Privacy Policy

Last updated: July 8, 2026  ·  Effective: July 8, 2026  ·  Version 1.8
CryptoVoice ("we", "our", or "us") is committed to protecting your privacy. This policy explains every category of data we collect, why we collect it, who we share it with, and your rights over it.

1. Information We Collect

Account Information

When you register, we collect your email address, username, and display name. Authentication is handled by Supabase Auth using email one-time passwords (OTP) — we never store plain-text passwords. A phone number is optional, not mandatory — it may be added for mobile OTP login, but you can use CryptoVoice fully without ever providing one.

Contacts (Optional Feature)

Contacts sync is completely optional and may be used only if you grant contacts permission on your device. If you choose to sync, your device address book is used solely to power contact discovery and friend matching — showing you which of your contacts are already on CryptoVoice and letting you invite the rest. To minimize what we store, normalized phone numbers and email addresses from your contacts are converted to one-way cryptographic hashes before being sent to our servers; raw contact names, phone numbers, and email addresses are not retained in our database. For contacts confirmed to already be CryptoVoice users, only that user's own public profile information (username, display name, reputation score, KYC badge) is cached. CryptoVoice does not collect device call logs, does not read your SMS, and does not sell contact data to anyone. Full phone numbers of your contacts are never shown publicly to other users. You can delete your synced contacts cache from CryptoVoice at any time from the Contacts screen in the app; deleting synced contacts does not delete or modify anything on your phone — your device's contact list is never touched.

Identity & KYC Data

KYC verification is optional and required only for the Verified Expert path. When you complete KYC we collect your full legal name, government-issued ID type and number, country of residence, a selfie photograph, and proof-of-address document. Community Expert applicants do not submit KYC documents and are not required to complete identity verification.

Profile & Reputation Data

Profile photo (optional), bio, specialisations, social media handles, verified wallet address (public address only — never private keys), reputation score, expert certifications, and tier status.

Community Activity

Concerns raised, votes cast, project chat messages, community analytics interactions, and abuse reports submitted (including reported message text, reason selected, and user IDs of both the reporting and reported user).

Groups

Messages sent in public and private groups, image attachments, emoji reactions, group membership data, and group admin roles. Public group messages are visible to all current members of that group. Private group messages are restricted to members only.

Direct Messages

Content of direct messages (text and image attachments) exchanged with other users. DMs are stored server-side to power the messaging feature. We do not read DM content except when required by a valid abuse report review or legal obligation. Voice call audio is not recorded or stored — only call timestamps and duration (metadata) are retained.

File Uploads & Attachments

Images and files attached to direct messages, group messages, and status updates are stored in Supabase Storage with per-file access controls. DM and group attachments are private to conversation participants. KYC documents are accessible only by admin reviewers. Status images are visible to other users. Profile photos and project/group icons are publicly visible.

Push Notification Tokens

When you grant notification permission on your device, we register your Expo push notification device token. This token is used solely to deliver in-app alerts (new messages, concern updates, risk level changes, voting notifications). Tokens are immediately revoked from our servers when you log out or revoke notification permissions on your device.

Payment Metadata

All CryptoVoice payments — including the Verified Expert subscription, project verification tiers, promotional placements, and analytics subscriptions — are processed exclusively through Apple App Store or Google Play Store via RevenueCat. RevenueCat receives anonymised purchase receipts from those stores; we receive subscription entitlement status only. We never receive or store raw card or banking details.

Device & Technical Data

Device type, operating system version, app version, and anonymised IP address — used solely for security, fraud prevention, and app functionality across devices.

Session Data

Login timestamps and Supabase JWT session tokens for account security and authenticated API access.

2. Data at a Glance

CategoryVisibilityPurpose
Account & AuthPrivateIdentity, login, security
KYC DocumentsAdmin onlyExpert verification
Profile & ReputationVisible to othersCommunity trust features
Concerns & VotesVisible to othersCommunity risk scoring
Group MessagesGroup membersCommunity discussion
Direct MessagesPrivate1-to-1 communication
File UploadsVaries (see above)In-app media sharing
Push TokensPrivatePush notifications only
Synced ContactsPrivate, optional, hashedContact discovery & friend matching
Payment MetadataPrivateActivate paid features
Device & TechnicalPrivateSecurity & debugging

3. How We Use Your Information

4. Data Storage and Security

Your data is stored on Supabase PostgreSQL infrastructure (encrypted at rest and in transit via TLS). Additional security measures include:

5. Data Sharing

We do not sell your personal data. We share data only with:

6. Public vs. Private Information

The following is publicly visible to all logged-in users:

7. Data Retention

8. Your Rights

9. Cookies & Analytics

The CryptoVoice website uses essential cookies for session management and authentication. We use Google Analytics (GA4, tag G-LKW3L1EP2Y) for anonymised website traffic analysis. No third-party advertising cookies are set. You can control cookie settings via your browser preferences.

10. Children's Privacy (COPPA)

CryptoVoice is not intended for users under 18 years of age. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal data, contact privacy@cryptovoice.app immediately and we will delete that data promptly.

11. Changes to This Policy

We may update this policy from time to time. We will notify you of significant changes via in-app notification and by updating the "Last updated" date above. Continued use of the platform after changes are posted constitutes acceptance of the updated policy.

12. Contact

For privacy-related questions, data requests, or to exercise your rights:
privacy@cryptovoice.app
Or visit our Contact page.