EION — месенджер. Ця політика описує, які дані ми отримуємо, навіщо, кому передаємо і як ви можете їх видалити. Ми намагались писати простою мовою і без обіцянок, яких не виконуємо.
Сервіс EION розробляє й підтримує приватна особа (незалежний розробник). Зв'язок: support@eion.network.
Якщо ви дозволите доступ до контактів, застосунок надсилає на сервер номери телефонів у нормалізованому вигляді, щоб перевірити, хто з ваших знайомих уже користується EION. Ми не зберігаємо вашу адресну книгу — номери використовуються лише для звірки під час запиту, а імена контактів на сервер не передаються взагалі.
Тільки якщо ви самі обрали «Надіслати місцезнаходження». Ми не збираємо координати у фоновому режимі й не відстежуємо переміщення.
На сайті працює Google Analytics — він збирає знеособлену статистику відвідувань (сторінки, приблизний регіон, тип пристрою) за допомогою файлів cookie. Ці дані не пов'язуються з вашим обліковим записом у застосунку. Вимкнути збір можна засобами браузера або офіційним доповненням Google. У самому застосунку EION аналітики немає.
Дзвінки шифруються наскрізно. Аудіо й відео передаються за протоколом WebRTC із обов'язковим шифруванням DTLS-SRTP. Ні ми, ні проміжні сервери не мають доступу до змісту розмови.
Текст особистих чатів — теж. Ключ створюється на вашому пристрої й ніколи його не залишає; на сервері зберігається лише шифротекст. Ми не можемо прочитати ці повідомлення й не можемо їх відновити — навіть на ваш власний запит, навіть на вимогу закону. Ключ не резервується: якщо ви перевстановите застосунок, недоставлені повідомлення, зашифровані для попереднього ключа, стануть недоступними. Це свідома ціна за те, що копії ключа не існує ніде, крім вашого пристрою.
Вкладення особистих чатів — теж. Фотографії, відео, голосові й документи шифруються на вашому пристрої перед вивантаженням, разом із підписами до них. У сховище потрапляє лише шифротекст: ні ми, ні хостинг сховища не бачимо вмісту навіть за посиланням. Кожен файл зашифрований для ключів усіх одержувачів — в особистому чаті це ви й співрозмовник, у групі всі учасники, — тож своє надіслане ви прочитаєте й на іншому пристрої.
Що видно серверу навіть у зашифрованих чатах. Імʼя файла, його розмір, тривалість голосового й форма звукової хвилі передаються відкрито — на них тримається доставка, показ у списку чатів і автоматичне прибирання файлів. Тобто ми не знаємо, що на фотографії, але знаємо, що ви надіслали файл із такою назвою й такого розміру. Хто з ким і коли листується, ми бачимо теж — це метадані, потрібні для роботи месенджера. Окремо про push-сповіщення: коли ви офлайн, пристрій будить Google (Firebase), і в цьому запиті ми передаємо нік відправника або назву групи — щоб сповіщення не було безликим. Тексту повідомлення там немає, але Google бачить, що вам пише саме ця людина й коли. Поки ви онлайн, пуш не надсилається взагалі.
Групи — теж. Текст, відповіді, закріплені повідомлення й вкладення в групах шифруються так само: кожне повідомлення зашифроване для всіх пристроїв усіх учасників, які є в групі на момент надсилання. Тому новий учасник бачить лише повідомлення, надіслані після його вступу, а вилучений не може прочитати нових. Якщо хтось із учасників користується версією застосунку без ключа шифрування або в групі понад 255 пристроїв, повідомлення в такій групі надсилаються відкрито. Наліпки не шифруються: це лише код наліпки з магазину.
Канали — навмисно ні. Канали публічні: підписатися може будь-хто, тож шифрування не приховало б вміст ні від кого, але зламало б пошук, прев'ю й сповіщення. Пости й коментарі каналів зберігаються у відкритому вигляді (файли — у приватному сховищі, за посиланнями з обмеженим строком дії). Технічно ми маємо до них доступ; ми не читаємо їх у буденній роботі, але не стверджуємо, що це неможливо.
