YumeBee mascot yumebee

Privacy Policy

Last updated · August 5, 2026

What YumeBee collects, what our servers genuinely cannot see, how long we keep things, and how to get rid of all of it. Please read this alongside our Terms of Service.

1. Who we are

YumeBee is a private, end-to-end encrypted messaging app for iOS and Android, operated by YuMe Private Limited ("YumeBee," "we," "us," or "our"). We are the data controller (in India, the "data fiduciary") for the personal data described here.

This policy covers the YumeBee mobile app and the backend services it talks to. It does not cover anything you do in other apps, including the messaging service used to deliver your one-time sign-in code.

2. The short version

Message contentEnd-to-end encrypted. We cannot read your texts, photos, or videos — not on request, not under pressure, not by accident.
LifespanMessages and media are deleted about 24 hours after they're sent, delivered or not. There is no chat history or backup, anywhere.
Account dataPhone number, name, username, date of birth, avatar, and an optional recovery email. Kept until you delete your account.
No address bookWe never upload your contacts. You add friends by typing a phone number or username.
No ads, no sellingNo advertising SDKs, no ad identifiers, no data brokers. We do not sell or rent your data to anyone.
Watch cardsThe one exception: watch cards are not encrypted and are kept indefinitely as an internal record. Details in §3 and §8.

3. Information we collect

a. Information you give us

  • Phone number. Required. It is your account identifier, and we verify it with a one-time code sent by SMS. We store the number; we store the code only as a keyed hash, for a few minutes.
  • Profile. First and last name, the display name assembled from them, a unique username, and your date of birth (collected once at signup, to check the minimum-age requirement and to decide whether you see age-restricted sticker packs, and not editable afterward).
  • Avatar. If you set one, the image is stored in our object storage and served to your friends. Unlike message media, an avatar is not end-to-end encrypted.
  • Recovery email (optional). If you choose to bind one, we store the address and whether it's verified. It is used only to help you regain access if you lose your phone number — never to log in, never for marketing.
  • Social graph. Friend requests and friendships, blocks, group memberships and pending group invitations, and group names.
  • Watch cards. When you send a watch card, we store the whole card: the title and poster from the third-party catalog, the season and episodes you marked watched, any star rating, and any note you typed. This is not encrypted and we can read it. See §4 and §8.
  • Reports. If you report a user or a message, whatever you send us as part of that report.

b. Information collected automatically

  • Device record. Platform (iOS or Android), app version, your push notification token, an internal device and connection identifier, and when the device was bound and last seen. One device per account — signing in elsewhere replaces this record.
  • IP address. Seen on every request, as it must be for anything on the internet to work. We use it transiently to rate-limit one-time codes and to spot abuse, and it appears in short-lived server access logs. We do not build a location profile from it.
  • Routing metadata. Delivering a message requires knowing who is sending to whom, when, roughly how large it is, and what type it is (text, photo, video, sticker, emoji) so a push notification can be labeled. This is inherent to running a messaging service and is not something encryption can hide.
  • Delivery state. Delivered and read markers per conversation, typing indicators, online/offline presence, and unread counts. These are not end-to-end encrypted.
  • Diagnostics and usage analytics. Our own self-hosted analytics records app events — which screen you opened, taps on major actions, connection and encryption-setup successes and failures, and API call outcomes — along with your user ID, a session ID, platform, OS version, and app version. No message content is ever included.
  • Crash reports. When the app hits an unhandled error we send the exception type, a truncated error message, and the top stack frames through that same pipeline. These are code locations, not your data.
  • Operational logs and metrics. Standard server logs and aggregate counters (request rates, error rates, delivery latency) used to keep the service running.

c. Message content

Message text, photos, and videos pass through our servers only as ciphertext we hold briefly for delivery. Encrypted media sits in object storage until the recipient fetches it, and is deleted on the same 24-hour schedule (or immediately, if you delete the message). We hold no key that would open any of it.

