Privacy Policy
Last Updated: January 2025
Introduction
Tapala is a zero-knowledge end-to-end encrypted messaging platform. We're built on the principle that we can't read what we can't decrypt. This privacy policy explains what data we collect, how we use it, and your rights.
Data Controller
The data controller for Tapala is 13n4, operated from Hyderabad, India.
For privacy concerns or queries, contact us at: [email protected]
What Data We Collect
We collect minimal data necessary to operate the service:
- Phone Number: Used for authentication and account identification
- Username: Your chosen display name for the platform
- Device Information: Device identifiers and cryptographic keys for end-to-end encryption
- Encrypted Message Envelopes: We store encrypted messages we cannot read for up to 30 days to enable offline message delivery
What We Cannot See
Due to our zero-knowledge architecture:
- Message content (all messages are end-to-end encrypted)
- Media files (encrypted before upload)
- Conversation metadata beyond participant lists
How We Use Your Data
- To authenticate and identify your account
- To deliver encrypted message envelopes to your devices
- To enable secure communication between users
- To maintain and improve the service
Third-Party Services
We use Firebase for:
- Analytics: To understand app usage and performance
- Crash Reporting: To identify and fix bugs
- Push Notifications: To notify you of new messages
Firebase may collect device information and usage data as described in Google's Privacy Policy.
Data Sharing
We do not share, sell, or rent your personal data to third parties. Your phone number and username remain private and are only used within the Tapala platform.
Data Retention
- Account Data: Retained while your account is active
- Encrypted Messages: Stored for up to 30 days to enable offline delivery, then automatically deleted
- Account Deletion: When you delete your account, all associated data is permanently deleted from our servers
Account Deletion
Account deletion functionality is currently in development. Once available, you'll be able to delete your account through the app settings. Upon deletion, all your data will be permanently removed from our servers.
To request account deletion before this feature is available, contact [email protected].
Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account and associated data
- Export your data (where technically feasible)
To exercise these rights, contact [email protected].
Security
We use industry-standard security measures including:
- End-to-end encryption using the Double Ratchet protocol
- Perfect forward secrecy for all messages
- Secure key exchange using X3DH
- HTTPS for all data transmission
Children's Privacy
Tapala is not intended for users under 13 years of age. We do not knowingly collect data from children under 13.
Changes to This Policy
We may update this privacy policy from time to time. We'll notify users of significant changes through the app or via email.
Contact Us
For questions, concerns, or requests regarding your privacy, contact us at: