Back to Summary

Keeftalk Privacy Policy

Effective Date: August 6, 2026

Company: Keeftalk LLC

Website: https://keeftalk.com

Contact: [email protected]

Jurisdiction: Tunisia

1. Introduction

1.1 Our Commitment

Keeftalk LLC (?Keeftalk,? ?we,? ?us,? or ?our?) is committed to protecting your privacy and the security of your personal information. This Privacy Policy describes how we collect, use, store, disclose, and safeguard your information when you access or use the Keeftalk application (the ?App?), our website located at https://keeftalk.com (the ?Site?), and any related services, features, or content (collectively, the ?Service?). It also explains your rights regarding your information and how you can control it.

1.2 Scope and Consent

By creating an account or otherwise using the Service, you consent to the practices described in this Privacy Policy. If you do not agree with this policy, you must not use the Service. This Privacy Policy is incorporated into and forms an integral part of our Terms of Service. Capitalized terms used but not defined in this policy shall have the meanings given to them in the Terms of Service.

1.3 Definitions

For clarity, in addition to the definitions in the Terms:

  • ?Personal Data? or ?Personal Information? means any information relating to an identified or identifiable natural person, such as name, email address, phone number, or online identifiers.
  • ?Processing? means any operation performed on Personal Data, including collection, recording, organization, storage, alteration, retrieval, use, disclosure, erasure, or destruction.
  • ?End-to-End Encryption? or ?E2EE? has the meaning given in the Terms, referring to the encryption of messages such that only the sender and intended recipient(s) can read the content.
  • ?Metadata? means data about data, such as timestamps, sender and recipient identifiers, message size, and call duration, but not the content of the communication.

1.4 Agreement with Terms

Your use of the Service is also governed by our Terms of Service. Please read this Privacy Policy together with the Terms to fully understand how we handle your information.

2. Core Privacy Principles

Keeftalk is founded on a set of unwavering privacy principles that guide every aspect of our design and operations:

2.1 ? End-to-End Encrypted Messaging

All your one-on-one and group messages, voice messages, and (where technically feasible) file transfers are secured with state-of-the-art end-to-end encryption. This means neither Keeftalk nor any third party can read or listen to your communications. We have engineered the Service so that plaintext message content is never accessible to us, even for the purpose of targeted advertising or law enforcement access.

2.2 ? No Ads, Ever

Keeftalk does not and will never display third-party advertisements. Our business model does not rely on collecting user data for advertising or profiling. We do not allow ad networks, data brokers, or any other advertising-related tracking technologies within the Service.

2.3 ? No Sale of Personal Data

We do not sell, rent, or trade your Personal Data to anyone for any purpose. We do not share your data with third parties for their own direct marketing. Any sharing with service providers is strictly limited to operating and improving the Service under contractual confidentiality and security obligations.

2.4 ? You Own Your Content

You retain full ownership of all messages, files, images, and other content you send or store through the Service. Our limited license to process your content is solely for the purpose of delivering the Service (e.g., encrypted transmission and temporary storage). We do not scan, analyze, or mine your messages for any purpose.

2.5 ?? You Can Delete Your Account

You have the right to delete your account at any time, directly through the App settings. When you delete your account, we follow a rigorous deletion process to remove your personal information from our active systems, as detailed in Section 13.

2.6 ? Transparency and User Control

We are committed to transparency about our data practices. This Privacy Policy describes in detail what data we collect, why we collect it, and how it is used. We provide you with controls to manage your privacy, including settings for disappearing messages, profile visibility, and data download.

3. Information We Collect

We collect only the information that is necessary to provide the Service and improve your experience. The types of information we collect depend on how you interact with the Service.

3.1 Account Information

When you register for a Keeftalk account, you provide certain information directly:

  • Full name: You may be required to provide your first and last name or a display name.
  • Username: A unique identifier chosen by you, visible to other users.
  • Email address: Used for account verification, login, recovery, and important communications.
  • Phone number (optional): If you choose to verify a phone number, we collect and store it to enable phone number-based discovery and account security features. Phone numbers are hashed and stored securely.
  • Date of birth: We collect your date of birth to verify that you meet the minimum age requirement (13 years or older, or the applicable digital consent age). We do not display your age or date of birth publicly.

3.2 Profile Information

You may optionally provide additional information to customize your profile:

  • Profile picture: An image you upload to represent yourself. You can choose not to upload one.
  • Bio or status: A short text description that you can set to be visible to your contacts.

This information is end-to-end encrypted or, if not encrypted, is under your control and can be managed in your privacy settings.