Дві межі, про які варто знати. По-перше, публічні ключі роздає наш сервер, тож поки в застосунку немає кодів звірки, шифрування захищає від крадіжки бази даних, від інсайдера й від стороннього доступу — але формально не від нас самих. По-друге, ключ сталий: якщо він колись витече, з ним можна прочитати те, що сервер ще зберігає (до 7 днів для особистих чатів і до 30 — для груп).
Ми вважаємо чесність важливішою за маркетинг і тому пишемо, де саме шифрування вже є, а де ще ні. Якщо вам потрібна гарантована таємниця листування навіть від постачальника сервісу, дочекайтеся кодів звірки або використовуйте месенджер, який їх уже має.
Ми користуємось послугами постачальників інфраструктури. Вони обробляють дані лише для роботи сервісу.
| Постачальник | Для чого | Що отримує |
|---|---|---|
| Supabase | База даних і сховище файлів | Обліковий запис, повідомлення, файли |
| Render | Хостинг сервера | Мережевий трафік, службові журнали |
| Google Firebase (FCM) | Push-сповіщення | Токен пристрою; нік відправника або назву групи; тип події (повідомлення, дзвінок). Текст повідомлення НЕ передається |
| Sentry (регіон ЄС) | Звіти про збої | Технічний опис помилки, модель пристрою й версія застосунку |
| Brevo | Службові листи (відновлення пароля) | Адреса пошти й текст листа |
| Groq | Вбудований AI-асистент і автопереклад | Ваші запити до асистента, а якщо ви ввімкнули автопереклад — текст повідомлень, які перекладаються (зокрема надісланих вам) |
| Google (Gemini) | Запасний постачальник AI, коли основний недоступний; пошук по довідці асистента | Те саме, що отримує Groq |
| Публічний вузол мережі Solana | Показ балансу токена й перекази | Публічну адресу вашого гаманця |
| YouTube | Перегляд трансляцій у каналах і відео з посилань YouTube | Стандартні дані відтворення відео |
| Google Analytics | Статистика відвідувань сайту (не застосунку) | Знеособлені дані відвідування |
Ми також можемо розкрити дані на законну вимогу компетентного органу — у межах, які вимагає закон.
Ви можете: отримати копію своїх даних, виправити їх, видалити акаунт, відкликати згоду на доступ до контактів чи місцезнаходження (у налаштуваннях системи), поскаржитись до наглядового органу з захисту даних.
У застосунку: Налаштування профілю → Копія моїх даних. Ми зберемо файл JSON — його можна прочитати самому або перенести в інший сервіс. В архів входять: профіль, журнал операцій з монетами й перекази токена, ваше листування в діалогах, ваші власні повідомлення в групах, ваші пости й коментарі в каналах, підписки й членства, куплені та створені набори наліпок, список заблокованих, журнал дзвінків і лічильники денних норм. Потрібен пароль акаунта: без нього копію не збере навіть той, хто заволодів вашим пристроєм.
Дві межі, про які чесніше сказати одразу. Перша: текст діалогів шифрується наскрізно, і ключ зберігається лише на вашому пристрої — тому відкритий текст у архів додає сам застосунок зі своєї локальної копії. Якщо повідомлення надійшло на інший ваш пристрій, у архіві воно залишиться зашифрованим і буде позначене encrypted: true; ми не можемо його прочитати ні для вас, ні на вимогу. Друга: файли не вкладаються в архів — замість них ідуть посилання, дійсні доки файл живий у сховищі. Повідомлення інших людей у групах і каналах в архів не входять: це їхні дані.