4. What we cannot see — and what we can

YumeBee uses the Signal protocol for end-to-end encryption, in both 1:1 chats and groups. Being precise about the boundary matters more than sounding reassuring, so:

We cannot read:

  • Message text and emoji.
  • Which emoji you reacted with, and which message you reacted to. A reaction is encrypted exactly like a message.
  • Photo and video content, and custom stickers you make from your own photos — all encrypted on your device before upload.
  • The keys that unlock media, which travel only inside the encrypted message.

We can see (protected in transit by TLS, but readable by our servers):

  • Everything in §3(a) and §3(b) — your account details, your friend and group lists, routing metadata, and delivery state.
  • Watch cards, including any note you type on one. A watch card note is the only text you type in YumeBee that our servers can read. If it's sensitive, send it as a message instead.
  • Which built-in sticker you sent (the sticker images themselves are public assets anyone can see in the app).
  • In a group, which members you @mentioned — sent to us in plain form solely so we can send those members a "you were tagged" notification. The message text itself, including the name you typed, stays encrypted.
  • When you react to a message: whose message it was, and what kind of message it was (a photo, a whisper, a sticker…). Both are sent in plain form solely so we can send that one person a "reacted to your photo" notification — nobody else in the chat is notified. (You can't react to your own messages, so this never describes you reacting to yourself.) The kind is something we had already seen when that message was sent. The emoji you picked, and which specific message you put it on, stay encrypted.
  • Group system messages (joins, leaves, invitations, renames) and the non-content activity signals we compute from message counts and timing — the most-active-member marker, the quiet-member note, and the group "aliveness" score.
  • Wink streaks. When you send a wink we already see that a wink was sent, in which chat, by whom — the same routing metadata every message carries, and what lets us send a "sent you a wink" notification. For streaks we keep a running count from it: how many days in a row everyone in that chat has winked, your longest-ever count, and when the current day started and ends. We do not keep a record of individual winks, and we never learn whether a wink was opened — that happens only on your phone, which is exactly why a streak counts sending rather than opening.

Because your keys never leave your devices, we cannot recover your messages if you lose your phone, reinstall, or switch devices — for you, for law enforcement, or for ourselves.

5. What we never collect

  • Your contacts. The app never reads or uploads your address book. Friends are found by typing a phone number or username.
  • Your location. No GPS, no location permission, no location inferred and stored from your IP.
  • Advertising identifiers. No IDFA, no Android Advertising ID, no advertising or attribution SDKs of any kind.
  • Biometrics. If you lock the app with Face ID, Touch ID, or a fingerprint, that check happens entirely on your device — nothing about it reaches us.
  • Unsent drafts. Text you type but don't send is saved on your phone so you can leave a chat and come back to it. It is never uploaded, never synced between devices, and is deleted after 24 hours like everything else.
  • A log of who winked when. Wink streaks are stored as a count and the current day's start and end time per chat — not as a history of individual winks, and never as a record of who in a group has or hasn't winked yet. The app never tells anyone who missed a day, and neither do we.
  • Payment information. YumeBee is currently free and has no in-app purchases.
  • Third-party trackers. Our analytics are self-hosted on our own infrastructure. There is no Google Analytics, Firebase Analytics, Crashlytics, Meta SDK, or similar in the app.
We do not sell, rent, or trade personal data — to anyone, for any price

