This Privacy Policy describes how Crypton Messenger ("we", "our") handles information when you use our mobile application and related services ("Service").
Messages, voice notes, and calls are end-to-end encrypted. The encryption keys are generated and stored on your device. We do not have access to the plaintext of your communications.
On iOS the optional "Activity Rings" feature displays your daily activity on the app's home screen. The data is read from Apple HealthKit. Access is disabled by default and can only be enabled by explicitly granting the permissions in the iOS system prompt. The Android app does not read any health or fitness data and does not integrate with Health Connect.
Crypton collects limited technical diagnostics to prevent crashes, investigate failed calls or message delivery, maintain security, and provide support. These records may include the app build, operating-system version, an install-stable random identifier, event timestamps, subsystem state, and Apple MetricKit crash details such as exception, signal, termination reason, and a truncated call stack. We redact known credential fields and do not intentionally include message contents, passwords, one-time codes, wallet private keys, seed phrases, or access tokens.
Diagnostics are linked to your account while you are signed in, are used only for app functionality, security and reliability, are not used for advertising or tracking, and are not sold. They are written to protected operational logs and retained only for the period needed for troubleshooting, security response and applicable legal obligations.
Messages are retained on our servers only for delivery. Account data is retained while your account is active. You can delete your account at any time from Settings; this removes your profile and associated data within 30 days, excluding information we must retain by law.
We do not sell your personal data. We may share limited data with service providers (cloud hosting, SMS delivery, push notification relays) strictly to operate the Service, and with law enforcement only when legally required.
You can access, correct, export, or delete your data from within the app Settings, or by contacting us. Users in the EEA, UK, and California have additional rights under GDPR/CCPA including the right to restrict processing and to lodge a complaint with a supervisory authority.
You can request a machine-readable copy of the personal data we hold
about you at any time. Inside the app, choose Settings → Privacy →
Download my data; the same flow is available over our REST API by
authenticated request to POST /api/v1/users/me/data-export,
polling GET /api/v1/users/me/data-export/<id>, and
finally downloading the archive from
GET /api/v1/users/me/data-export/<id>/download.
The archive is delivered as a single indented JSON file (UTF-8) with the following top-level sections:
The following are intentionally not included in the archive: your password, two-factor secret, two-factor backup codes, raw push device tokens, raw session/access tokens, and the cleartext bodies of your chat messages. Chat content is end-to-end encrypted on your device — the server only ever holds ciphertext, so there is no plaintext for us to export.
Generated archives are stored on our servers for 72 hours, after which they are automatically deleted; if you need a copy past that window, simply request a new export. Each archive is served only to the requesting account over an authenticated HTTPS download.
The Service is not directed to children under 13. We do not knowingly collect data from children under 13.
We use industry-standard protections including TLS in transit, encrypted storage at rest, and hardware-backed key storage (Keychain/Secure Enclave) on your device.
We will notify you of material changes to this policy via in-app notice or email. Continued use after changes indicates acceptance.
Questions? Email gectorclub@gmail.com.