When you register, we collect your email address, username, and display name. Authentication is handled by Supabase Auth using email one-time passwords (OTP) — we never store plain-text passwords. A phone number is optional, not mandatory — it may be added for mobile OTP login, but you can use CryptoVoice fully without ever providing one.
Contacts sync is completely optional and may be used only if you grant contacts permission on your device. If you choose to sync, your device address book is used solely to power contact discovery and friend matching — showing you which of your contacts are already on CryptoVoice and letting you invite the rest. To minimize what we store, normalized phone numbers and email addresses from your contacts are converted to one-way cryptographic hashes before being sent to our servers; raw contact names, phone numbers, and email addresses are not retained in our database. For contacts confirmed to already be CryptoVoice users, only that user's own public profile information (username, display name, reputation score, KYC badge) is cached. CryptoVoice does not collect device call logs, does not read your SMS, and does not sell contact data to anyone. Full phone numbers of your contacts are never shown publicly to other users. You can delete your synced contacts cache from CryptoVoice at any time from the Contacts screen in the app; deleting synced contacts does not delete or modify anything on your phone — your device's contact list is never touched.
KYC verification is optional and required only for the Verified Expert path. When you complete KYC we collect your full legal name, government-issued ID type and number, country of residence, a selfie photograph, and proof-of-address document. Community Expert applicants do not submit KYC documents and are not required to complete identity verification.
Profile photo (optional), bio, specialisations, social media handles, verified wallet address (public address only — never private keys), reputation score, expert certifications, and tier status.
Concerns raised, votes cast, project chat messages, community analytics interactions, and abuse reports submitted (including reported message text, reason selected, and user IDs of both the reporting and reported user).
Messages sent in public and private groups, image attachments, emoji reactions, group membership data, and group admin roles. Public group messages are visible to all current members of that group. Private group messages are restricted to members only.
Content of direct messages (text and image attachments) exchanged with other users. DMs are stored server-side to power the messaging feature. We do not read DM content except when required by a valid abuse report review or legal obligation. Voice call audio is not recorded or stored — only call timestamps and duration (metadata) are retained.
Images and files attached to direct messages, group messages, and status updates are stored in Supabase Storage with per-file access controls. DM and group attachments are private to conversation participants. KYC documents are accessible only by admin reviewers. Status images are visible to other users. Profile photos and project/group icons are publicly visible.
When you grant notification permission on your device, we register your Expo push notification device token. This token is used solely to deliver in-app alerts (new messages, concern updates, risk level changes, voting notifications). Tokens are immediately revoked from our servers when you log out or revoke notification permissions on your device.
All CryptoVoice payments — including the Verified Expert subscription, project verification tiers, promotional placements, and analytics subscriptions — are processed exclusively through Apple App Store or Google Play Store via RevenueCat. RevenueCat receives anonymised purchase receipts from those stores; we receive subscription entitlement status only. We never receive or store raw card or banking details.
Device type, operating system version, app version, and anonymised IP address — used solely for security, fraud prevention, and app functionality across devices.
Login timestamps and Supabase JWT session tokens for account security and authenticated API access.
| Category | Visibility | Purpose |
|---|---|---|
| Account & Auth | Private | Identity, login, security |
| KYC Documents | Admin only | Expert verification |
| Profile & Reputation | Visible to others | Community trust features |
| Concerns & Votes | Visible to others | Community risk scoring |
| Group Messages | Group members | Community discussion |
| Direct Messages | Private | 1-to-1 communication |
| File Uploads | Varies (see above) | In-app media sharing |
| Push Tokens | Private | Push notifications only |
| Synced Contacts | Private, optional, hashed | Contact discovery & friend matching |
| Payment Metadata | Private | Activate paid features |
| Device & Technical | Private | Security & debugging |
Your data is stored on Supabase PostgreSQL infrastructure (encrypted at rest and in transit via TLS). Additional security measures include:
We do not sell your personal data. We share data only with:
The following is publicly visible to all logged-in users:
The CryptoVoice website uses essential cookies for session management and authentication. We use Google Analytics (GA4, tag G-LKW3L1EP2Y) for anonymised website traffic analysis. No third-party advertising cookies are set. You can control cookie settings via your browser preferences.
CryptoVoice is not intended for users under 18 years of age. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal data, contact privacy@cryptovoice.app immediately and we will delete that data promptly.
We may update this policy from time to time. We will notify you of significant changes via in-app notification and by updating the "Last updated" date above. Continued use of the platform after changes are posted constitutes acceptance of the updated policy.
For privacy-related questions, data requests, or to exercise your rights:
privacy@cryptovoice.app
Or visit our Contact page.