3.3 Usage Data

We automatically collect certain information about how you interact with the Service to ensure it functions properly, to understand feature usage, and to improve performance. This includes:

  • App activity: The features you use (e.g., messaging, calling, AI assistant, settings changes), the frequency and duration of your sessions, and actions taken within the App (such as creating groups, deleting messages).
  • Feature usage metrics: Aggregated counts of messages sent, calls made, media shared, etc., without accessing the content. This data is anonymized where possible.
  • Crash reports: When the App encounters an error, we may automatically collect diagnostic information such as stack traces, device state, and the sequence of actions leading to the crash to identify and fix bugs.
  • Analytics data: We use analytics services (see Section 10) that collect aggregated data like screen views, button taps, and user flow patterns. This data is used solely to improve the Service and is never used for advertising profiling.

3.4 Device Information

To deliver the Service effectively, we collect technical information from the device you use to access Keeftalk:

  • Device type and model: (e.g., iPhone 15, Samsung Galaxy S24)
  • Operating system and version: (e.g., iOS 18, Android 15)
  • App version: The specific build of the Keeftalk App you are using.
  • IP address: Logged temporarily for security, rate limiting, and network diagnostics. IP addresses are not permanently linked to your account and are stored in hashed form or deleted after a short period.
  • Push notification token: A unique identifier provided by the operating system (Apple Push Notification Service or Firebase Cloud Messaging) used to send notifications to your device. This token does not reveal your message content.
  • Language preferences and time zone: To customize the App experience.
  • Mobile network information (carrier): Possibly collected for diagnostic purposes only.

3.5 Content and Communications

Due to our end-to-end encryption architecture, Keeftalk has no access to the plaintext content of your messages, voice calls, video calls, or shared files. However, for the Service to function, we necessarily process:

  • Encrypted message payloads: These are temporarily stored on our servers for delivery and synchronization. The payloads are indecipherable to us.
  • Metadata: For message routing, we process metadata such as the sender's and recipient's user IDs, message timestamps, and approximate message size. For calls, we may store call logs (participants, duration, time). This metadata is necessary for features like delivery receipts, message ordering, and call history.
  • Reported content: If you report a user or a message, the App may allow you to share specific message content with our support team. In such cases, only the messages you choose to report are decrypted and transmitted to us; all other messages remain encrypted.

3.6 Optional Information

  • Location data: Keeftalk does not track your real-time location. If you share your location in a chat via a location-sharing feature, that location is treated as message content and is end-to-end encrypted. We do not access, store, or retain your device's GPS coordinates or any background location data.

3.7 Information from Third Parties

We may receive limited information when you connect third-party services to Keeftalk (if such integrations become available in the future). For example, if you choose to link a cloud storage provider for backups, we would process data as directed by you, in accordance with that provider's privacy policy.

3.8 What We Do NOT Collect

We explicitly do not collect:

  • Message content (plaintext).
  • Call audio or video content (unless you explicitly use the call recording feature, in which case the recording is stored locally on your device, not on our servers).
  • Your contacts' address book without your permission (if a contact discovery feature is added, it will be optional and privacy-preserving).
  • Precise real-time geolocation.
  • Biometric data or health information.
  • Sensitive personal data such as race, political opinions, religious beliefs, or sexual orientation unless you voluntarily include it in your profile or messages, which remains encrypted.

4. How We Use Your Information

We use the information we collect for the following purposes, and only as necessary:

4.1 Service Provision and Operations

  • To create, maintain, and secure your account.
  • To enable the core functionalities of the Service: delivering messages, routing calls, synchronizing across devices, and displaying your profile.
  • To process your account settings and preferences.

4.2 Communication with You

  • To send service-related announcements, security alerts, and administrative messages via email or in-app notifications. These are essential communications; you cannot opt out of them while having an active account.
  • To respond to your inquiries, support requests, and feedback.

4.3 Service Improvement and Development

  • To analyze aggregated usage patterns to understand how users interact with the Service and prioritize new features or improvements.
  • To identify and fix bugs, crashes, and performance issues using crash reports and analytics.
  • To test and validate new functionality in beta programs.

4.4 Security and Integrity

  • To detect, prevent, and combat fraudulent activity, spam, abuse, and Terms of Service violations.
  • To verify user identity and prevent unauthorized account access.
  • To enforce our Terms of Service and protect the rights, property, and safety of Keeftalk, our users, and the public.

4.5 Legal Compliance

  • To comply with applicable laws, regulations, legal processes, or enforceable governmental requests.
  • To respond to valid legal orders such as subpoenas, court orders, or warrants, to the extent consistent with our encryption architecture and our commitment to user privacy.

