Kebijakan Privasi
Berlaku sejak 4 Oktober 2026 · Voryn versi beta
- Tidak perlu nomor HP, email, atau nama asli untuk mendaftar.
- Isi pesan, foto, dan voice note dienkripsi end-to-end. Kami tidak bisa membacanya.
- Tidak ada iklan, tidak ada pelacakan, tidak ada analitik pihak ketiga. Kami tidak menjual data.
- Kamu bisa menghapus akun kapan saja dari dalam app.
1. Tentang kami
Voryn adalah aplikasi chat yang dikembangkan oleh Sonny, pengembang independen di Surabaya, Indonesia ("kami"). Voryn saat ini dalam tahap beta tertutup. Pertanyaan tentang privasi bisa dikirim ke subrata.surabaya@gmail.com.
2. Data akun
- Voryn ID dibuat otomatis oleh sistem dan dipakai untuk login serta agar teman bisa menemukanmu. Secara teknis, sistem login memakai alamat email buatan yang diturunkan dari Voryn ID. Alamat itu bukan email sungguhan dan tidak bisa menerima pesan.
- Password disimpan dalam bentuk hash oleh penyedia autentikasi kami. Kami tidak bisa melihatnya.
- Nama tampilan, foto profil, dan status (opsional) terlihat oleh kontak dan anggota grupmu. Ketiganya tidak dienkripsi end-to-end.
- Recovery phrase (12 kata) hanya ditampilkan di HP-mu. Server hanya menyimpan hash-nya, yang dipakai untuk memverifikasi saat kamu lupa password. Kata-katanya sendiri tidak disimpan.
- Kunci publik enkripsi disimpan di server agar orang lain bisa mengirim pesan terenkripsi kepadamu. Kunci privat tidak pernah meninggalkan HP-mu. Jika kamu memulai dengan kunci baru, kunci publik lama tetap disimpan agar lawan chat masih bisa membuka riwayat lama di HP mereka.
3. Pesan dan komunikasi
Dienkripsi end-to-end (tidak bisa kami baca)
- Isi pesan teks, foto, voice note, dan kartu kontak yang kamu bagikan.
Disimpan di server tanpa enkripsi end-to-end
Data berikut diperlukan agar layanan berjalan:
- Metadata pesan: pengirim, penerima atau grup, waktu kirim, jenis pesan, tanda pesan diedit atau disematkan, dan waktu kedaluwarsa (timer hapus otomatis).
- Waktu pesan dibaca, hanya jika fitur "Kirim status dibaca" aktif. Fitur ini nonaktif secara default.
- Reaksi emoji pada pesan.
- Nama, deskripsi, dan foto grup, serta daftar anggota grup.
- Pesan sistem grup, misalnya "X telah keluar dari grup".
- Daftar kontakmu di Voryn dan permintaan kontak.
- Daftar pengguna yang kamu blokir. Daftar ini hanya bisa dilihat olehmu.
Tidak disimpan
- Indikator "sedang mengetik" dikirim langsung dan tidak masuk database.
- Status online atau "terakhir dilihat". Voryn sengaja tidak punya fitur ini.
4. Notifikasi
Kami memakai Firebase Cloud Messaging (Google) untuk memberi tahu HP-mu bahwa ada pesan baru. Sinyal yang dikirim lewat Google hanya berisi ID acak pesan dan pengirim, tanpa isi pesan atau nama. App kemudian mengambil pesan langsung dari server kami dan menampilkan notifikasi di HP-mu. Untuk ini kami menyimpan token notifikasi perangkatmu.
5. Izin perangkat
- Kamera untuk memindai kode QR saat menambah kontak atau memindahkan akun ke HP baru.
- Mikrofon untuk merekam voice note.
- Foto untuk memilih gambar yang ingin dikirim atau dipakai sebagai foto profil.
- Biometrik (sidik jari atau Face ID) untuk membuka App Lock. Proses ini ditangani sistem operasi HP-mu, dan kami tidak pernah menerima data biometrik.
- Jaringan lokal untuk memindahkan akun dan riwayat chat langsung ke HP baru lewat WiFi yang sama, tanpa melewati server.
- Sensor gerak untuk fitur privasi tampilan. Data sensor diproses di HP dan tidak dikirim ke mana pun.
- Notifikasi untuk memberi tahu pesan baru.
6. Data yang hanya ada di HP-mu
Kunci privat enkripsi, PIN App Lock, pengaturan fitur privasi tampilan, dan cache lokal disimpan hanya di HP-mu. Di Android, screenshot diblokir secara default.
Voryn tidak mengirim pesanmu ke layanan AI mana pun. Sebagian konten pendukung fitur app, misalnya teks bawaan, dibuat terlebih dahulu dan diunduh dari server tanpa melibatkan data pengguna.
