Data safety summary
This is a plain-language companion to the Privacy Policy. Store forms remain authoritative for the exact shipped binary.
Typical data types
| Category | Collected? | Notes |
|---|---|---|
| Buzzio ID / profile | Yes | Random ID and optional profile fields |
| Personal email / phone as account identity | No | Messaging identity is ID + phrase; developer OAuth is separate |
| Messages | Feature-dependent | Sealed ciphertext briefly; OHG / Community / Broadcast plaintext; bot text readable ~7 days |
| Photos / videos / files | Yes when sent | Privacy follows the surface; user→bot files up to 2 MB may remain ~7 days |
| Calls / audio | Yes as needed | Private call media is not recorded; TURN may see IP/port/timing |
| Location | Optional | Only when you choose to send it |
| Contacts | Optional | Only if contact sync is enabled |
| Purchases | Yes | Play / App Store entitlement status; not card numbers |
| Device / app IDs | Yes | Push, integrity, and configured analytics identifiers |
| Wallet data | Optional | Non-custodial; Bitcoin chain data is public |
Encryption boundaries
E2E message bodies: 1-to-1, Whisper private chat, E2E groups.
Not E2E: Open-history groups, Communities, Broadcast, Whisper Questions, bots.
OHG / Community / Broadcast use TLS in transit and store text and media without at-rest encryption. Buzzio can read them. Vault, backup, and Note to Self encrypt locally before upload.
Sale and sharing
- Buzzio does not sell personal data.
- Buzzio does not share it for cross-context behavioral advertising.
- Processors operate infrastructure; independent controllers process data under their own terms. See Subprocessors.