У застосунку: Налаштування профілю → Видалити акаунт. Разом з акаунтом видаляються ваш профіль і аватар, баланс монет, адреса гаманця, повідомлення в діалогах, підписки на канали й членства в групах, реакції, позначки прочитання, лічильники денних норм, коди підтвердження та всі сесії; пуш-сповіщення припиняються. Файли з ваших особистих переписок прибираються зі сховища одразу — крім тих, на які ще посилається чиясь інша переписка. Записи в журналі операцій з монетами й дані про перекази токена ми не видаляємо, а знеособлюємо: нік прибирається, лишаються лише суми — вони потрібні для обліку монет і щоб той самий переказ не зарахувався вдруге. Ваші повідомлення в групах, а також пости й коментарі в каналах залишаються видимими їх учасникам — як і в інших месенджерах. Блокування платформи (якщо воно було) зберігається: інакше видалення акаунта стало б способом його зняти. Дія незворотна. Токени на вашій адресі в блокчейні нам не належать і видаленням акаунта не зачіпаються — доступ до них дає лише резервна фраза. Якщо доступу до застосунку немає — напишіть на support@eion.network із адреси, вказаної в акаунті.
EION не призначений для осіб молодших за 13 років (у Європейському Союзі — молодших за 16, якщо законодавство країни не встановлює нижчий вік). Ми свідомо не збираємо дані таких осіб. Якщо ви вважаєте, що дитина створила акаунт, напишіть нам — ми його видалимо.
Доступ до бази даних відкритий лише нашому серверу; звернення до неї потребують токена сесії. Файли зберігаються у приватному сховищі й видаються за посиланнями з обмеженим строком дії. Паролі хешуються bcrypt. Дії з монетами — переказ, обмін на токен, зміна адреси гаманця, платна підписка — додатково вимагають пароль акаунта; він не зберігається на пристрої, тож загублений чи вкрадений телефон не дає витратити баланс. Ключ гаманця зберігається лише на пристрої й зашифрований окремим паролем гаманця. Попри це, жодна система не є абсолютно захищеною.
Ми можемо оновлювати цю політику. Дата вгорі показує чинну редакцію; про суттєві зміни повідомимо в застосунку.
EION is a messenger. This policy explains what data we receive, why, who we share it with, and how you can delete it. We have tried to write plainly and to avoid promises we do not keep.
EION is developed and operated by an individual (an independent developer). Contact: support@eion.network.
If you grant contacts permission, the app sends normalised phone numbers to the server to check which of your contacts already use EION. We do not store your address book — numbers are used only for that comparison, and contact names are never sent.
Only when you choose "Send location" yourself. We do not collect coordinates in the background and do not track movement.
The website uses Google Analytics, which collects de-identified visit statistics (pages, approximate region, device type) using cookies. This data is not linked to your app account. You can opt out through your browser settings or the official Google add-on. The EION app itself contains no analytics.
Calls are end-to-end encrypted. Audio and video use WebRTC with mandatory DTLS-SRTP encryption. Neither we nor any relay server can access the content of a call.
The text of direct chats is too. The key is created on your device and never leaves it; the server stores only ciphertext. We cannot read those messages and cannot restore them — not even at your own request, and not on a legal demand. The key is not backed up: if you reinstall the app, undelivered messages encrypted for the previous key become unreadable. That is the deliberate price of no copy of the key existing anywhere but your device.
So are attachments in direct chats. Photos, videos, voice messages and documents are encrypted on your device before upload, together with their captions. Only ciphertext reaches the storage: neither we nor the storage provider can see the contents, even with the link. Every file is encrypted for the keys of all its recipients — in a direct chat that is you and your correspondent, in a group every member — so you can still open what you sent from another device.
What the server sees even in encrypted chats. The file name, its size, the length of a voice message and its waveform travel in the clear — delivery, the chat list preview and automatic file cleanup rely on them. So we do not know what is in a photo, but we do know that you sent a file with that name and that size. We also see who talks to whom and when: that is the metadata a messenger needs to work. A separate note on push notifications: when you are offline, your device is woken up by Google (Firebase), and that request carries the sender's nickname or the group name — so that the notification is not anonymous. The message text is not included, but Google does see that this particular person is writing to you, and when. While you are online, no push is sent at all.
So are groups. Text, replies, pinned messages and attachments in groups are encrypted the same way: each message is encrypted for every device of every member in the group at the moment it is sent. So a new member sees only messages sent after they joined, and a removed member cannot read new ones. If any member uses an app version without an encryption key, or a group has more than 255 devices, messages in that group are sent in the clear. Stickers are not encrypted: they are just a sticker code from the shop.
