Privacy Policy
+one is a messenger first. Messages are delivered to the people you send them to, and we use your account data to run the service — not to sell it.
What we collect
- Account basics — your username, a password (stored only as a bcrypt hash), and optionally your phone number, display name, about text, and profile photo.
- Affiliations — college, organization, or workplace you add, so colleague discovery works.
- Messages & media — text, images, voice notes, reactions, and their delivery/read state. We store them so your chats sync across your devices and history survives app restarts.
- Status & last seen — your online dot and read receipts, governed by the privacy controls you choose in Settings → Privacy.
- Location (optional) — only if you allow it, and only once per day, to put real weather into your daily AI greeting via Open-Meteo. We do not build a location history.
- Camera and microphone — used only at the moment you record a voice note or take a call; nothing is recorded in the background.
- Push tokens — a device identifier so chat notifications reach you. It is used only for that.
- Technical logs — standard request metadata (IP, user agent, timestamps) kept briefly by our hosting providers to keep the service secure and reliable.
How we use it
- Delivering your messages, calls, and posts to the people you choose.
- Syncing your chats and settings across your devices.
- Showing you your Network feed, statuses, communities, and colleagues.
- Sending the notifications you asked for.
- Keeping the service safe: abuse prevention, spam handling, and account recovery.
We do not sell or rent your data, and we don't run third-party ad networks. Aggregate, anonymized web analytics (page views, load performance) are collected by our deployment provider to help us improve the site.
What we don't do with it
- No ad targeting, no data brokering, no sale of your contact lists.
- We don't read your chats to advertise to you.
- We don't ask for contacts-book access on Android or iOS.
How long we keep it
We keep your data for as long as your account exists. The database is backed up automatically every six hours (and before each redeploy); backups are rotated and older copies are discarded.
Deleting your account — Settings → Danger Zone → Delete One ID permanently removes your account after you verify your password. Shared groups, communities, and institutions transfer safely to the remaining members. Messages in chats with other people may remain for those other members, exactly as their own copies of your conversation.
Messages you delete on your side are deleted from your history; disappearing-ink messages (30s–24h timers) are hard-deleted on expiry and vanish from every device.
Security
- Passwords are stored only as bcrypt hashes — nobody, including us, can read them.
- Sessions use signed JWTs over HTTPS; the web app and API never mix traffic with third-party origins.
- Privacy settings (last seen, read receipts, status audience, blocks) are enforced on the server, not just hidden in the app.
- Uploaded media is served with strict content-type and sandboxing headers.
Age
+one is intended for people aged 13 and over. If you're under 13, please don't create an account — contact us and we'll help.
Changes
If this policy changes in a meaningful way, the new version is published here with a new effective date, and notable changes are announced in the app. Continued use after changes means you accept the updated policy.
Contact
Questions about your data, or requests to export or delete it: open the app and go to Settings → Help & Support, or file an issue at github.com/sakshamfit/BROSKIE/issues. You can also start here: Support.