4.6 Aggregated and De-identified Data

We may create aggregated, anonymized, or de-identified data from the information we collect, such as statistical metrics about overall service usage. This data cannot reasonably be linked to any specific individual and may be used for any lawful purpose, including research and public reporting.

5. Legal Bases for Processing (For Users in the EEA, UK, and Similar Jurisdictions)

If you are located in the European Economic Area, the United Kingdom, or a jurisdiction with similar data protection laws, our legal bases for processing your Personal Data are:

  • Performance of a Contract: Processing is necessary to provide the Service and fulfill our obligations under the Terms of Service (e.g., creating your account, delivering messages).
  • Legitimate Interests: We process data for our legitimate interests in improving the Service, ensuring its security, and preventing fraud, provided those interests are not overridden by your data protection rights.
  • Consent: We rely on your explicit consent for certain optional processing, such as sending you non-essential marketing communications (which we currently do not send) or enabling certain AI features that require data processing beyond the core service. You may withdraw consent at any time.
  • Legal Obligation: Processing is necessary to comply with our legal and regulatory obligations.

6. End-to-End Encryption and Message Privacy

6.1 How Encryption Protects You

All messages, voice messages, and file transfers sent through Keeftalk are protected by end-to-end encryption (E2EE). This means:

  • Encryption on your device: Messages are encrypted using a lock that only the recipient has the key to open.
  • No plaintext on our servers: Keeftalk never has access to the decryption keys. We only see encrypted data that is unreadable to us.
  • Even if compelled by law, we cannot provide the content of your encrypted communications because we simply do not have it.

6.2 What is Not Encrypted

  • Metadata: As described, we process metadata for routing. Metadata does not include the message body.
  • Public profile information: Your username, display name, and profile picture (if you set visibility to ?everyone?) are visible to other users and are not encrypted end-to-end.
  • Data you explicitly report: If you choose to report a message, the specific message content is shared with us.

6.3 Your Control Over Encryption

You can verify the security of your chats by comparing safety numbers or security codes with your contacts (if the feature is available). You are responsible for ensuring your device is not compromised, as a jailbroken or rooted device may undermine encryption.

7. Call Data

7.1 Voice and Video Calls

Keeftalk supports end-to-end encrypted voice and video calls. During a call, audio and video are encrypted and transmitted peer-to-peer or via relay servers in a manner that we cannot access. We do not listen to or record calls.

7.2 Call Logs

We store basic metadata about calls to display your call history: the participants, date/time, duration, and type (voice/video). This data is stored in association with your account and can be deleted by you by clearing your call log within the App.

7.3 Call Recording

If call recording is available and you enable it:

  • The recording is created and stored locally on your device. Keeftalk does not have access to the recording content.
  • It is your responsibility to comply with laws regarding consent to recording. The App will provide visual or audible indicators where required.

8. Media Storage and Deletion

8.1 Media Handling

When you send images, videos, or other files:

  • Media is compressed by default to reduce data usage. You may choose to send original quality.
  • Media files are end-to-end encrypted when transmitted and may be temporarily stored in encrypted form on our servers to facilitate delivery and cross-device synchronization.

8.2 Deletion and Retention

When you delete a media file from a chat, it is not instantly removed from all infrastructure. Our system retains deleted media for up to 14 days in encrypted form within backup and caching systems. After this period, the data is permanently and securely erased. This grace period allows for recovery from accidental deletion and technical contingencies. The media remains inaccessible to Keeftalk throughout.

9. AI Features and Data Processing

9.1 AI Chat Assistant

Keeftalk may provide an AI-powered assistant that you can interact with. The AI is designed with privacy in mind:

  • On-device translation: Text you translate is processed locally on your device and never sent to our servers.
  • Server-based AI: If a server-based AI feature is offered, we will clearly inform you, and we will only send the necessary input to our servers. We will strip personal identifiers where possible, and we will never use your AI queries to train our models unless you give explicit opt-in consent.

9.2 AI Data Protection

  • AI interactions that occur on our servers may be logged for quality and abuse monitoring, but these logs are not linked to your identity beyond the necessary and are deleted per our retention policy.
  • You must not input sensitive personal data (e.g., passwords, financial information) into the AI assistant.

10. Analytics and Crash Reports

10.1 Analytics Tools

We use the following analytics services to understand usage and improve the Service:

  • Firebase Analytics (Google): Collects anonymized usage data, device information, and engagement metrics. We have configured Firebase Analytics to limit data collection and do not use it for advertising or remarketing.
  • Supabase Analytics: As part of our backend infrastructure, we may use Supabase's built-in analytics for database performance monitoring. This includes query metrics and request patterns, not personal message content.

