Privacy Policy
Last updated: 10 Temmuz 2026
hudhudcell uses a vault-first architecture: your E2EE chats are stored in a hardware-keyed encrypted vault on your device; we do not archive message content on our servers. This policy explains what data is processed and your rights (including App Store requirements).
Data controller
HudHudCell
DUMLUPINAR MAH. BARIS SK. C BLOK NO: 7 CE KADIKOY, ISTANBUL 34720, Türkiye
Contact: support@hudhudcell.com
1. Messages and media
- Vault-first model: E2EE chat messages are written to hardware-keyed encrypted
.encvault files on your device as they are created. We do not archive message content on our servers. - RAM is a display cache only. When the app goes to the background, memory is securely wiped and content is rehydrated from the vault when you return.
- Messaging is peer-to-peer (P2P) with end-to-end encryption (E2EE). Timed messages are stored in the vault with TTL and removed automatically when they expire.
- Chat media (photos, voice, documents) is stored encrypted in the same hardware-keyed vault.
2. Data storage architecture (vault-first)
- The source of truth is your device's hardware-keyed vault. E2EE messages, media attachments, chat list, and send queue are stored in AES-256-GCM encrypted
.encfiles. - Key material lives in the Secure Enclave / platform keystore. Session and pairing keys stay in RAM only and are not written to the vault.
- RAM is a display cache. When the app backgrounds, memory is securely wiped; chats rehydrate from the vault when you return.
- We do not use AsyncStorage, SQLite, MMKV, or server-side message archives for chat content.
- The offline delivery bridge carries only pubkey-sealed encrypted blobs; the bridge cannot read message plaintext.
3. Authentication
Sign-in uses Privy and optional WalletConnect. Identity data is processed by those providers; our bridge does not archive your identity profile.
4. Bridge API
AI assistant, image search, and place search use api.hudhudcell.com only at request time. With AI enabled, text may be sent to Google Gemini (with your consent). We do not persist chat archives.
5. Location
- Location sharing only when you choose; requires GPS permission.
- Place search may use Google Places via our bridge; queries are not stored as chats.
- Live location is time-limited and stops automatically.
6. Device permissions
- Camera / microphone — calls and media
- Location — optional location sharing
- Contacts — optional address-book matching only when you tap import (not background scanning)
- Face ID — app lock and signatures
- Photo library — send / save media
Contact discovery
- Registered users can be found by someone who already knows their phone number, email address, or wallet address. This is not random or anonymous matching: the searcher must enter a known identifier.
- Phone, email, and wallet plaintext never leave the device for discovery. The app derives a one-way hash (app-wide pepper) and may publish that hash plus an encrypted peer-id record to the DHT and our short-lived bridge registry (typically up to 7 days) so others can resolve a peer when they already know the identifier.
- Lookups are rate-limited on the device to reduce bulk guessing / enumeration of common numbers or emails.
- Optional address-book import runs only when you tap import and grant Contacts permission. We do not scan your contacts in the background. Matched peers stay on your device; we do not build or sell a contact database.
- Invite links remain available as an additional way to connect; they are not required when the other person is already registered and discoverable by a known identifier.
7. Stories
Stories may be stored encrypted on-device for up to 24 hours, then removed.
Third-party services and sharing
- Privy and WalletConnect / Reown — sign-in only; we do not archive your identity profile on our bridge.
- Google Gemini — only when you enable AI and confirm per-session consent; prompts may leave the device for that request. You can decline or use on-device-only mode where available.
- Google Places — place search queries only when you use search.
- Twilio — +90 SMS OTP delivery for phone sign-in.
- Apple APNs / FCM — optional push for message/call relay when you enable notifications in Settings.
We do not use third-party analytics or advertising SDKs, do not track users across apps or websites (no App Tracking Transparency), and do not sell personal data. Address-book matching runs only when you tap import and grant Contacts permission; invites are sent one contact at a time (no bulk “select all”). Discovery hashes on the bridge are not sold or used for advertising.
8. Deletion and account
Deleting a message or chat (for me / for everyone) also removes the related vault records. Settings → Storage → Delete everything permanently wipes all vault files and caches. Permanent account deletion: Settings → Account → Delete account (Apple guideline 5.1.1). This removes your Privy identity.
Your rights (EEA / UK)
Where GDPR applies, you may request access, rectification, erasure, restriction, portability, or object to processing. Contact support@hudhudcell.com. You may also lodge a complaint with your local supervisory authority.
Children
The app is not directed at children under 13. We do not knowingly collect personal data from anyone under 13. If you believe a child has provided data, contact support@hudhudcell.com.
9. Contact
Türkiye: destek@hudhudcell.com · International: support@hudhudcell.com
Turkish version: /privacy