Privacy
Privacy Policy
Effective date: October 6, 2026. Publisher: AnzenApp.
Contents
Anzen is a chat app published by AnzenApp. This policy describes what the current app and API do with information. The legal entity is [TODO: owner to confirm legal entity name, e.g. AnzenApp LLC].
This is not a promise about a feature the software does not have. Where a choice is not settled in the product, it is marked for the owner.
What we collect and why
We collect only what the service needs to create an account, deliver messages, and keep sign-in safe.
Account. You give an email address, a username, and a display name. The email address receives sign-in codes and a notice when a new device signs in. The server stores the email address, the username, the display name, the plan (free or paid), and timestamps for when the account was created and last active. There is no password. A leftover database column can hold a password hash, and the current sign-in flow does not ask for or check a password.
Sign-in secrets. A one-time email code is stored only as a hash, with a short expiry and a limit on guesses. If you add an authenticator app, the server stores the authenticator secret sealed at rest. The API can open that seal to check a code, because the seal key is a server secret, not your PIN. If you add a passkey, the server stores the passkey credential the authenticator returns. Short-lived sign-in sessions for those checks are deleted when they expire.
Keys. Each account has a public quantum-proof key (ML-KEM-1024). Each device has its own public key. The server also stores a wrapped copy of the account private key. The recovery secret that unwraps it stays with you. The server does not have that recovery secret.
Messages and files. The server stores ciphertext, a nonce, a key envelope for each recipient, the scheme name, who sent it, which conversation it belongs to, and the time. Files are separate encrypted blobs tied to a conversation, an uploader, and, once sent, a message. The name, the type, and the file key travel inside the encrypted message.
Membership and invites. The server stores workspace and channel membership, roles, who joined and when, and notification mute choices. Invite codes are stored as hashes. An invite can last at most 7 days and has a use limit.
Devices. The server stores a device label, the device public key, when the device was verified, how long that device stays trusted (14 days unless you change it, including a choice of never), and when it was last seen.
Push tokens. If a build is made with push turned on, the server stores that device’s Firebase Cloud Messaging token and whether the device is Android, iOS, or web. Builds without those settings do not register a token.
Voice. The server stores who is in a voice channel, whether they are muted, deafened, or shown as speaking, and the call-setup messages it relays. It does not store the audio.
IP addresses and logs. The API uses the connection’s IP address to slow repeated sign-in attempts. That limit is kept in memory on the API process, not in a database table. When a new device signs in, the security email names the device, the time, and that IP address. The API writes operational messages to its own log, such as a failed email send. [TODO: owner to confirm how long Lightsail keeps container logs]
On your device only. The PIN vault that holds private keys is on the device. The PIN is not stored. Face ID or a fingerprint can release the key from the phone’s secure storage. Decrypted messages and files stay in memory until the vault locks. Link-preview allow lists, deny lists, and a short cache stay on that device. Android backups and device transfers exclude app data. iOS excludes the vault directory from backup.
This website. The marketing site does not run sign-in, does not send forms anywhere, and does not load an analytics script. Its only browser storage is localStorage key anzen-theme, which remembers light or dark mode. The site’s code does not set a cookie. [TODO: owner to confirm what connection logs Cloudflare keeps for this website]
End-to-end encryption
Messages use quantum-proof encryption (ML-KEM-1024). The app makes a random key for that message, locks the message with authenticated encryption (AES-256-GCM), and wraps the message key for each member. The server stores the sealed result so it can deliver it. It does not have the keys that open the message. A recovery key you keep is what lets a new device open the same history. AnzenApp cannot recreate that key.
Call audio is encrypted between the devices (DTLS-SRTP). Call setup is different: the server relays signaling, and that signaling is not end-to-end encrypted. If a TURN relay is configured, it carries encrypted packets so the other people see the relay’s address instead of yours.
What we can’t see
From the way the app is built, the server cannot read:
- Message text, replies, edits, or reactions
- File names, types, or contents
- Your PIN or your recovery key
- Voice audio
- Link addresses and preview titles, which are fetched by your device
- Decrypted pictures, which stay in memory until the vault locks
The server can see the account and device records above, ciphertext and its size, membership, who is typing (not the draft), who is in a voice channel, and the call-setup messages. A push notification, when push is on, names the sender and the channel or workspace. It does not contain the message.
