What YumeBee collects, what our servers genuinely cannot see, how long we
keep things, and how to get rid of all of it. Please read this alongside
our Terms of Service.
1. Who we are
YumeBee is a private, end-to-end encrypted messaging app for iOS and
Android, operated by YuMe Private Limited ("YumeBee,"
"we," "us," or "our").
We are the data controller (in India, the "data fiduciary") for the
personal data described here.
This policy covers the YumeBee mobile app and the backend services it
talks to. It does not cover anything you do in other apps, including the
messaging service used to deliver your one-time sign-in code.
2. The short version
Message contentEnd-to-end encrypted. We cannot read your texts, photos, or videos — not on request, not under pressure, not by accident.
LifespanMessages and media are deleted about 24 hours after they're sent, delivered or not. There is no chat history or backup, anywhere.
Account dataPhone number, name, username, date of birth, avatar, and an optional recovery email. Kept until you delete your account.
No address bookWe never upload your contacts. You add friends by typing a phone number or username.
No ads, no sellingNo advertising SDKs, no ad identifiers, no data brokers. We do not sell or rent your data to anyone.
Watch cardsThe one exception: watch cards are not encrypted and are kept indefinitely as an internal record. Details in §3 and §8.
3. Information we collect
a. Information you give us
Phone number. Required. It is your account identifier, and we verify it with a one-time code sent over WhatsApp. We store the number; we store the code only as a keyed hash, for a few minutes.
Profile. First and last name, the display name assembled from them, a unique username, and your date of birth (collected once at signup, to check the minimum-age requirement, and not editable afterward).
Avatar. If you set one, the image is stored in our object storage and served to your friends. Unlike message media, an avatar is not end-to-end encrypted.
Recovery email (optional). If you choose to bind one, we store the address and whether it's verified. It is used only to help you regain access if you lose your phone number — never to log in, never for marketing.
Social graph. Friend requests and friendships, blocks, group memberships and pending group invitations, and group names.
Watch cards. When you send a watch card, we store the whole card: the title and poster from the third-party catalog, the season and episodes you marked watched, any star rating, and any note you typed. This is not encrypted and we can read it. See §4 and §8.
Reports. If you report a user or a message, whatever you send us as part of that report.
b. Information collected automatically
Device record. Platform (iOS or Android), app version, your push notification token, an internal device and connection identifier, and when the device was bound and last seen. One device per account — signing in elsewhere replaces this record.
IP address. Seen on every request, as it must be for anything on the internet to work. We use it transiently to rate-limit one-time codes and to spot abuse, and it appears in short-lived server access logs. We do not build a location profile from it.
Routing metadata. Delivering a message requires knowing who is sending to whom, when, roughly how large it is, and what type it is (text, photo, video, sticker, emoji) so a push notification can be labeled. This is inherent to running a messaging service and is not something encryption can hide.
Delivery state. Delivered and read markers per conversation, typing indicators, online/offline presence, and unread counts. These are not end-to-end encrypted.
Diagnostics and usage analytics. Our own self-hosted analytics records app events — which screen you opened, taps on major actions, connection and encryption-setup successes and failures, and API call outcomes — along with your user ID, a session ID, platform, OS version, and app version. No message content is ever included.
Crash reports. When the app hits an unhandled error we send the exception type, a truncated error message, and the top stack frames through that same pipeline. These are code locations, not your data.
Operational logs and metrics. Standard server logs and aggregate counters (request rates, error rates, delivery latency) used to keep the service running.
c. Message content
Message text, photos, and videos pass through our servers only as
ciphertext we hold briefly for delivery. Encrypted media sits in object
storage until the recipient fetches it, and is deleted on the same 24-hour
schedule (or immediately, if you delete the message). We hold no key that
would open any of it.
4. What we cannot see — and what we can
YumeBee uses the Signal protocol for end-to-end encryption, in both 1:1
chats and groups. Being precise about the boundary matters more than
sounding reassuring, so:
We cannot read:
Message text and emoji.
Photo and video content, and custom stickers you make from your own photos — all encrypted on your device before upload.
The keys that unlock media, which travel only inside the encrypted message.
We can see (protected in transit by TLS, but readable by our servers):
Everything in §3(a) and §3(b) — your account details, your friend and group lists, routing metadata, and delivery state.
Watch cards, including any note you type on one. A watch card note is the only text you type in YumeBee that our servers can read. If it's sensitive, send it as a message instead.
Which built-in sticker you sent (the sticker images themselves are public assets anyone can see in the app).
In a group, which members you @mentioned — sent to us in plain form solely so we can send those members a "you were tagged" notification. The message text itself, including the name you typed, stays encrypted.
Group system messages (joins, leaves, invitations, renames) and the non-content activity signals we compute from message counts and timing — the most-active-member marker, the quiet-member note, and the group "aliveness" score.