6. How we use information

  • To run the service: verify your phone number, create and secure your account, bind your device, route messages to the right recipients, deliver push notifications, and show presence and receipts.
  • To let you find and be found by friends: phone number and username lookup, friend requests, groups.
  • For the catalog and watch cards: your search terms are proxied to the third-party movie/TV catalog through our backend, so the catalog provider sees our server rather than you.
  • For wink streaks: counting the consecutive days everyone in a chat has winked, and sending you at most two reminders on a day when your streak is running out and you haven't winked yet. Streak reminders are never sent to someone who has already winked, and we never send a notification when a streak ends.
  • To decide what is age-appropriate: some built-in sticker packs are marked 18+, and your date of birth decides whether they appear in your sticker tray at all. The filtering happens on our servers, so a pack you are too young for is never sent to your phone. We do not otherwise profile you by age.
  • To keep the service safe: rate limits, abuse and spam detection, and acting on user reports.
  • To fix and improve the app: diagnosing crashes, finding broken flows, and understanding which features are used — from event and error data, never from message content.
  • To help you recover access: if you bound a recovery email, sending a code to it when you ask to recover.
  • To comply with law: responding to valid legal process, within the hard limits of what we actually hold (§9).

We do not use your data for advertising, profiling for marketing, or automated decisions with legal effects. We do not send marketing email.

8. How long we keep it

DataKept for
Message text and encrypted media About 24 hours from sending, whether or not delivered, then deleted from our infrastructure. Deleted immediately if you delete the message.
One-time sign-in codes 5 minutes, stored only as a keyed hash, then discarded. Also discarded on use.
Session and refresh tokens Access tokens minutes; refresh tokens up to 30 days, stored hashed. Revoked immediately on logout, account deletion, or when a new device takes over.
Presence, typing, unread counts Transient — held in an ephemeral store and expired automatically.
Delivered / read markers Kept per conversation for as long as the conversation exists, so receipts survive a reconnect.
Account, profile, avatar, public keys, friendships, group memberships Until you delete your account, after which they are removed.
Wink streak counts For as long as the chat exists. The count and the current day's window are kept even after the messages they were counted from have gone — that is the point of a streak. A streak that ends is zeroed, and everything is removed when you delete your account or the chat ends (unfriending, or leaving a group).
Watch card send records Indefinitely, as an internal record — even though the card disappears from your chat after 24 hours and is never shown back to any user.
Diagnostics, usage analytics, crash reports Up to 12 months, then deleted or kept only in aggregate form that no longer identifies you.
Server access logs and operational metrics Up to 90 days.

We may keep a specific item longer where a law or a live legal claim requires it, and only for as long as that requirement lasts.

9. Who we share information with

We share the minimum necessary, with these categories only:

RecipientWhat they get, and why
Other YumeBee users Your display name, username, and avatar are visible to people who can find or message you. Your friends see your presence and receipts. Message content goes only to the recipients you chose — encrypted.
SMS messaging provider (Fast2SMS) Your phone number and the one-time code, solely to deliver your sign-in code by SMS.
Apple (APNs) and Google (FCM) Your push token and a content-less notification — enough to say a message arrived, never what it says.
Email relay Your recovery email address and a verification or recovery code, only if you use email recovery.
TMDB (movie/TV catalog) Search terms and title lookups, proxied through our backend. TMDB does not receive your identity or IP address from us.
Infrastructure providers Hosting and network providers that run our servers. They process data on our instructions under contract; our databases and analytics are self-hosted on infrastructure we control.
Legal and safety Government or law enforcement bodies, where we receive valid legal process. We disclose only what we actually hold — which, for message content, is nothing readable.
Corporate transactions If YumeBee is ever involved in a merger, acquisition, or asset sale, data may transfer to the successor, which stays bound by this policy. We will tell you before it takes effect.

That is the complete list of categories. We do not share your data with advertisers, data brokers, or analytics companies, because we do not work with any.

10. Device permissions we ask for

Each of these is optional, requested only in the moment you use the feature, and revocable in your device settings at any time.

  • Camera — to take a photo or video to send. Captured media is encrypted on your device.
  • Microphone — to record a whisper (a voice message, up to one minute, held down in the message box) and the audio of a video you shoot. Both are end-to-end encrypted like any other message. YumeBee has no voice or video calling.
  • Photo library — to pick an existing photo or video to send, or to set your avatar. We access only what you pick.
  • Notifications — to alert you that a message arrived. Notifications never contain message content.