Sharing and processors
We do not sell personal information. The app has no advertising or analytics SDK. We share information with service providers only so they can do the work below.
| Who | What they process | When |
|---|---|---|
| Amazon Web Services | The API and the PostgreSQL database on Amazon Lightsail in us-east-1, and sign-in email through Amazon SES | Whenever the service is running |
| Google Firebase Cloud Messaging | The push token, and a notification that names the sender and the place | Only if that build has push turned on |
| Apple Push Notification service | The same notification, on iPhone, through Firebase | Only if that iOS build has push turned on |
| Apple (App Store / TestFlight) and Google (Google Play) | The store account you use to install a test build | When you install from that store |
| Cloudflare | This website, which is a static site | When you open anzenapp.com |
A TURN relay is used only if one is configured. The repository does not name a relay vendor. [TODO: owner to confirm the voice-relay provider, if any is deployed]
Billing is not live. The API can record a plan change from a signed webhook, and a development upgrade switch exists only when it is explicitly turned on. No payment processor is integrated, and this site does not take payment.
Retention and deletion
What you can scroll depends on your plan. Free accounts load 30 days of history. Plus accounts load 10 years (3,650 days). Separately, an hourly job deletes messages sent by Free accounts once they are older than 30 days. Deleting a message deletes the file attached to it. An upload that no message claims is deleted after about an hour.
Sign-in codes, device challenges, and realtime tickets expire. Invite codes expire within 7 days. Revoking a device deletes that device’s key and its push token.
You can delete a message you sent, leave a workspace, sign out, and remove a device. The app has no control that deletes the whole account. [TODO: owner to confirm how someone asks for an account to be deleted, because the app has no delete-account control]
Security
Messages are sealed on the device before they are sent. Authenticator secrets are sealed at rest. A new device needs an email code and then an authenticator app or a passkey. After the trust window, the next check is authenticator-first. Sign-in attempts are rate-limited. The PIN vault is excluded from Android backup and from iOS backup.
No method is perfect. A person who knows your PIN, has your recovery key, or controls your unlocked device can read what that device can read.
Children
Anzen is not for children under 13, or under 16 in the European Economic Area. [TODO: owner to confirm how age is checked at sign-up, because the app does not ask for a date of birth]
International users and GDPR
The database is in the United States (us-east-1). If you use Anzen from the European Economic Area, the United Kingdom, or Switzerland, your information is processed there.
For those users, the legal bases we rely on are:
- Contract. Creating your account, delivering messages and files, and providing the plan you are on.
- Legitimate interests. Securing sign-in, rate-limiting abuse, and keeping the service running, where those interests are not overridden by your rights.
- Legal obligation. Where a law requires us to keep or disclose something.
[TODO: owner to confirm the GDPR transfer tool for data stored in the United States, such as Standard Contractual Clauses]
You can ask to access, correct, delete, or restrict your information, to receive a portable copy, or to object to processing based on legitimate interests. You can also complain to your supervisory authority. Some of those requests cannot be completed inside the app today, because there is no account-deletion or export control. Use the contact details below. We may need to confirm the request is yours.
US state rights
If you live in California, the CCPA/CPRA gives you the right to know, correct, and delete personal information, and to opt out of sale or sharing. We do not sell personal information, and we do not share it for cross-context behavioral advertising. If you live in Texas, the Texas Data Privacy and Security Act gives you similar rights to access, correct, delete, and opt out of sale and targeted advertising. We will not discriminate against you for using these rights.
To use a right, contact us. We will need enough information to find the account. [TODO: owner to confirm whether an authorized agent may submit a request, and how identity is checked]
Changes to this policy
We will post changes on this page and change the effective date. [TODO: owner to confirm whether a change is also sent by email or shown in the app]
Contact
[TODO: owner to confirm legal entity name, e.g. AnzenApp LLC][TODO: contact email][TODO: mailing address]
Until those details are filled in, do not send personal information to this website. The site does not accept it.