The rules for using YumeBee — a cozy, end-to-end encrypted space for you and
your friends. Please read this alongside our Privacy Policy.
1. Acceptance of these Terms
These Terms of Service ("Terms") are a binding agreement
between you ("you" or "User") and YuMe
Private Limited ("YumeBee," "we,"
"us," or "our"), governing your access to
and use of the YumeBee mobile application and backend services (together,
the "Service").
By creating an account or otherwise using the Service, you agree to these
Terms and to our Privacy Policy. If you do not agree, do not use the
Service.
2. What YumeBee is
YumeBee is a mobile messaging app for iOS and Android. It provides:
1:1 private messaging — text, emoji, photo, and short view-once video messages between exactly two people.
Group messaging — invite-only groups of 2–20 members ("watch circles"), used the same way as 1:1 chats. Being added to a group is an invitation you must accept, not an automatic join (see §4).
End-to-end encryption (E2EE) for message text and media, using the Signal protocol. See §5 for exactly what this does and does not protect.
Ephemeral content — messages, media, and group chat content are not stored in server-side chat history. They are automatically deleted from our infrastructure approximately 24 hours after being sent, whether or not they were delivered, and are deleted on your device on the same schedule. There is no message backup, export, or history feature. If you or a friend delete the app, or a device is lost, that content cannot be recovered by us or by you.
Magic Connect — an opt-in, in-person way to become friends: two users open the Magic Connect screen and hold their phones together, and the app uses Bluetooth Low Energy proximity to connect them instantly, with no friend request or acceptance step. See §4.
Watch cards — a feature for sharing a movie or TV title pulled from a third-party catalog (TMDB): a card carrying the poster and title, for a TV show the season and episodes you marked watched, and optionally a star rating and a short free-text note you type (up to 280 characters). Unlike chat messages, watch cards are not end-to-end encrypted — including any note you type — and a copy is retained indefinitely on our servers as an internal record, even though it disappears from your chat view after 24 hours. See §5 and §6.
Stickers — a built-in sticker tray of public, non-secret images (only the fact of which sticker you sent is encrypted), plus custom stickers you make from your own photos, which are sent through the same end-to-end encrypted media pipeline as a photo. Sending any sticker is end-to-end encrypted at the message level.
Group activity signals — for groups we compute non-content indicators from message counts and timing (never content): a "most active member" marker, an occasional automated note when a member has gone quiet, and a group "aliveness" rating score. See §4.
Presence, typing indicators, and delivery/read receipts — real-time status signals that are not end-to-end encrypted (see §5).
Push notifications that tell you a message arrived without including its content ("content-less push").
No voice or video calling in YumeBee — none is planned
3. Eligibility and accounts
You must be at least 13 years old to use YumeBee, and must be able to form a binding contract under the laws of your jurisdiction. Your date of birth is set once at signup and cannot be changed afterward.
Sign-up is phone-number based. We verify your phone number via a one-time code delivered over WhatsApp. Your account is tied to that phone number.
One device per account. Only one device can be active on your account at a time. Completing sign-up on a new device (e.g., a new phone, or reinstalling the app) replaces the previous device: its encryption keys and connection are revoked, and it will no longer receive new messages. Message content already delivered to the old device is not transferred — see §2 on ephemerality.
Email recovery. You may optionally bind an email address to your account solely to help you regain access if you lose your phone number. Email is never used to log in.
You're responsible for keeping your device and account secure, and for all activity under your account. Tell us promptly if you suspect unauthorized access.
You agree to provide accurate information (in particular, a phone number you control) and not to impersonate another person.
4. Friends, Magic Connect, and groups
Messaging requires becoming "friends" with another user (by phone number or in-app search) and having that request accepted. Either side may remove a friend at any time.
Magic Connect. As an alternative to a friend request, both users may open the Magic Connect screen and hold their phones together. Because both people must deliberately open that screen at the same time and be physically next to each other, we treat that as mutual consent: the friendship is created directly in an accepted state, with no separate acceptance step, and both phones open the conversation. If one of you had already sent the other a pending friend request, a Magic Connect connection accepts it. If either of you has blocked the other, Magic Connect will not connect you.
How Magic Connect works, and what it broadcasts. Magic Connect requires Bluetooth permission (and, on older Android versions, location permission, which Android itself requires for Bluetooth scanning — we do not collect or use your location). While the Magic Connect screen is open in the foreground, your phone broadcasts a random, opaque, single-use code issued by our servers. That code contains no name, phone number, profile, or account identifier; it expires after approximately three minutes and is consumed the moment a connection is made. Nothing is broadcast when the Magic Connect screen is not open. Bluetooth broadcasts are, by nature, receivable by nearby devices — only use Magic Connect when you intend to connect with the person in front of you.