Recovery Kit adalah kode cadangan berisi kunci privatmu yang dikunci dengan recovery phrase. Kamu sendiri yang membuat dan menyimpannya. Voryn tidak pernah menerima atau menyimpan Recovery Kit-mu. Siapa pun yang memegang Recovery Kit dan recovery phrase-mu sekaligus bisa memulihkan kuncimu, jadi simpan keduanya di tempat terpisah.
Penting: karena kunci privat hanya ada di HP-mu, jika HP hilang atau rusak tanpa Recovery Kit dan sebelum akun dipindahkan ke HP baru, pesan lama tidak bisa dibuka lagi. Kami pun tidak bisa memulihkannya.
7. Penyedia layanan pihak ketiga
- Supabase untuk database, autentikasi, dan penyimpanan file. Servernya mungkin berada di luar Indonesia.
- Google Firebase Cloud Messaging untuk sinyal notifikasi, seperti dijelaskan di bagian 4.
- Apple App Store dan Google Play untuk distribusi app, yang tunduk pada kebijakan privasi masing-masing.
Kami tidak memakai SDK iklan, analitik, atau pelacakan pihak ketiga.
8. Laporan dan blokir
Jika kamu melaporkan pengguna, laporan berisi alasan dan keterangan yang kamu tulis, ID pelapor dan terlapor, serta grup tempat kejadian jika ada. Karena enkripsi end-to-end, kami tidak bisa melihat isi chat yang dilaporkan. Laporan disimpan untuk keperluan moderasi. Jika pelapor menghapus akunnya, identitas pelapor dihapus dari laporan.
9. Penyimpanan dan penghapusan data
- Pesan tersimpan sampai dihapus. Kamu bisa menghapus pesan, dan pesan dengan timer hapus otomatis terhapus setelah waktunya habis.
- Kamu bisa menghapus akun lewat Pengaturan → Profile → Hapus Akun, atau lewat halaman ini jika tidak bisa membuka app.
- Saat akun dihapus, kami menghapus nama, Voryn ID, foto, status, data login, token notifikasi, hash recovery phrase, kontak, daftar blokir, semua pesan yang kamu kirim, dan semua chat pribadimu. Chat pribadi juga hilang di sisi lawan chat. Kamu juga dikeluarkan dari semua grup.
- Yang tersisa hanya penanda "Akun Terhapus" berisi ID acak dan kunci publik (termasuk kunci publik lama), tanpa nama, Voryn ID, foto, atau data login. Penanda ini diperlukan agar riwayat grup milik anggota lain tetap bisa dibuka.
- File foto atau voice note dari pesan yang dihapus dapat tetap tersimpan di server dalam bentuk terenkripsi yang tidak bisa kami buka.
10. Keamanan
Pesan dienkripsi dengan X25519 dan AES-256-GCM. Kunci privat disimpan di penyimpanan aman HP, dan akses database dibatasi aturan keamanan per pengguna. Saat ini Voryn belum memakai forward secrecy. Tidak ada sistem yang 100% aman, apalagi aplikasi yang masih beta. Jika menemukan celah keamanan, mohon kabari kami lewat email.
11. Anak-anak
Voryn tidak ditujukan untuk anak di bawah 13 tahun.
12. Hak kamu
Sesuai UU Pelindungan Data Pribadi (UU No. 27 Tahun 2022), kamu berhak mengakses, memperbaiki, dan menghapus data pribadimu. Profil bisa diubah langsung di app, akun bisa dihapus di app, dan permintaan lain bisa dikirim ke subrata.surabaya@gmail.com.
13. Perubahan kebijakan
Jika kebijakan ini berubah, versi terbaru akan dipasang di halaman ini dengan tanggal berlaku yang baru. Perubahan penting juga akan diberitahukan di dalam app.
14. Kontak
subrata.surabaya@gmail.com · Surabaya, Indonesia
Privacy Policy
Effective 4 October 2026 · Voryn beta
- No phone number, email address or real name is needed to sign up.
- Message text, photos and voice notes are end-to-end encrypted. We cannot read them.
- No ads, no tracking, no third-party analytics. We do not sell data.
- You can delete your account at any time from inside the app.
1. About us
Voryn is a messaging app developed by Sonny, an independent developer in Surabaya, Indonesia ("we"). Voryn is currently in closed beta. Privacy questions can be sent to subrata.surabaya@gmail.com.
2. Account data
- Voryn ID is generated by the system and used to sign in and to let friends find you. Technically, sign-in uses a synthetic email address derived from your Voryn ID. It is not a real mailbox and cannot receive mail.
- Password is stored as a hash by our authentication provider. We cannot see it.