10.2 Data Collected by Analytics

These services may collect:

  • App events (screen views, feature interactions)
  • Device model and OS
  • Coarse location (country-level derived from IP address, which we have truncated)
  • Crash data (stack traces, device state)

10.3 Opting Out

You may be able to limit analytics collection through your device settings (e.g., ?Limit Ad Tracking? on iOS or ?Opt out of Ads Personalization? on Android, even though we do not personalize ads). Because we do not show ads, the impact of such settings is limited to the analytics data collected. We are exploring an in-app opt-out for analytics.

11. Notifications

11.1 Push Notifications

We use Firebase Cloud Messaging (FCM) to deliver push notifications to your device. To enable this, we share your device push token with Firebase. This token is a unique but pseudonymous identifier; it does not contain message content. Notifications sent through FCM may be processed on Google's servers in accordance with their privacy policy.

11.2 Control

You can disable notifications entirely or for specific types through your device's system settings or within the App's notification settings. Disabling notifications does not affect message delivery.

12. Data Sharing and Disclosure

12.1 Service Providers

We share limited information with trusted third-party service providers who assist us in operating the Service. These providers are contractually bound to process your data only on our instructions and in accordance with this Privacy Policy. They include:

Service Provider Purpose Data Shared
Firebase (Google) Analytics, crash reporting, push notifications Device token, app events, crash logs, coarse IP
Supabase Backend database hosting, storage Encrypted data, account metadata, usage logs
Infrastructure/CDN File delivery, DNS, server hosting IP addresses, encrypted traffic

We do not authorize these providers to use your data for their own purposes.

12.2 Legal Compliance and Law Enforcement

We may disclose information if we believe in good faith that it is necessary to:

  • Comply with a valid legal process, court order, or government request.
  • Protect the safety of any person; prevent death or imminent bodily harm.
  • Investigate, prevent, or take action regarding illegal activities, suspected fraud, or violations of our Terms.
  • Protect the rights, property, or security of Keeftalk, our users, or the public.

Due to E2EE, the only information we can provide is metadata and account details, not message content. We publish transparency reports regarding law enforcement requests when legally permissible.

12.3 Business Transfers

If Keeftalk is involved in a merger, acquisition, reorganization, or sale of assets, your Personal Data may be transferred as part of that transaction. We will notify you (e.g., via email or prominent notice in the App) before your data is transferred and becomes subject to a different privacy policy.

12.4 With Your Consent

We may share your data for other purposes if you give us explicit consent.

12.5 Aggregated or De-identified Data

We may share aggregated, anonymized, or de-identified data that cannot reasonably identify you with third parties for research, marketing, or other purposes.

12.6 No Sale of Data

We do not sell, rent, or trade your Personal Data to any third party for monetary or other valuable consideration. This includes your messages, profile, or usage data.

13. Data Retention

13.1 Account Data

We retain your account information (email, username, phone number if provided) for as long as your account is active. When you delete your account, we initiate a deletion process:

  • 30-day grace period: Your account is deactivated immediately, but data is retained for 30 days in case of accidental deletion. You can contact us to reactivate.
  • Permanent deletion: After 30 days, we begin permanently deleting your personal data from active systems. This process may take up to an additional 60 days to fully clear backups and logs.

13.2 Messages and Content

  • Encrypted messages are stored on our servers only until delivered. Undelivered messages may be retained for a maximum of 30 days, then permanently deleted.
  • When you delete a message, it is removed from our active delivery systems. Backups may hold encrypted remnants for up to 14 days.
  • Media follows the 14-day post-deletion retention described in Section 8.

13.3 Analytics and Logs

Analytics data (anonymized) may be retained for up to 26 months. Server logs (IP addresses, request paths) are retained for a rolling 30-day period or less.

13.4 Legal Holds

If we are subject to a legal preservation order or are required by law to retain data, we will keep the specified information beyond our standard periods. We will notify you of any such hold where permitted.

14. Your Rights and Choices

You have control over your data. Depending on your jurisdiction, you may have the following rights:

14.1 Access and Portability

You can request a copy of the Personal Data we hold about you in a structured, machine-readable format. We provide an in-app ?Download My Data? feature or you can email us. Note that due to E2EE, we cannot export the plaintext of encrypted messages; you must back up those locally.

14.2 Rectification

You can update, correct, or modify your account and profile information at any time through the App settings. If you need assistance, contact us.