Magic Connect is your responsibility to use deliberately. A Magic Connect connection is immediate and creates a real friendship. If you connect with someone by mistake or change your mind, remove them as a friend, and block them if needed (§8).
Groups have no admin role — any member can invite or remove other members, rename the group, or leave it. Invitees are chosen from the acting member's friend list; other members of the group need not be friends with each other. A group is deleted once its last member leaves.
Invitations, not automatic adds. Adding someone to a group (whether when creating it or later) sends them a pending invitation rather than placing them in the group directly. They become a member only when they accept; if they decline, or a member cancels the invite, the invitation quietly disappears. A pending invitation reserves one of the group's 20 slots until it is accepted, declined, or canceled.
Because group encryption is pairwise (each member's device separately encrypts to each other member), any current member can read messages sent to the group while they are a member, consistent with the E2EE model described in §5.
We compute non-content activity metadata for groups — a "most active member" indicator, an occasional automated note if a member has been quiet, and a group "aliveness" rating score (currently a number from 100 to 1000 reflecting recent engagement) — entirely from message counts and timing over a trailing period, never from message content, which we cannot read.
5. Encryption — what is and isn't protected
We built YumeBee so that we, and anyone operating our infrastructure,
cannot read the text or media content of your messages.
Please understand the actual scope of that protection:
End-to-end encrypted (we cannot read this):
Message text, emoji, and photo/video/media content, in both 1:1 chats and groups. Every photo and video is also view-once: it's fetched and decrypted only when you open it, and closing the viewer permanently consumes it on your device.
Custom stickers you make from your own photos — sent through the same encrypted pipeline as a photo, not stored as a plain image.
Media encryption keys, which travel only inside the encrypted message itself.
Not end-to-end encrypted (visible to our servers, protected only by transport encryption/TLS):
Delivery and read receipts, and typing indicators.
Online/offline presence.
The built-in sticker tray images themselves are public, non-secret assets hosted on our CDN — encryption protects only the fact of which sticker you sent, not the image content, which anyone can already see in the app.
Watch cards (§2, §6) — the title, poster, season/episode markers, rating, and any note you type are stored on our servers in plain, readable form, and are retained even after the card disappears from the chat UI. A note on a watch card is the one piece of text you type in YumeBee that our servers can read; if something is sensitive, put it in a message instead.
Magic Connect discovery codes (§4) — the short-lived random code your phone broadcasts, and the fact that two accounts connected via Magic Connect. The code itself is held only transiently (about three minutes) and is not a durable record; the resulting friendship is retained like any other (§6).
Group system messages (membership and invitation changes, renames, and the "quiet member" note) and the group activity signals described in §4 (most-active-member marker and aliveness rating), which are derived from message counts and timing.
Cleartext routing metadata attached to every message: who is messaging whom, message timing and approximate size, and message type (text/photo/video/emoji/sticker) used to label push notifications. This metadata is inherent to operating the delivery infrastructure and is not something end-to-end encryption can hide.
In a group chat, @mentioning ("tagging") a member — the message text and the @name you typed stay end-to-end encrypted, but which member(s) you tagged is additionally sent to our servers in plain form, solely so we can send that member a "you were tagged" push notification.
We cannot recover lost messages. Because each message is
encrypted with a fresh, forward-secret key that is discarded after use, if
you switch devices, lose your device, or reinstall the app, previously sent
or received messages are permanently unrecoverable — by you or by us. This
is by design and is not a bug we can fix on request.
Key trust. Because we distribute the public encryption
keys used to start a conversation, a compromised or malicious server could
theoretically substitute keys to intercept a new conversation. YumeBee
provides safety-number/QR verification so you and your contacts can
independently confirm you're talking to each other, and warns you when a
contact's key changes (e.g., because they replaced their device). We
encourage you to use this feature for sensitive conversations.
6. Data we retain
Most of what YumeBee handles is designed to be short-lived. We do, however, retain:
Friendship and group membership records — including friendships created through Magic Connect, which are stored no differently from any other friendship. Magic Connect discovery codes are not retained: they live in short-lived ephemeral storage for about three minutes and are discarded on use or expiry.
Watch card sends: the complete card you send (title, poster, for TV shows the season/episodes you marked watched, and any rating and note you added) is stored as-is and retained indefinitely as an internal record, even though it is never shown back to you or any user through the app and disappears from the chat view after 24 hours.
Operational logs and metadata needed to run the Service (e.g., message timing and size, not content) for abuse prevention, debugging, and reliability.
Full detail on what we collect and why will be in our Privacy Policy (coming soon).
7. Acceptable use
You agree not to use YumeBee to:
Harass, threaten, stalk, or abuse another person.
