Privacy Policy

Last Updated: May 29, 2026 · Effective Date: May 29, 2026

Change Log (2026-05-29)
Chat translation: Gemini → on-device Apple Translation (iOS 26+); manual delete vs inactivity auto-delete; Apple Sign In active; Firebase Crashlytics; no chat location sharing
Change Log (2026-05-05)
Clarified default iOS sign-in path vs social login rollout; private keys stored in iOS Keychain; optional chat translation (Gemini) disclosure; contact-book wording; fixed §12 list markup
Change Log (2026-05-03)
Added §2.5 covering Capture feature and screen-recording detection introduced in v1.0
Added Photo Library permission disclosure (NSPhotoLibraryAddUsageDescription)
Corrected section numbering in §8 (8.1, 8.2, 8.3 — previously 7.1, 7.2, 7.3)
Corrected cross-reference in §8.3 (now points to §9 — previously §8)
Aligned response-time wording in §9.2 with §14
Improved tone with privacy-first framing

Talky ("the Service") respects your privacy and complies with applicable laws including the Korean Personal Information Protection Act (PIPA), EU GDPR, and Russian Federal Law 152-FZ. This Privacy Policy explains what information Talky processes, how it is used, and how it is protected.

1. Operator Information

2. Information Talky Processes

🔒 Talky's Principle: Minimum Processing, Maximum Protection
Talky is an anonymous messenger that processes only the information truly necessary to operate the service.
No phone number, no email address, no real name is required.
Secret chats are end-to-end encrypted — not even the operator can read your messages.

2.1 Minimum Information for Account Creation (At Sign-Up)

2.2 Social Login (User's Choice)

Current iOS app: The default path is anonymous user ID + backup code. Continue with Apple links your account using Apple's identifier. Google / Kakao sign-in are coming soon; Google/Kakao bullets below apply only after those features are enabled.

If you use Apple / Google / Kakao login:

2.3 Information for Message Delivery (Service Operation)

2.4 What Talky NEVER Processes ⭐⭐⭐

Unlike other messengers, Talky never processes the following:

Designed for true anonymity.

2.5 User Protection Features (v1.0+) ⭐ NEW

Talky provides the following user-protection features:

Capture Feature (User-Initiated)

Screen Recording / AirPlay Detection

2.6 Chat Message Translation (Optional, iOS 26+)

Applies only when you use full-chat or bubble translation. Message text is not sent to Talky servers or cloud AI for translation.

2.7 Crash and Error Diagnostics (Firebase Crashlytics)

3. Purpose of Processing

Talky processes information only for the following purposes and for no other purpose whatsoever:

Item Purpose
User ID, display name Account identification and message routing
Backup code hash Account recovery authentication
Public key End-to-end encryption for secret chats
Message content Delivering messages between users
Friends list Displaying chat partners
FCM token Sending push notifications
Online status "Online", "typing" indicators
Photo Library permission Saving chat screen via Capture feature (user-initiated only)
Translation (optional, iOS 26+) On-device Apple translation (§2.6, not sent to servers)
Crashlytics diagnostics Crash/error analysis and stability (§2.7)

🚫 Talky does NOT use personal information for marketing, advertising, sale to third parties, or any similar purpose.

4. End-to-End Encryption (E2E) Security

4.1 Secret Chats (Even the Operator Cannot Read Them)

4.2 Regular Chats

4.3 Security Measures

5. Retention Period

Item Retention
Active account information Until you delete your account
Messages Until you delete them
Manual account deletion Permanent server deletion immediately after confirmation (cannot be undone)
Auto-delete on inactivity After your chosen period (30, 90, 180, or 365 days of no use)
FCM token (inactive) Auto-deleted after 1 year of inactivity
Logs (for debugging) Auto-deleted after 90 days

5.1 Manual Account Deletion

When you confirm Delete Account in Settings → Account & Security:

  1. You are shown as a withdrawn user in chats you participated in
  2. Server data (Firestore, Storage, Firebase Authentication, etc.) is permanently deleted immediately (cannot be undone)

5.2 Auto-Delete on Inactivity

If you enable it in Settings, your account may be deleted automatically after 30, 90, 180 (default), or 365 days without sign-in. This is separate from manual deletion.

6. Third-Party Sharing and Processing

6.1 Data Processors (Required Infrastructure)

Processor Items Location
Google (Firebase) Auth, database, storage, push, Crashlytics (crash diagnostics) Seoul + Singapore
Apple Apple Sign In (if selected) USA / EU
Google Google Sign In (if selected) USA
Kakao Kakao Login (if selected) Republic of Korea

6.2 Advertising / Marketing

6.3 Legal Requests for Information

Talky operates under the laws of the Republic of Korea and is legally obligated to cooperate with valid legal requests.

Information Talky Can Provide (Stored in Firestore or Firebase System Logs)

Information Technically Impossible to Provide

Information Talky Never Processes

Legal Request Response Policy: Upon receiving valid court warrants or lawful requests under Korean Communications Privacy Act, Talky responds minimally within the scope of "Information Talky Can Provide" above. Regular chat messages are stored on the server and may be provided in response to legal requests, but Secret Chats are end-to-end encrypted and message content cannot be disclosed for any legal request. For truly confidential conversations, please use Secret Chat. All legal requests should be sent to bryan910508@gmail.com.

7. IP Address and System Log Processing

The Talky app does not directly collect, store, or analyze IP addresses. However, our infrastructure provider (Google Cloud Firebase) temporarily handles IPs for security monitoring and system stability:

7.1 Firebase Automatic System Logs

Log Type Includes Retention
Firebase Authentication Sign-up IP, last login IP 30 days
Cloud Functions API call IP, function name 30 days
Firestore Used temporarily during connection (no long-term storage) Real-time

7.2 Operator Access to IPs

7.3 GDPR Data Download and IP

When you request "Download My Data," you receive Talky-stored information as JSON. IP addresses are NOT included in this download (Firebase system logs cannot be exported by the operator).

7.4 Rate Limiting (Spam Prevention)

To prevent spam/bots, IPs may be temporarily used (e.g., daily account creation limit per IP). Even in this case, IPs are auto-deleted after 24 hours and never permanently stored.

8. International Data Transfer

8.1 Server Locations

8.2 Russian Users (152-FZ Law)

Notice for Russian users:

8.3 EU Users (GDPR)

EU users have the rights set forth in Section 9 in accordance with GDPR.

9. Your Rights

9.1 Available In-App

9.2 Available via Email Request

Send requests to bryan910508@gmail.com. We respond within 3 business days, and no later than 30 days.

10. Children Under 14

11. Cookies and Tracking

12. Security Incident Response

  1. Operator initiates first response immediately upon discovery
  2. Notify affected users within 72 hours (in-app + email)
  3. Report to Korean Personal Information Protection Commission (if applicable)
  4. For EU user impact, report to relevant supervisory authority per GDPR

13. Policy Changes

14. Contact

EU users may contact their local data protection authority. Korean users may also report violations to the Personal Information Dispute Mediation Committee (1833-6972).

Talky © 2026 Yeong-Won Kim. All rights reserved.