← Back to home Legal

Privacy Policy

This policy describes the personal data Qwing processes, the lawful basis for it, how long it is kept, who it is shared with, and the rights you have over it. It is written to match what the software actually does. Qwing is an end-to-end encrypted messenger: what you write, send and say in calls leaves your device only in a form your recipient alone can decrypt. The end-to-end layer uses hybrid encryption, which combines classical and post-quantum algorithms; the connection to our server (TLS) and the outer layer of calls use standard, non-post-quantum cryptography.

1. Data controller

Qwing is developed and operated by CODEARMORY, MB, a private limited liability company registered in the Republic of Lithuania (European Union), legal entity code 306047013, registered address Šumsko g. 166, LT-02196 Vilnius, Lithuania. For the purposes of the EU General Data Protection Regulation (GDPR), CODEARMORY, MB is the data controller for the limited personal data described in this policy.

You can reach the controller about any privacy matter, including data-subject requests, at privacy@qwing.app.

2. The short version

3. What is end-to-end encrypted (and never visible to us)

Everything you send to a contact is encrypted on your device before it leaves, and is decryptable only on your recipient's device: text, photos, videos, voice notes, files, replies, reactions, read receipts, profile names and avatars (except a profile photo set with an earlier app version — see §4.1), and any wallet address you choose to share. Voice and video calls are encrypted end-to-end and routed peer-to-peer where the network allows. Link previews are built on your own device, only for links you send: your device fetches the page from the linked site, which sees your IP address. The cryptographic primitives are:

The following are technically impossible for us to access, because we never hold the keys: message, call and file content, and the contents of files in your encrypted Vault, which are encrypted on your device before they are uploaded. Who you talk to is not hidden from us (see §2).

4. What the server processes

To deliver messages and route calls, the server processes a small amount of data. To be truthful about it: the server sees opaque ciphertext envelopes, delivery metadata (for much of the traffic, who sends to whom — see §2), push tokens, and the IP address of your device when it connects.

4.1 Account / identity

4.2 Message routing

4.3 Media and Vault

Attachments are encrypted on your device with a per-file key carried inside the encrypted message. The server stores the ciphertext so the recipient can fetch it; it cannot decrypt it. Files you put in your Vault are encrypted on your device (AES-256-GCM, with a key the server never receives) and stored on the server as ciphertext until you delete them. The file name is encrypted too; the server sees each Vault file's size, a hash of its ciphertext, when it was uploaded, and how many files you keep.

4.4 Push tokens

Your most recent Apple (APNs) or Google (FCM) push token, used to wake your device for incoming messages and calls. The push payload contains no message content.

4.5 Connection metadata

When your device connects to the server, the server (and our reverse proxy) necessarily observes your IP address for the duration of the connection and in short-lived, rotating access logs used for abuse and denial-of-service protection. There is no per-user IP history table.

4.6 Calls

To set up a call, your app sends encrypted, signed call messages through our server under your login, so the server sees who calls whom and when, but not the call type or the connection details. A call offer for a phone that is not connected is kept for about 30 seconds, while it rings. Calls go directly between the two phones where the network allows, and each phone then sees the other's IP address. If the network prevents a direct connection, the encrypted audio and video pass through our relay (TURN) server, which sees both IP addresses but cannot decrypt the call.

4.7 Moving to a new phone

When you move your account to a new phone, the old phone shows your account — identity keys, recovery phrase, contacts, groups, message history, app settings and wallet keys — as a series of QR codes that the new phone scans with its camera. It is encrypted to a key the new phone created (X25519 + ML-KEM-1024, then XChaCha20-Poly1305), and the old phone encrypts it only after you type the 12-digit code the new phone shows. This data moves directly between your two phones; none of it is uploaded to our server. Afterwards the new phone signs in and uploads its own new prekeys; the server then stops serving the old phone and deletes its push tokens, and your contacts' apps set up new sessions with the new phone.