Send unlawful, defamatory, obscene, or infringing content.
Impersonate any person or entity, or misrepresent your affiliation with one.
Attempt to access another user's account, intercept another user's messages, or circumvent the Service's encryption, access controls, or rate limits.
Send spam, phishing content, or malware.
Scrape, reverse-engineer, or interoperate with the Service outside the official client app and documented API, or attempt to overload or disrupt our infrastructure (including the message broker, catalog, or media storage).
Use the Service in violation of applicable law.
Because messages and media are end-to-end encrypted, we generally
cannot see chat content and cannot proactively moderate it.
Enforcement against abusive users therefore relies primarily on reports
from the recipients of that content, on account-level signals we can see
(e.g., messaging patterns), and on the block/report tools in the app. If
you experience abuse, block the user and report it to us using the in-app
report flow.
8. Blocking and reporting; enforcement
You may block or report another user at any time via the app. We may
investigate reports, and may warn, suspend, or terminate accounts, or
remove a user from a group, for violating these Terms. Because message
content is encrypted, a report may rely on what you, as the recipient, are
able to show us (e.g., a description or screenshot); we cannot
independently verify encrypted content.
9. Third-party content and services
Watch card data (movie/TV titles, posters, and season/episode listings) is sourced from a third-party catalog (TMDB) via our backend. We don't control that data's accuracy or availability.
Message delivery, notification, and OTP infrastructure rely on third-party providers (e.g., WhatsApp Business messaging for OTP delivery, Apple/Google push notification services). Your use of those channels is also subject to those providers' own terms.
We are not responsible for third-party services' content, availability, or conduct.
10. Intellectual property
The YumeBee app, backend, branding, and built-in sticker packs are owned
by YuMe Private Limited or its licensors and are protected by intellectual
property law. You may not copy, modify, distribute, or create derivative
works from the Service except as the app's normal functionality allows
(e.g., sending a sticker to a friend).
You retain ownership of the content you send (text, photos, videos,
stickers, etc.). By sending a watch card, you acknowledge it is stored
server-side as described in §6, and you grant us the limited right to
store and process that content for that purpose. We claim no ownership
over your message content and, for end-to-end encrypted content, have no
technical ability to access it in the first place.
11. Account deletion
You may delete your account at any time in the app. Doing so is
irreversible and: removes you from every group you're in
(leaving a system note for other members), notifies your friends that
you've been removed, deletes your account and associated
device/key/token/friendship records, deletes any media you have pending in
the ephemeral mailbox, and deletes your avatar. Retained watch-card send
records (§6) are handled per our Privacy Policy's retention schedule.
We may suspend or terminate your account for violating these Terms,
extended inactivity, or to comply with law.
12. Service availability
YumeBee is provided on an "as is" and "as available" basis. We do not
guarantee uninterrupted or error-free operation. Because message and media
delivery depend on a real-time connection and messages expire after 24
hours if undelivered, messages sent to a recipient who does not
come online within that window will not be delivered — this is
expected behavior, not a defect.
13. Disclaimers
TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SERVICE IS PROVIDED WITHOUT
WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. WE DO NOT WARRANT
THAT THE SERVICE WILL BE UNINTERRUPTED, SECURE, OR ERROR-FREE, OR THAT
ENCRYPTION WILL BE IMPENETRABLE AGAINST ALL POSSIBLE ATTACKS.
14. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, YUME PRIVATE LIMITED WILL NOT BE
LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE
DAMAGES, OR ANY LOSS OF DATA, MESSAGES, OR GOODWILL, ARISING FROM YOUR USE
OF THE SERVICE, INCLUDING LOSS OF MESSAGE CONTENT DUE TO THE SERVICE'S
EPHEMERAL DESIGN (§2, §5). YUMEBEE IS CURRENTLY PROVIDED FREE OF CHARGE;
OUR TOTAL LIABILITY FOR ANY CLAIM RELATING TO THE SERVICE WILL NOT EXCEED
INR 5,000 (RUPEES FIVE THOUSAND).
15. Indemnification
You agree to indemnify and hold YuMe Private Limited harmless from
claims, damages, and expenses (including reasonable legal fees) arising
from your violation of these Terms or misuse of the Service.
16. Changes to these Terms
We may update these Terms from time to time. If we make material changes,
we'll notify you in the app or by another reasonable means before they
take effect. Continued use of the Service after changes take effect
constitutes acceptance.
17. Governing law and disputes
These Terms are governed by the laws of India, without regard to
conflict-of-law principles. Subject to applicable law, the courts of
competent jurisdiction in India will have exclusive jurisdiction over any
dispute arising out of or relating to these Terms or the Service.