- Display name, profile photo and status (optional) are visible to your contacts and group members. They are not end-to-end encrypted.
- Recovery phrase (12 words) is shown only on your phone. The server stores only a hash of it, used to verify a password reset. The words themselves are never stored.
- Public encryption key is stored on the server so others can send you encrypted messages. Your private key never leaves your phone. If you start over with a new key, your old public key is kept so the people you chatted with can still open your old conversations on their phones.
3. Messages and communication
End-to-end encrypted (we cannot read)
- Message text, photos, voice notes and shared contact cards.
Stored on our servers without end-to-end encryption
The following is needed for the service to work:
- Message metadata: sender, recipient or group, time sent, message type, edited or pinned flags, and expiry time (auto-delete timer).
- Read time, only if "Send read receipts" is turned on. It is off by default.
- Emoji reactions to messages.
- Group name, description and photo, and the group member list.
- Group system messages, for example "X left the group".
- Your Voryn contact list and contact requests.
- The list of users you have blocked. Only you can see it.
Not stored
- "Typing…" indicators are sent directly and never written to the database.
- Online or "last seen" status. Voryn deliberately has no such feature.
4. Notifications
We use Firebase Cloud Messaging (Google) to tell your phone that a new message has arrived. The signal sent through Google contains only random message and sender IDs, with no message content or names. The app then fetches the message directly from our server and shows the notification on your phone. For this we store your device's notification token.
5. Device permissions
- Camera to scan QR codes when adding a contact or moving your account to a new phone.
- Microphone to record voice notes.
- Photos to pick images to send or to use as a profile photo.
- Biometrics (fingerprint or Face ID) to unlock App Lock. This is handled by your phone's operating system, and we never receive biometric data.
- Local network to move your account and chat history directly to a new phone over the same Wi-Fi, without going through a server.
- Motion sensors for the display privacy feature. Sensor data is processed on your phone and never sent anywhere.
- Notifications to alert you to new messages.
6. Data that stays on your phone
Your private encryption key, App Lock PIN, display privacy settings and local caches are stored only on your phone. On Android, screenshots are blocked by default.
Voryn never sends your messages to any AI service. Some supporting app content, such as built-in text, is created in advance and downloaded from our server without involving any user data.
Recovery Kit is a backup code containing your private key, locked with your recovery phrase. You create and store it yourself. Voryn never receives or stores your Recovery Kit. Anyone holding both your Recovery Kit and your recovery phrase can restore your key, so keep them in separate places.
Important: because your private key exists only on your phone, if the phone is lost or broken without a Recovery Kit and before you move your account to a new phone, old messages can no longer be opened. We cannot recover them either.
7. Third-party service providers
- Supabase for the database, authentication and file storage. Its servers may be located outside Indonesia.
- Google Firebase Cloud Messaging for notification signals, as described in section 4.
- Apple App Store and Google Play for app distribution, subject to their own privacy policies.
We do not use any third-party advertising, analytics or tracking SDKs.
8. Reports and blocking
If you report a user, the report contains the reason and details you write, the reporter's and reported user's IDs, and the group where it happened, if any. Because of end-to-end encryption, we cannot see the content of the reported chat. Reports are kept for moderation. If the reporter deletes their account, their identity is removed from the report.
9. Retention and deletion
- Messages are kept until deleted. You can delete messages, and messages with an auto-delete timer are removed when it expires.
- You can delete your account in Settings → Profile → Delete Account, or through this page if you cannot open the app.
- When an account is deleted, we remove the name, Voryn ID, photo, status, login data, notification token, recovery phrase hash, contacts, block list, all messages you sent and all your private chats. Private chats also disappear for the other person. You are also removed from all groups.
- All that remains is a "Deleted Account" marker with a random ID and public keys (including old ones), with no name, Voryn ID, photo or login data. It is needed so other members can still open their group history.
- Photo or voice note files from deleted messages may remain on the server in encrypted form that we cannot open.
10. Security
Messages are encrypted with X25519 and AES-256-GCM. Private keys are kept in the phone's secure storage, and database access is restricted by per-user security rules. Voryn does not yet use forward secrecy. No system is 100% secure, especially an app still in beta. If you find a security issue, please tell us by email.
11. Children
Voryn is not intended for children under 13.
12. Your rights
Under Indonesia's Personal Data Protection Law (Law No. 27 of 2022), you have the right to access, correct and delete your personal data. You can edit your profile and delete your account in the app, and send any other request to subrata.surabaya@gmail.com.
13. Changes
If this policy changes, the latest version will be posted on this page with a new effective date. Important changes will also be announced in the app.
14. Contact
subrata.surabaya@gmail.com · Surabaya, Indonesia