YumeBee mascot yumebee

Privacy Policy

Last updated · August 5, 2026

What YumeBee collects, what our servers genuinely cannot see, how long we keep things, and how to get rid of all of it. Please read this alongside our Terms of Service.

1. Who we are

YumeBee is a private, end-to-end encrypted messaging app for iOS and Android, operated by YuMe Private Limited ("YumeBee," "we," "us," or "our"). We are the data controller (in India, the "data fiduciary") for the personal data described here.

This policy covers the YumeBee mobile app and the backend services it talks to. It does not cover anything you do in other apps, including the messaging service used to deliver your one-time sign-in code.

2. The short version

Message contentEnd-to-end encrypted. We cannot read your texts, photos, or videos — not on request, not under pressure, not by accident.
LifespanMessages and media are deleted about 24 hours after they're sent, delivered or not. There is no chat history or backup, anywhere.
Account dataPhone number, name, username, date of birth, avatar, and an optional recovery email. Kept until you delete your account.
No address bookWe never upload your contacts. You add friends by typing a phone number or username.
No ads, no sellingNo advertising SDKs, no ad identifiers, no data brokers. We do not sell or rent your data to anyone.
Watch cardsThe one exception: watch cards are not encrypted and are kept indefinitely as an internal record. Details in §3 and §8.

3. Information we collect

a. Information you give us

  • Phone number. Required. It is your account identifier, and we verify it with a one-time code sent over WhatsApp. We store the number; we store the code only as a keyed hash, for a few minutes.
  • Profile. First and last name, the display name assembled from them, a unique username, and your date of birth (collected once at signup, to check the minimum-age requirement, and not editable afterward).
  • Avatar. If you set one, the image is stored in our object storage and served to your friends. Unlike message media, an avatar is not end-to-end encrypted.
  • Recovery email (optional). If you choose to bind one, we store the address and whether it's verified. It is used only to help you regain access if you lose your phone number — never to log in, never for marketing.
  • Social graph. Friend requests and friendships, blocks, group memberships and pending group invitations, and group names.
  • Watch cards. When you send a watch card, we store the whole card: the title and poster from the third-party catalog, the season and episodes you marked watched, any star rating, and any note you typed. This is not encrypted and we can read it. See §4 and §8.
  • Reports. If you report a user or a message, whatever you send us as part of that report.

b. Information collected automatically

  • Device record. Platform (iOS or Android), app version, your push notification token, an internal device and connection identifier, and when the device was bound and last seen. One device per account — signing in elsewhere replaces this record.
  • IP address. Seen on every request, as it must be for anything on the internet to work. We use it transiently to rate-limit one-time codes and to spot abuse, and it appears in short-lived server access logs. We do not build a location profile from it.
  • Routing metadata. Delivering a message requires knowing who is sending to whom, when, roughly how large it is, and what type it is (text, photo, video, sticker, emoji) so a push notification can be labeled. This is inherent to running a messaging service and is not something encryption can hide.
  • Delivery state. Delivered and read markers per conversation, typing indicators, online/offline presence, and unread counts. These are not end-to-end encrypted.
  • Diagnostics and usage analytics. Our own self-hosted analytics records app events — which screen you opened, taps on major actions, connection and encryption-setup successes and failures, and API call outcomes — along with your user ID, a session ID, platform, OS version, and app version. No message content is ever included.
  • Crash reports. When the app hits an unhandled error we send the exception type, a truncated error message, and the top stack frames through that same pipeline. These are code locations, not your data.
  • Operational logs and metrics. Standard server logs and aggregate counters (request rates, error rates, delivery latency) used to keep the service running.

c. Message content

Message text, photos, and videos pass through our servers only as ciphertext we hold briefly for delivery. Encrypted media sits in object storage until the recipient fetches it, and is deleted on the same 24-hour schedule (or immediately, if you delete the message). We hold no key that would open any of it.

4. What we cannot see — and what we can

YumeBee uses the Signal protocol for end-to-end encryption, in both 1:1 chats and groups. Being precise about the boundary matters more than sounding reassuring, so:

We cannot read:

  • Message text and emoji.
  • Photo and video content, and custom stickers you make from your own photos — all encrypted on your device before upload.
  • The keys that unlock media, which travel only inside the encrypted message.

