’s name or the chat name, the fact of a new message, a mention or a reaction;
- confirmation emails are sent through Resend (Resend, Inc., USA), which receives your address and the contents of the email for that purpose.
9. Server logs, metrics and updates
To run the service we process a minimum of technical data and use no third-party analytics or advertising trackers — neither on the website nor in the app.
- the web server keeps standard request logs for the site, the API and downloads: IP address, time, requested address, browser or app details;
- we collect anonymous service metrics — counts of connections, messages, uploads, calls, notifications and emails sent — with no content and no link to individual people;
- on launch the Android app asks squeek.net whether a newer build exists and downloads it from there when you say so; those requests land in the site’s logs like any other.
10. What other users see
Some data is visible to others by the nature of a messenger:
- your name, username, avatar and profile description — to anyone; you can be found in search by username;
- whether you are online and typing (the typing indicator can be hidden on a paid plan), and whether you have read a message;
- your membership in groups and channels — to their participants; groups and channels are visible in search by default and anyone can join unless the owner turns that off;
- bot owners see what their bots receive (section 4).
11. Who we share data with
We do not sell data and do not share it for advertising. Data is processed only by those without whom the service does not work:
- the hosting provider whose servers Squeek runs on;
- Resend — email delivery; Expo, Google and Apple — push notification delivery; Google — STUN servers during calls (sections 5 and 8);
- Ukrainian public authorities — only where the law expressly requires it. We cannot hand over the content of end-to-end encrypted conversations, because we have no access to it.
12. Your rights and controls
Under the law of Ukraine you have the right to know what data about you is processed, to have it corrected or deleted, and to object to processing. To exercise them, write to the email address below. In the app itself you can:
- change your name, avatar and profile description;
- delete your messages for all participants and set self-destruct timers;
- block users — a blocked user cannot message or call you; leave groups and channels; hide private chats;
- clear the local copy of conversations and files in Settings;
- delete your account — in your profile, confirmed with your password. We erase the profile, keys, sessions and everything you sent, files included; groups and channels you owned are deleted and your bots are switched off. Messages already delivered to other participants remain on their devices, and in shared chats they see “Deleted account” where your name was.
13. Security and its limits
Data between the app and the server travels over an encrypted channel (TLS), passwords are stored as hashes, and encryption keys are created on your device and leave it only encrypted with your recovery phrase. At the same time Squeek is a beta product: we do not guarantee the absence of vulnerabilities, and as of this edition a forgotten password or a lost recovery phrase means losing access to the account or to the message history respectively. We will announce incidents affecting your data that come to our knowledge in the app or on the website.
14. Age of users
Squeek is intended for people aged 18 and over. We knowingly collect no data about children; if we learn of an account belonging to someone under 18, we will delete it.
15. Changes to this Policy
We update this page as the product evolves; the date of the current edition is shown at the top. We announce material changes in the app or on the website. Continuing to use the service after a change takes effect means you accept the new edition.
Contact us: [email protected]