Channels, deliberately, are not. Channels are public: anyone can subscribe, so encryption would hide the content from no one while breaking search, previews and notifications. Channel posts and comments are stored in the clear (files in private storage, served via time-limited links). Technically we can access them; we do not read them in ordinary operation, but we do not claim it is impossible.
Two limits worth knowing. First, our server distributes the public keys, so until the app has verification codes, the encryption protects against database theft, an insider and outside access — but formally not against us. Second, the key is static: if it ever leaks, it can decrypt whatever the server still holds (up to 7 days for direct chats and up to 30 for groups).
We consider honesty more important than marketing, so we state exactly where encryption already exists and where it does not. If you need guaranteed confidentiality even from the service provider, wait for verification codes or use a messenger that already has them.
| Provider | Purpose | What it receives |
|---|---|---|
| Supabase | Database and file storage | Account, messages, files |
| Render | Server hosting | Network traffic, service logs |
| Google Firebase (FCM) | Push notifications | Device token; sender's nickname or group name; event type (message, call). Message text is NOT transmitted |
| Sentry (EU region) | Crash reports | Technical error description, device model, app version |
| Brevo | Service emails (password recovery) | Email address and message text |
| Groq | Built-in AI assistant and auto-translation | Your requests to the assistant and, if you enabled auto-translation, the text of the messages being translated (including those sent to you) |
| Google (Gemini) | Fallback AI provider when the main one is unavailable; search across the assistant's knowledge base | The same as Groq receives |
| A public Solana network node | Showing the token balance and making transfers | The public address of your wallet |
| YouTube | Watching streams in channels and videos from YouTube links | Standard video playback data |
| Google Analytics | Visit statistics for the website (not the app) | De-identified visit data |
We may also disclose data upon a lawful request from a competent authority, to the extent required by law.
You may obtain a copy of your data, correct it, delete your account, withdraw consent for contacts or location access (in system settings), and lodge a complaint with a data protection authority.
In the app: Profile settings → A copy of my data. We build a JSON file you can read yourself or move to another service. It contains your profile, the coin transaction log and token transfers, your direct conversations, your own group messages, your channel posts and comments, subscriptions and memberships, sticker packs you bought or created, your block list, call history and daily quota counters. Your account password is required: without it nobody can export your data, not even someone holding your unlocked device.
Two limits worth stating plainly. First, direct message text is end-to-end encrypted and the key lives only on your device, so the plaintext is added to the archive by the app itself, from its local copy. A message that arrived on a different device of yours stays encrypted in the archive and is marked encrypted: true; we cannot read it for you, nor on anyone’s demand. Second, files are not embedded — the archive holds links that work while the file remains in storage. Messages other people wrote in groups and channels are not included: they are their data.
In the app: Profile settings → Delete account. This removes your profile and avatar, coin balance, wallet address, direct messages, channel subscriptions and group memberships, reactions, read markers, daily allowance counters, verification codes and all sessions, and stops push notifications. Files from your direct conversations are removed from storage right away — except any still referenced by someone else's conversation. Entries in the coin ledger and records of token transfers are not deleted but anonymised: the nickname is stripped and only the amounts remain — they are needed for coin accounting and to keep the same transfer from being credited twice. Your messages in groups, along with channel posts and comments, remain visible to their participants — as in other messengers. A platform ban, if there was one, is kept: otherwise deleting an account would be a way to lift it. The action is irreversible. Tokens at your blockchain address do not belong to us and are not affected by deleting the account — only the recovery phrase gives access to them. If you cannot access the app, write to support@eion.network from the address on the account.
EION is not intended for people under 13 (under 16 in the European Union, unless national law sets a lower age). We do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
Database access is limited to our server and requires a session token. Files are kept in private storage and served via time-limited links. Passwords are hashed with bcrypt. Actions that move coins — a transfer, a conversion into tokens, a change of wallet address, a paid subscription — additionally require the account password; it is never stored on the device, so a lost or stolen phone cannot spend the balance. The wallet key stays on the device and is encrypted with a separate wallet password. Even so, no system is perfectly secure.
We may update this policy. The date above shows the current version; we will announce material changes in the app.