We can see (protected in transit by TLS, but readable by our servers):

  • Everything in §3(a) and §3(b) — your account details, your friend and group lists, routing metadata, and delivery state.
  • Watch cards, including any note you type on one. A watch card note is the only text you type in YumeBee that our servers can read. If it's sensitive, send it as a message instead.
  • Which built-in sticker you sent (the sticker images themselves are public assets anyone can see in the app).
  • In a group, which members you @mentioned — sent to us in plain form solely so we can send those members a "you were tagged" notification. The message text itself, including the name you typed, stays encrypted.
  • Group system messages (joins, leaves, invitations, renames) and the non-content activity signals we compute from message counts and timing — the most-active-member marker, the quiet-member note, and the group "aliveness" score.

Because your keys never leave your devices, we cannot recover your messages if you lose your phone, reinstall, or switch devices — for you, for law enforcement, or for ourselves.

5. What we never collect

  • Your contacts. The app never reads or uploads your address book. Friends are found by typing a phone number or username.
  • Your location. No GPS, no location permission, no location inferred and stored from your IP.
  • Advertising identifiers. No IDFA, no Android Advertising ID, no advertising or attribution SDKs of any kind.
  • Biometrics. If you lock the app with Face ID, Touch ID, or a fingerprint, that check happens entirely on your device — nothing about it reaches us.
  • Payment information. YumeBee is currently free and has no in-app purchases.
  • Third-party trackers. Our analytics are self-hosted on our own infrastructure. There is no Google Analytics, Firebase Analytics, Crashlytics, Meta SDK, or similar in the app.
We do not sell, rent, or trade personal data — to anyone, for any price

6. How we use information

  • To run the service: verify your phone number, create and secure your account, bind your device, route messages to the right recipients, deliver push notifications, and show presence and receipts.
  • To let you find and be found by friends: phone number and username lookup, friend requests, groups.
  • For the catalog and watch cards: your search terms are proxied to the third-party movie/TV catalog through our backend, so the catalog provider sees our server rather than you.
  • To keep the service safe: rate limits, abuse and spam detection, and acting on user reports.
  • To fix and improve the app: diagnosing crashes, finding broken flows, and understanding which features are used — from event and error data, never from message content.
  • To help you recover access: if you bound a recovery email, sending a code to it when you ask to recover.
  • To comply with law: responding to valid legal process, within the hard limits of what we actually hold (§9).

We do not use your data for advertising, profiling for marketing, or automated decisions with legal effects. We do not send marketing email.

8. How long we keep it

DataKept for
Message text and encrypted media About 24 hours from sending, whether or not delivered, then deleted from our infrastructure. Deleted immediately if you delete the message.
One-time sign-in codes 5 minutes, stored only as a keyed hash, then discarded. Also discarded on use.
Session and refresh tokens Access tokens minutes; refresh tokens up to 30 days, stored hashed. Revoked immediately on logout, account deletion, or when a new device takes over.
Presence, typing, unread counts Transient — held in an ephemeral store and expired automatically.
Delivered / read markers Kept per conversation for as long as the conversation exists, so receipts survive a reconnect.
Account, profile, avatar, public keys, friendships, group memberships Until you delete your account, after which they are removed.
Watch card send records Indefinitely, as an internal record — even though the card disappears from your chat after 24 hours and is never shown back to any user.
Diagnostics, usage analytics, crash reports Up to 12 months, then deleted or kept only in aggregate form that no longer identifies you.
Server access logs and operational metrics Up to 90 days.

We may keep a specific item longer where a law or a live legal claim requires it, and only for as long as that requirement lasts.

9. Who we share information with

We share the minimum necessary, with these categories only:

RecipientWhat they get, and why
Other YumeBee users Your display name, username, and avatar are visible to people who can find or message you. Your friends see your presence and receipts. Message content goes only to the recipients you chose — encrypted.
WhatsApp Business messaging provider (Gupshup) Your phone number and the one-time code, solely to deliver your sign-in code over WhatsApp.
Apple (APNs) and Google (FCM) Your push token and a content-less notification — enough to say a message arrived, never what it says.
Email relay Your recovery email address and a verification or recovery code, only if you use email recovery.
TMDB (movie/TV catalog) Search terms and title lookups, proxied through our backend. TMDB does not receive your identity or IP address from us.
Infrastructure providers Hosting and network providers that run our servers. They process data on our instructions under contract; our databases and analytics are self-hosted on infrastructure we control.
Legal and safety Government or law enforcement bodies, where we receive valid legal process. We disclose only what we actually hold — which, for message content, is nothing readable.
Corporate transactions If YumeBee is ever involved in a merger, acquisition, or asset sale, data may transfer to the successor, which stays bound by this policy. We will tell you before it takes effect.