Because your keys never leave your devices, we cannot recover your
messages if you lose your phone, reinstall, or switch devices —
for you, for law enforcement, or for ourselves.
5. What we never collect
Your contacts. The app never reads or uploads your address book. Friends are found by typing a phone number or username.
Your location. No GPS, no location permission, no location inferred and stored from your IP.
Advertising identifiers. No IDFA, no Android Advertising ID, no advertising or attribution SDKs of any kind.
Biometrics. If you lock the app with Face ID, Touch ID, or a fingerprint, that check happens entirely on your device — nothing about it reaches us.
Payment information. YumeBee is currently free and has no in-app purchases.
Third-party trackers. Our analytics are self-hosted on our own infrastructure. There is no Google Analytics, Firebase Analytics, Crashlytics, Meta SDK, or similar in the app.
We do not sell, rent, or trade personal data — to anyone, for any price
6. How we use information
To run the service: verify your phone number, create and secure your account, bind your device, route messages to the right recipients, deliver push notifications, and show presence and receipts.
To let you find and be found by friends: phone number and username lookup, friend requests, groups.
For the catalog and watch cards: your search terms are proxied to the third-party movie/TV catalog through our backend, so the catalog provider sees our server rather than you.
To keep the service safe: rate limits, abuse and spam detection, and acting on user reports.
To fix and improve the app: diagnosing crashes, finding broken flows, and understanding which features are used — from event and error data, never from message content.
To help you recover access: if you bound a recovery email, sending a code to it when you ask to recover.
To comply with law: responding to valid legal process, within the hard limits of what we actually hold (§9).
We do not use your data for advertising, profiling for marketing, or
automated decisions with legal effects. We do not send marketing email.
7. Legal bases for processing
Where the GDPR, the UK GDPR, or India's Digital Personal Data Protection
Act applies, we rely on:
Performance of a contract — everything needed to give you the service you signed up for (§6, first three bullets).
Consent — the optional pieces: binding a recovery email, setting an avatar, granting camera or photo access, enabling notifications. You can withdraw consent by removing the data or revoking the permission.
Legitimate interests — security, abuse prevention, and keeping the app working (rate limits, logs, crash reports, aggregate usage analytics), balanced against the fact that we deliberately hold as little as possible.
Legal obligation — where a law or valid order requires us to retain or produce something.
8. How long we keep it
Data
Kept for
Message text and encrypted media
About 24 hours from sending, whether or not delivered, then deleted from our infrastructure. Deleted immediately if you delete the message.
One-time sign-in codes
5 minutes, stored only as a keyed hash, then discarded. Also discarded on use.
Session and refresh tokens
Access tokens minutes; refresh tokens up to 30 days, stored hashed. Revoked immediately on logout, account deletion, or when a new device takes over.
Presence, typing, unread counts
Transient — held in an ephemeral store and expired automatically.
Delivered / read markers
Kept per conversation for as long as the conversation exists, so receipts survive a reconnect.
Account, profile, avatar, public keys, friendships, group memberships
Until you delete your account, after which they are removed.
Watch card send records
Indefinitely, as an internal record — even though the card disappears from your chat after 24 hours and is never shown back to any user.
Diagnostics, usage analytics, crash reports
Up to 12 months, then deleted or kept only in aggregate form that no longer identifies you.
Server access logs and operational metrics
Up to 90 days.
We may keep a specific item longer where a law or a live legal claim
requires it, and only for as long as that requirement lasts.
9. Who we share information with
We share the minimum necessary, with these categories only:
Recipient
What they get, and why
Other YumeBee users
Your display name, username, and avatar are visible to people who can find or message you. Your friends see your presence and receipts. Message content goes only to the recipients you chose — encrypted.
WhatsApp Business messaging provider (Gupshup)
Your phone number and the one-time code, solely to deliver your sign-in code over WhatsApp.
Apple (APNs) and Google (FCM)
Your push token and a content-less notification — enough to say a message arrived, never what it says.
Email relay
Your recovery email address and a verification or recovery code, only if you use email recovery.
TMDB (movie/TV catalog)
Search terms and title lookups, proxied through our backend. TMDB does not receive your identity or IP address from us.
Infrastructure providers
Hosting and network providers that run our servers. They process data on our instructions under contract; our databases and analytics are self-hosted on infrastructure we control.
Legal and safety
Government or law enforcement bodies, where we receive valid legal process. We disclose only what we actually hold — which, for message content, is nothing readable.
Corporate transactions
If YumeBee is ever involved in a merger, acquisition, or asset sale, data may transfer to the successor, which stays bound by this policy. We will tell you before it takes effect.
That is the complete list of categories. We do not share your data with
advertisers, data brokers, or analytics companies, because we do not work
with any.