4.8 Incoming calls on your phone

Qwing rings through your phone's own calling system (CallKit on iPhone, the Android telephony framework). By default the incoming-call screen shows the caller's name from the contacts on your phone, and Qwing calls appear in your phone's call history (on Android, from Android 9); on iPhone, iCloud may sync that history to your other Apple devices, under Apple's terms. The name comes from your own device, never from our server or the push message. If you turn on Private calls (Settings → Privacy on iPhone, Settings → Security on Android), the call screen shows “Encrypted call” instead of the name and Qwing calls are kept out of your phone's call history.

4.9 What the server never stores

5. Lawful basis for processing

We process the limited data above on the following GDPR Article 6 bases:

6. Retention periods

We keep personal data only as long as it is needed for the purpose it was collected, then delete it.

DataRetention
Message ciphertext (server queue)Marked delivered when your device acknowledges it and deleted about 5 minutes later (for a message from a version before 2.0, sooner if a self-destruct timer is set). A message that is never delivered is deleted 30 days after it was sent.
Account / identity (UUID, public keys and prekeys, encrypted profile)Until you delete your account.
Block list and reportsA block until you unblock or either account is deleted; a report until either account is deleted.
Legacy unencrypted profile photo (§4.1)Until your app deletes it when you change or remove your photo or switch to an emoji, or you delete your account.
Bot listing (name, description, @username, picture)Until the bot is revoked. Revoking deletes the picture immediately.
Push token (APNs / FCM)Until you log out, delete your account, or the token becomes invalid.
Encrypted attachments on the serverDeleted 7 days after upload, whether or not the recipient fetched them.
Encrypted Vault files on the serverUntil you delete them or your account.
Server database backupsEncrypted backups of the database are taken every 6 hours and kept for 30 days. They contain the records that describe attachments and Vault files (size, time, encrypted metadata), not the files themselves. Data deleted from the database, including a deleted account, stays in these backups until they expire.
Connection / access logs (incl. IP)Short-lived, rotating; retained only briefly for abuse and DoS protection, then automatically rolled off.
On-device data (messages, keys, cached files)Stored on your device, encrypted at rest, under your control; removed by deleting your account, the in-app wipe, or uninstalling.

7. Third parties & recipients

Qwing minimises third-party processing. The third parties that may receive data are:

We do not sell personal data, and we do not share it with advertising networks or data brokers.

8. Wallet & blockchain networks

Qwing includes a self-custodial wallet. Your wallet keys are derived from your recovery phrase and stored only on your device. When you send a transaction, the app signs and broadcasts a real transaction to public blockchain networks through third-party RPC providers. At broadcast time those providers can see your wallet address and IP address, and the transaction is recorded permanently and publicly on-chain. Transactions are irreversible. Full detail is in the Wallet Disclosure.

9. Your rights

Under the GDPR you have the right to:

To exercise any right, contact privacy@qwing.app. You also have the right to lodge a complaint with your local supervisory authority; in Lithuania that is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija).

10. Account deletion

You can delete your account at any time in the app (Settings → Delete account). This calls the server's account-deletion endpoint, which removes your account row, your public keys and prekeys, queued envelopes addressed to you, your Vault files and uploaded attachments, your encrypted contact backup, your block list and reports, delivery tokens and push tokens, and wipes the app's local data on the device. Full detail and timeline are on the Account Deletion page.

11. Data breaches

End-to-end encryption means a server compromise exposes ciphertext, not your messages. Nonetheless, if a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where the law requires it, within 72 hours of becoming aware of it, and we will inform affected users where the breach is likely to result in a high risk.

12. Children

Qwing is not directed at children. You must be at least 17 years old to use it (see the Terms of Service). We do not knowingly process data from anyone under that age; if you believe a minor has created an account, contact us and we will delete it.

13. Jurisdiction & transfers

Qwing is operated from the European Union and its server infrastructure is hosted in the EU. Lithuanian and EU law apply to this policy. The push providers (Apple, Google) and any blockchain RPC providers you choose to use may process data outside the EU under their own terms and safeguards.

14. Changes

Material changes to this policy are published on this page. The “Last updated” date at the top reflects the most recent change.

15. Contact

For any privacy question or data-subject request, contact the data controller at privacy@qwing.app.