1. The short version
clyr is designed so our systems do not ordinarily receive the plaintext of supported end-to-end encrypted messages. We do store encrypted message records so conversations can be delivered and synchronized, along with limited account, device, relationship, community, and operational data needed to run the communication service.
We do not sell personal information or use private message content for advertising. A conversation becomes readable to Clyr reviewers only when a participant deliberately reports selected messages, when content is sent to us outside an encrypted conversation, or when it is otherwise not end-to-end encrypted.
2. Who is responsible
Clyr (“clyr,” “we,” “us”) is responsible for the personal information described in this Policy. We operate from Canada and apply Canadian privacy principles, including accountability, identified purposes, consent, limited collection and retention, safeguards, openness, and individual access. Contact our privacy lead at privacy@clyrzones.com.
3. Information we collect
- Account and profile: email address, username, password hash, optional profile details and avatar, settings, two-factor authentication secret in encrypted form, and session records.
- Communities and relationships: zones, channels, memberships, roles, permissions, invitations, friends, blocks, and direct- or group-conversation membership.
- Encrypted communications: ciphertext, unique nonces, authenticated metadata, encrypted key envelopes, message and conversation identifiers, sender device identifiers, timestamps, delivery state, and attachment references. These records enable delivery and history without giving our systems the ordinary plaintext or content keys.
- Device security: device names and platform, public encryption and signing keys, cryptographic key fingerprints, approval or revocation state, first and last activity, and key-change or security events. A key fingerprint verifies a Clyr identity key; it is not an advertising or cross-site tracking fingerprint.
- Calls: participant and session identifiers, invitations, signaling data, connection state, and timestamps used to establish WebRTC calls. Clyr does not record call audio, video, or screen content.
- Reports and moderation: report reason, reporter-provided details, the selected plaintext message and small surrounding snippet deliberately disclosed by the reporting user, affected authors, moderation actions, appeals, and audit records.
- Support and privacy requests: messages and verification details you send to support, safety, legal, or privacy teams.
- Operational and security data: request, error, abuse-prevention, authentication, and diagnostic records, which may include IP address, browser or app version, approximate network information, timestamps, and event identifiers.
- Cookies and local storage: essential sign-in, consent, preference, and security data. Browser clients may store non-extractable private cryptographic keys in local browser storage such as IndexedDB.
4. How and why we use information
- Provide the Service: create accounts, deliver encrypted messages, maintain zones and friendships, synchronize approved devices, connect calls, and remember settings. This is generally necessary to perform our contract with you.
- Protect users and clyr: authenticate accounts, detect abuse, notify you about device and key changes, investigate reports, enforce rules, prevent fraud, and secure the Service. We rely on our legitimate interests and legal obligations where applicable.
- Communicate with you: send transactional, security, moderation, privacy-request, and support messages. Marketing is optional and may be withdrawn.
- Improve reliability: diagnose errors, measure aggregate performance, and develop features. Non-essential analytics, where used, depend on consent where the law requires it.
- Meet legal obligations: respond to valid legal process, preserve evidence, protect rights and safety, and maintain required records.
5. How end-to-end encryption works
Your device creates encryption and signing keys locally. Clyr receives public keys so other users can encrypt conversation keys for your approved devices; private keys remain on your device in non-extractable storage where the platform supports it. Encrypted key envelopes let recipient devices unlock a per-conversation or per-message key without sending that plaintext key to our servers.
Security numbers and key fingerprints let people compare identity keys through a separate trusted channel. Clyr warns when a contact’s key changes. New devices require approval and do not automatically receive old history. Revocation stops future key distribution to that device, but cannot remotely erase content or keys it already received.
Encryption protects message content in transit and on our systems, not compromised endpoints. A participant can still copy, screenshot, export, or report content. Browser-delivered encryption also depends on the integrity of the browser, device, and client code delivered to it.
6. Reports: when plaintext is disclosed
Before a report is sent, the reporting client identifies the selected message and limited surrounding context that will leave the encrypted conversation. That content is decrypted locally and submitted to Trust & Safety with the report reason. Authors whose messages are included receive a notice explaining that those specific messages were disclosed and why. Reviewers can see the submitted snippet, not browse the rest of the conversation.
7. Calls and network privacy
Call media is designed to pass directly between participants through WebRTC when possible. Our systems handle signaling and basic session state, but do not record call media. Peer-to-peer calling can expose a participant’s network address or network characteristics to other participants and depends on browser, device, and network providers. If Clyr later uses a media relay where direct connection is unavailable, we will update this Policy and the product disclosure.
8. When we share information
We do not sell personal information. We disclose only what is reasonably needed:
- to infrastructure, hosting, storage, network, email, security, and support providers acting for us under contractual restrictions;
- to people, zones, and devices you direct us to communicate with;
- to reviewers when a user deliberately submits a report;
- to authorities or others when required by valid law, or when reasonably necessary to protect rights, safety, and the integrity of the Service; and
- as part of a merger, financing, reorganization, or sale, subject to appropriate confidentiality and notice where required.
Providers may process information in Canada, the United States, and other places where they or their systems operate. This means information may be subject to local law. We use contractual and other safeguards required for applicable international transfers.
9. Retention and deletion
- Account, profile, membership, and relationship data is generally retained while your account is active.
- Encrypted message records are retained to provide conversation history until they are deleted by a user or space with authority to do so, the related account or zone is deleted where applicable, or they are no longer needed.
- Session tokens ordinarily expire after 30 days unless ended sooner.
- Device, authentication, moderation, report, appeal, and security records are retained as reasonably necessary to protect users, document decisions, prevent abuse, and meet legal obligations.
- Support and privacy-request records are retained while the request is handled and for an appropriate accountability period.
- Deleted data may remain in restricted backups until those backups age out under our operational schedule.
Deletion requests are verified and reviewed. We delete or de-identify information unless retention is required for law, security, fraud prevention, an unresolved dispute, enforcement, or another permitted purpose. Revoking a device or deleting server records cannot erase copies already decrypted or saved by another participant.
10. Your choices and rights
Depending on where you live, you may ask to access, correct, delete, restrict, or receive a portable copy of personal information; object to certain processing; withdraw consent; or complain to a privacy regulator. We will not discriminate against you for exercising a privacy right. Some rights have legal exceptions and we may verify your identity.
Use Data & account requests or email privacy@clyrzones.com. You can also manage profile data, sessions, devices, keys, notifications, blocks, and account deletion from Settings. EU, EEA, and UK users may complain to their local supervisory authority; Canadian users may contact the Office of the Privacy Commissioner of Canada or the applicable provincial regulator.
11. Automated tools and appeals
We may use automated signals to prevent spam, abuse, credential attacks, or other security threats and to help prioritize moderation. Where a decision materially restricts an account, eligible users can request human review through Data & account requests. We do not use private encrypted message plaintext for general automated scanning.
12. Children
clyr is not intended for children under 13. If local law requires a higher age or parental consent, that rule applies. Contact safety@clyrzones.com if you believe a child is using clyr unlawfully.
13. Security
We use encryption in transit, password hashing, encrypted two-factor secrets, access controls, non-extractable device keys where supported, authenticated encryption, device approval and revocation, key-change warnings, audit records, and other safeguards appropriate to the information. No service is perfectly secure. Keep your device and recovery methods safe, verify unexpected key changes, and report suspected compromise to security@clyrzones.com.
14. Changes and contact
We may update this Policy when the product, providers, or law changes. We will update the effective date and give additional notice for material changes. Questions or requests can be sent to privacy@clyrzones.com or through our privacy contact form.