We ask for nothing else — no contacts, no location, no calendar, no microphone access outside of video capture, and no background tracking.

11. How we protect information

  • End-to-end encryption (Signal protocol) for message and media content, with forward secrecy — each message uses a fresh key that is destroyed after use.
  • TLS on every connection between the app and our servers, including the real-time message channel.
  • Encryption at rest for stored data, and media that is already ciphertext before it reaches our storage.
  • No plaintext secrets: one-time codes and refresh tokens are stored only as hashes. Private keys exist solely on your device and are never transmitted.
  • Single-device binding: signing in on a new device revokes the old device's keys and connection immediately.
  • Key-change warnings and safety numbers, so you can verify independently that you're talking to the person you think you are.
  • Least privilege internally — access to production systems is restricted, and message content is beyond even our own reach by design.

12. Your rights and choices

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you, and get a summary of it.
  • Correct inaccurate data — most of it (name, username, avatar, recovery email) is editable directly in the app. Date of birth is set once at signup; contact us if it's wrong.
  • Delete your account and data — available in the app, immediately (§13).
  • Withdraw consent for optional processing, by unbinding your recovery email, removing your avatar, or revoking a device permission.
  • Object to or restrict processing based on legitimate interests.
  • Portability of data you gave us, where applicable. Note that message content is not exportable by anyone, including us — it is encrypted and short-lived by design.
  • Complain to your local data protection authority, or in India to the Data Protection Board.
  • Nominate another person to exercise your rights in the event of your death or incapacity, where Indian law provides this.

Write to [email protected] to exercise any of these. We'll verify the request against your account — usually via your registered phone number — and respond within 30 days. There is no charge.

13. Deleting your account

You can delete your account from within the app at any time — no email, no waiting period. Step-by-step instructions live at yumebee.app/delete-account. Deletion is irreversible, and it:

  • Deletes your account record, profile, date of birth, and recovery email.
  • Deletes your device record, public keys, and all session and refresh tokens.
  • Deletes your avatar and any encrypted media still waiting in the ephemeral mailbox.
  • Removes your friendships and notifies your friends that you're gone.
  • Removes you from every group you're in, leaving a system note for the other members.

Two honest caveats. First, messages you already sent live on the recipients' devices until they expire on their normal 24-hour schedule — we cannot reach into someone else's phone. Second, watch-card send records (§8) are retained as internal records, and are de-identified rather than erased where we must keep them; ask us at [email protected] if you want that confirmed for your account. Backups and logs age out on the schedules in §8.

14. Children

YumeBee is not for children under 13, and we do not knowingly collect data from them. We ask for date of birth at signup to enforce this. If you believe a child under 13 has created an account, write to [email protected] and we will delete it. Where local law sets a higher minimum age for consent to data processing, that higher age applies. Our standards against child sexual abuse and exploitation, how to report it from inside the app, and our designated contact are published at yumebee.app/child-safety.

15. Where data is stored and transferred

Our servers and databases are operated by us on infrastructure we control. Because messaging is global, your data may be processed in countries other than your own, including by the notification and messaging providers listed in §9. Where such a transfer involves personal data protected by the GDPR, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. Regardless of where a server sits, message content remains encrypted end-to-end and unreadable in transit and at rest.

16. Changes to this policy

We may update this policy as the app changes. The "last updated" date at the top always reflects the current version. If a change is material — for example, collecting a new category of data or sharing with a new kind of recipient — we'll notify you in the app or by another reasonable means before it takes effect. Continued use after that means you accept the updated policy.

17. Contact and grievances

Privacy questions, data requests, and complaints: [email protected]. This address also reaches our Grievance Officer for the purposes of India's Digital Personal Data Protection Act and the Information Technology (Intermediary Guidelines) Rules. We acknowledge grievances promptly and aim to resolve them within the timelines those rules require.

Postal address: YuMe Private Limited, India. Write to the address above and we'll provide the registered office details for formal service.