Data & Security
Plain summary
Traffic is encrypted in transit. Media sits in private storage behind short-lived, per-user links. Call and live audio and video are relayed, not recorded.
We describe only the protections that are actually in place today. End-to-end encryption for conversations is in development — this page will say so plainly the day it ships, and not before.
What we protect, and how
| In transit | Traffic between the app and our servers is encrypted using industry-standard transport encryption. The web viewer for live sessions is served over HTTPS. |
|---|---|
| Media at rest | Photos, videos, voice notes, and profile photos are held in private object storage that is not publicly listable. Access is granted through short-lived, per-user authorized links rather than permanent public URLs. |
| Calls | Voice and video call media is relayed in real time through our call infrastructure and is not recorded or stored by us. Only call metadata is retained. |
| Live sessions | Live video is relayed to viewers in real time. We do not record streams; comments attached to a session are stored with that session. |
| Access control | Message, media, and order data is scoped to the accounts entitled to it, and media links are issued per user rather than shared. |
| Verification codes | One-time codes expire after five minutes. |
End-to-end encryption
End-to-end encryption for conversations is currently in development. Today, your messages and media are encrypted in transit and held on private, access-controlled infrastructure so that they can be delivered to people who are offline. Real-time call and live-stream media is relayed and never recorded.
Because that content is stored in a form our infrastructure can process in order to deliver it, it could in principle be reached by a compromise of our systems or by a lawful order compelling disclosure. We would rather tell you that than imply a protection that is not yet in place. When end-to-end encryption ships, we will update this page and the Privacy Policy, and tell you in the app.
No advertising, no third-party tracking
Cyca contains no advertising SDKs, no third-party analytics services, and no data-broker integrations. We do not combine your data with data from other companies' apps or websites, and we do not track you across them. Usage telemetry is first-party, tied to your account, and used to operate and improve the Services — described in the Privacy Policy.
Where your data lives
Your data resides on infrastructure that we operate, comprising our application servers, database, private media storage, and the relays that carry real-time call and live-stream media. We do not transfer your content to third-party analytics or advertising services. Push notification payloads pass through Apple's notification service in order to reach your device.
Because OCARRY LLC is established in the United States, data may be processed there. Where you are located in a jurisdiction that restricts international transfer, contact us for details of the safeguards we apply.
Your part
- Your phone number is your identity: anyone who can receive your verification codes can access your account. Never share a code — we will never ask you for one.
- Use a device passcode and keep your operating system updated; someone with your unlocked phone has your Cyca account.
- Review who can see your last-seen, profile photo, about text, and statuses in Privacy settings.
- Remember that anything you broadcast in a live session can be captured by any viewer, and that a live link can be opened by anyone who receives it.
- Review the device permissions you have granted — location, contacts, camera, microphone, photos — and revoke any you no longer want.
Reporting a vulnerability
If you believe you have found a security vulnerability in Cyca, report it privately to [email protected] with enough detail to reproduce it. Please give us a reasonable opportunity to remediate before public disclosure, and do not access, modify, or delete data belonging to other people while investigating. We will acknowledge your report and keep you informed.
If something goes wrong
If we become aware of a security incident affecting personal data, we will investigate, contain it, and notify affected users and the relevant supervisory authority where the applicable law requires — including within the timeframes set by laws such as the GDPR. Our notice will describe what happened, what data was involved, and what you should do.