Privacy Policy
Last Updated: August 5, 2026
Welcome to Talksy. We are committed to protecting your privacy and ensuring you have a safe and secure experience using our application. This Privacy Policy outlines the types of information we collect, how we process and protect it, and your rights regarding your data in full compliance with the Google Play Console Developer Policies.
1. Information We Collect
To provide and improve our real-time video matching and communication services, we collect the following categories of data:
- Account Profile Information: Authentication is handled securely via Google Sign-In or Guest session parameters. We receive and store your email address, full name, profile picture URL, and Google unique identifier. If you choose to upload a custom profile avatar, it is securely uploaded to Google Cloud Storage (GCS).
- Video & Audio Streams: To support live matches, your camera and microphone streams are transmitted directly to your matchmaking partner using Agora RTC peer-to-peer and relayed nodes. We **never** record, intercept, monitor, or store video or audio calls on our databases. All real-time streams are private and ephemeral.
- Coarse Location Data: The app processes geolocation parameters locally to match users by region/country. Precise coordinates (latitude/longitude) are processed locally on your device to calculate distance filters (e.g. within a selected radius) and are **never** persistently stored on our servers. Other users can only see your generalized country name.
- Push Notification Tokens: We collect and upload Firebase Cloud Messaging (FCM) tokens to route call invites and chat notifications. You can disable notifications anytime in your Android system settings.
- Financial and Transaction Info: Purchases of virtual coins are handled securely using our payment partner SDK (Razorpay). We do **not** collect or store credit/debit card numbers, bank details, or UPI credentials. We only record the transaction ID, payment status, coins balance, and transaction history on our databases to manage your wallet.
- Customer Support Data: If you submit a support ticket via the Help & Support screen inside the app, we collect the support category, subject, description, and your contact email to resolve your query and contact you back.
2. How We Use Your Data
We process your information to fulfill our contractual and service agreements with you, specifically:
- To manage your account, authenticate sessions, and maintain your user profile.
- To match you with other active users according to your search and filter preferences.
- To facilitate Agora video and audio calls with dynamic RTC authentication tokens.
- To credit, deduct, and update your virtual coin wallet balance during active calls.
- To deliver push notifications when other users invite you to a call or chat.
- To reply to your queries and support tickets submitted through the in-app Help center.
- To monitor and prevent fraud, harassment, malicious activities, and violations of our Community Guidelines.
3. Data Sharing & Third-Party SDKs
We do not sell, trade, or rent your personal information to third parties. We share data only with verified services integrated to run the app:
- Agora: Facilitates real-time video/audio transmission. Agora receives technical streaming parameters to establish the connection but does not record call media.
- Razorpay: Processes payments securely. All payment details are processed under Razorpay's PCI-DSS compliant secure infrastructure.
- Google Cloud & Firebase: Houses our backend databases and routes notifications using industry-standard security.
4. Data Retention & Account Deletion
Under Google Play Store guidelines, we provide a clear in-app mechanism to delete your account. You can request permanent account deletion via Settings -> Delete Account inside the app. Upon double-confirmation:
- Your email, full name, avatar images, and Google ID are immediately marked for erasure.
- Your coins balance, payment history, friend lists, block records, and AES-encrypted chats are permanently wiped from MongoDB within 14 days.
- Any uploaded custom avatar files are permanently deleted from our Google Cloud Storage bucket.
5. Children's Privacy (COPPA Compliance)
Our services are strictly restricted to individuals aged 18 and over. We do not knowingly collect or solicit personal information from children under 13, nor do we target the app to minors. If we discover that a user under 18 has registered an account, we will terminate the account and delete their data immediately.
6. Security Measures & Encryption
We deploy robust security controls to safeguard your data:
- Data in Transit: All API communications between the mobile application and our servers are encrypted using Transport Layer Security (TLS/HTTPS) to prevent unauthorized interception.
- Chat Privacy (Encryption at Rest): All direct text messages sent within the app are encrypted at rest using the industry-standard AES-256-CBC algorithm. Nobody, including developers or database administrators, can access or read your chats.
- Database & Media Security: User profiles and metadata are stored on MongoDB databases protected by strict IAM policies. Profile pictures and avatars are securely hosted in Google Cloud Storage with strict access rules.
- RTC Call Security: Video and audio sessions use dynamic security tokens generated by our Node.js server for every single call to prevent unauthorized eavesdropping.
7. Android Device Permissions Required
To enable the core features of the Talksy application, the app requests the following runtime permissions on your mobile device:
- Camera Permission (CAMERA): Required to capture video streams during video call matches. Video frames are processed in real-time and are never saved on the device or servers.
- Microphone Permission (RECORD_AUDIO): Required to capture audio streams during voice/video chats. Audio is processed in real-time and is never recorded or stored.
- Notification Permission (POST_NOTIFICATIONS): Required to notify you of incoming call invitations and chat messages while the app is in the background.
8. Child Sexual Abuse Material (CSAM) & Exploitation (CSAE) Prevention Policy
Talksy has a strict Zero-Tolerance Policy against the creation, distribution, sharing, or facilitation of Child Sexual Abuse Material (CSAM) and Child Sexual Abuse and Exploitation (CSAE). We employ multiple layers of defense to prevent and respond to child safety hazards:
- Immediate Account Termination: Any user attempting to share, discuss, or request CSAM/CSAE content will be banned permanently from the platform instantly.
- Law Enforcement Reporting: We comply with national and international reporting requirements. All detected instances of CSAM/CSAE will be reported directly to the National Center for Missing & Exploited Children (NCMEC) and appropriate law enforcement agencies.
- In-App User Reporting: Every video matchmaking session and text chat contains a persistent "Report" button, allowing users to report child safety violations immediately. All reports are flagged with high priority for our safety moderation team.
9. Contact Us
If you have questions regarding this Privacy Policy, data security, GDPR/CCPA compliance, or account deletion, please contact our Privacy Office at:
Email: shriramasociate17@gmail.com