14.3 Deletion (Right to be Forgotten)

You can delete your account and associated data as described in Section 13. You may also request deletion of specific non-encrypted data. Some data may be retained as necessary for legal compliance.

14.4 Restriction and Objection

You may have the right to restrict or object to certain processing of your data, for example, if you contest accuracy or object to processing based on legitimate interests. Contact us to exercise these rights.

14.5 Withdrawal of Consent

Where processing is based on consent, you may withdraw that consent at any time. This will not affect the lawfulness of processing prior to withdrawal.

14.6 Right to Lodge a Complaint

If you believe your data protection rights have been violated, you can file a complaint with the relevant supervisory authority in your country. In Tunisia, the national authority is the Instance Nationale de Protection des Données Personnelles (INPDP). We encourage you to contact us first to resolve any issues.

14.7 Communication Preferences

You can manage email and notification preferences in the App. You cannot opt out of essential service communications (e.g., security alerts) while your account is active.

15. Security Measures

15.1 Our Security Practices

We implement robust technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction:

  • Encryption in transit: All data transmission between your device and our servers is encrypted using TLS.
  • End-to-end encryption: Messages and calls are E2EE as described.
  • Data at rest: Data stored on our servers (including encrypted message payloads and account information) is encrypted using industry-standard encryption.
  • Access controls: Strict internal access policies ensure that only authorized personnel with a legitimate need can access limited, non-encrypted data. Multi-factor authentication, audit logs, and regular reviews are employed.
  • Infrastructure security: We partner with leading cloud providers that maintain rigorous physical and network security.
  • Incident response: We maintain a security incident response plan. In the event of a data breach affecting your Personal Data, we will notify you and relevant authorities as required by law.

15.2 Your Role

Security is a shared responsibility. Please safeguard your account credentials, enable biometric or PIN protection on your device, and keep the App updated.

16. International Data Transfers

16.1 Data Hosting and Processing

Your data may be processed and stored on servers located in Tunisia, the European Economic Area (EEA), the United States, or other countries where our service providers operate. Some of these countries may have data protection laws different from your home country.

16.2 Safeguards

When we transfer Personal Data internationally, we implement appropriate safeguards to ensure a level of protection equivalent to that provided under the applicable law. These safeguards include:

  • Adequacy decisions: Relying on countries recognized as providing adequate protection.
  • Standard Contractual Clauses (SCCs): Entering into EU-approved standard contractual clauses with service providers.
  • Binding corporate rules or similar commitments.

For more information on transfer mechanisms, contact us.

17. Children's Privacy

17.1 Age Restriction

Keeftalk is not intended for use by children under the age of 13 (or the applicable age of digital consent in your country). We do not knowingly collect or solicit Personal Data from anyone under that age.

17.2 Parental Measures

If we become aware that we have collected Personal Data from a child under the required age without verified parental consent, we will delete that data as quickly as possible. If you believe a child has provided us with personal information, please contact us immediately.

18. Cookies and Similar Technologies

18.1 Use on the Website

Our Site at https://keeftalk.com may use essential cookies and similar technologies to ensure proper functionality:

  • Essential cookies: Necessary for website operation, such as session management and security. These do not require your consent.
  • Analytics cookies: We may use cookies to understand website traffic and improve our web presence. You can manage or disable these via your browser settings.

18.2 In-App Tracking

The App itself does not use cookies; instead, it relies on the data collection methods described in this Policy (device identifiers, analytics SDKs). You can control tracking through your device's privacy settings.

18.3 Your Choices

You can set your browser to reject cookies or alert you when a cookie is placed. Disabling essential cookies may affect the functionality of the Site.

19. Changes to This Privacy Policy

19.1 Updates

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. The ?Effective Date? at the top will be revised.

19.2 Notification

For material changes, we will notify you through:

  • A prominent in-app notice; or
  • An email to the address associated with your account.

We encourage you to review this policy periodically.

19.3 Continued Use

Your continued use of the Service after the effective date of the updated Privacy Policy constitutes acceptance of the changes. If you disagree with the changes, you must stop using the Service and delete your account.

20. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: [email protected]
Website: https://keeftalk.com

For legal and privacy-specific inquiries, you may also write to:

Keeftalk LLC
[Insert Physical Address, Tunis, Tunisia]
Attention: Data Protection Officer
Email: [email protected]

We will respond to your request within the timeframe required by applicable law.

By using Keeftalk, you acknowledge that you have read and understood this Privacy Policy.

© Keeftalk LLC. All rights reserved.

© 2026 Keeftalk. All rights reserved.