10. Device permissions we ask for
Each of these is optional, requested only in the moment you use the
feature, and revocable in your device settings at any time.
Camera — to take a photo or video to send. Captured media is encrypted on your device.
Microphone — to record audio as part of a video you shoot. YumeBee has no voice or video calling.
Photo library — to pick an existing photo or video to send, or to set your avatar. We access only what you pick.
Notifications — to alert you that a message arrived. Notifications never contain message content.
We ask for nothing else — no contacts, no location, no calendar, no
microphone access outside of video capture, and no background tracking.
11. How we protect information
End-to-end encryption (Signal protocol) for message and media content, with forward secrecy — each message uses a fresh key that is destroyed after use.
TLS on every connection between the app and our servers, including the real-time message channel.
Encryption at rest for stored data, and media that is already ciphertext before it reaches our storage.
No plaintext secrets: one-time codes and refresh tokens are stored only as hashes. Private keys exist solely on your device and are never transmitted.
Single-device binding: signing in on a new device revokes the old device's keys and connection immediately.
Key-change warnings and safety numbers, so you can verify independently that you're talking to the person you think you are.
Least privilege internally — access to production systems is restricted, and message content is beyond even our own reach by design.
NO SYSTEM IS PERFECTLY SECURE. WE CANNOT GUARANTEE ABSOLUTE SECURITY OF
INFORMATION TRANSMITTED TO OR STORED ON THE SERVICE, AND YOU ARE
RESPONSIBLE FOR KEEPING YOUR DEVICE AND ITS LOCK SCREEN SECURE.
12. Your rights and choices
Depending on where you live, you may have the right to:
Access the personal data we hold about you, and get a summary of it.
Correct inaccurate data — most of it (name, username, avatar, recovery email) is editable directly in the app. Date of birth is set once at signup; contact us if it's wrong.
Delete your account and data — available in the app, immediately (§13).
Withdraw consent for optional processing, by unbinding your recovery email, removing your avatar, or revoking a device permission.
Object to or restrict processing based on legitimate interests.
Portability of data you gave us, where applicable. Note that message content is not exportable by anyone, including us — it is encrypted and short-lived by design.
Complain to your local data protection authority, or in India to the Data Protection Board.
Nominate another person to exercise your rights in the event of your death or incapacity, where Indian law provides this.
Write to legal@yumebee.com to
exercise any of these. We'll verify the request against your account —
usually via your registered phone number — and respond within 30 days.
There is no charge.
13. Deleting your account
You can delete your account from within the app at any time — no email,
no waiting period. Step-by-step instructions live at
yumebee.app/delete-account. Deletion is
irreversible, and it:
Deletes your account record, profile, date of birth, and recovery email.
Deletes your device record, public keys, and all session and refresh tokens.
Deletes your avatar and any encrypted media still waiting in the ephemeral mailbox.
Removes your friendships and notifies your friends that you're gone.
Removes you from every group you're in, leaving a system note for the other members.
Two honest caveats. First, messages you already sent live on the
recipients' devices until they expire on their normal 24-hour schedule —
we cannot reach into someone else's phone. Second, watch-card send records
(§8) are retained as internal records, and are de-identified rather than
erased where we must keep them; ask us at
legal@yumebee.com if you want that
confirmed for your account. Backups and logs age out on the schedules in
§8.
14. Children
YumeBee is not for children under 13, and we do not knowingly collect data
from them. We ask for date of birth at signup to enforce this. If you
believe a child under 13 has created an account, write to
legal@yumebee.com and we will delete
it. Where local law sets a higher minimum age for consent to data
processing, that higher age applies.
15. Where data is stored and transferred
Our servers and databases are operated by us on infrastructure we control.
Because messaging is global, your data may be processed in countries other
than your own, including by the notification and messaging providers listed
in §9. Where such a transfer involves personal data protected by the GDPR,
we rely on appropriate safeguards such as the European Commission's
Standard Contractual Clauses. Regardless of where a server sits, message
content remains encrypted end-to-end and unreadable in transit and at rest.
16. Changes to this policy
We may update this policy as the app changes. The "last updated" date at
the top always reflects the current version. If a change is material — for
example, collecting a new category of data or sharing with a new kind of
recipient — we'll notify you in the app or by another reasonable means
before it takes effect. Continued use after that means you accept the
updated policy.
17. Contact and grievances
Privacy questions, data requests, and complaints:
legal@yumebee.com. This address
also reaches our Grievance Officer for the purposes of India's Digital
Personal Data Protection Act and the Information Technology (Intermediary
Guidelines) Rules. We acknowledge grievances promptly and aim to resolve
them within the timelines those rules require.
Postal address: YuMe Private Limited, India. Write to the address above
and we'll provide the registered office details for formal service.