That is the complete list of categories. We do not share your data with advertisers, data brokers, or analytics companies, because we do not work with any.

10. Device permissions we ask for

Each of these is optional, requested only in the moment you use the feature, and revocable in your device settings at any time.

  • Camera — to take a photo or video to send. Captured media is encrypted on your device.
  • Microphone — to record audio as part of a video you shoot. YumeBee has no voice or video calling.
  • Photo library — to pick an existing photo or video to send, or to set your avatar. We access only what you pick.
  • Notifications — to alert you that a message arrived. Notifications never contain message content.

We ask for nothing else — no contacts, no location, no calendar, no microphone access outside of video capture, and no background tracking.

11. How we protect information

  • End-to-end encryption (Signal protocol) for message and media content, with forward secrecy — each message uses a fresh key that is destroyed after use.
  • TLS on every connection between the app and our servers, including the real-time message channel.
  • Encryption at rest for stored data, and media that is already ciphertext before it reaches our storage.
  • No plaintext secrets: one-time codes and refresh tokens are stored only as hashes. Private keys exist solely on your device and are never transmitted.
  • Single-device binding: signing in on a new device revokes the old device's keys and connection immediately.
  • Key-change warnings and safety numbers, so you can verify independently that you're talking to the person you think you are.
  • Least privilege internally — access to production systems is restricted, and message content is beyond even our own reach by design.

12. Your rights and choices

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you, and get a summary of it.
  • Correct inaccurate data — most of it (name, username, avatar, recovery email) is editable directly in the app. Date of birth is set once at signup; contact us if it's wrong.
  • Delete your account and data — available in the app, immediately (§13).
  • Withdraw consent for optional processing, by unbinding your recovery email, removing your avatar, or revoking a device permission.
  • Object to or restrict processing based on legitimate interests.
  • Portability of data you gave us, where applicable. Note that message content is not exportable by anyone, including us — it is encrypted and short-lived by design.
  • Complain to your local data protection authority, or in India to the Data Protection Board.
  • Nominate another person to exercise your rights in the event of your death or incapacity, where Indian law provides this.

Write to legal@yumebee.com to exercise any of these. We'll verify the request against your account — usually via your registered phone number — and respond within 30 days. There is no charge.

13. Deleting your account

You can delete your account from within the app at any time — no email, no waiting period. Step-by-step instructions live at yumebee.app/delete-account. Deletion is irreversible, and it:

  • Deletes your account record, profile, date of birth, and recovery email.
  • Deletes your device record, public keys, and all session and refresh tokens.
  • Deletes your avatar and any encrypted media still waiting in the ephemeral mailbox.
  • Removes your friendships and notifies your friends that you're gone.
  • Removes you from every group you're in, leaving a system note for the other members.

Two honest caveats. First, messages you already sent live on the recipients' devices until they expire on their normal 24-hour schedule — we cannot reach into someone else's phone. Second, watch-card send records (§8) are retained as internal records, and are de-identified rather than erased where we must keep them; ask us at legal@yumebee.com if you want that confirmed for your account. Backups and logs age out on the schedules in §8.

14. Children

YumeBee is not for children under 13, and we do not knowingly collect data from them. We ask for date of birth at signup to enforce this. If you believe a child under 13 has created an account, write to legal@yumebee.com and we will delete it. Where local law sets a higher minimum age for consent to data processing, that higher age applies.

15. Where data is stored and transferred

Our servers and databases are operated by us on infrastructure we control. Because messaging is global, your data may be processed in countries other than your own, including by the notification and messaging providers listed in §9. Where such a transfer involves personal data protected by the GDPR, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. Regardless of where a server sits, message content remains encrypted end-to-end and unreadable in transit and at rest.

16. Changes to this policy

We may update this policy as the app changes. The "last updated" date at the top always reflects the current version. If a change is material — for example, collecting a new category of data or sharing with a new kind of recipient — we'll notify you in the app or by another reasonable means before it takes effect. Continued use after that means you accept the updated policy.

17. Contact and grievances

Privacy questions, data requests, and complaints: legal@yumebee.com. This address also reaches our Grievance Officer for the purposes of India's Digital Personal Data Protection Act and the Information Technology (Intermediary Guidelines) Rules. We acknowledge grievances promptly and aim to resolve them within the timelines those rules require.

Postal address: YuMe Private Limited, India. Write to the address above and we'll provide the registered office details for formal service.