Privacy Policy

Maxfiylik siyosati · Effective 27 September 2026

Last updated: 27 September 2026 · Operator: Abbosjon Dev (“Zamin”, “we”) · Contact: info@zamin.app

1. Summary

  • Your messages, photos, videos, voice messages, files, shared locations, contact cards and stories are end-to-end encrypted. We cannot read them.
  • We collect only what the app needs to work. We do not sell your data, show ads, or track you across apps or websites.
  • You can delete your account and data in the app at any time.

2. Information we collect

DataWhy
Phone numberTo create your account and sign you in with an SMS code. Hidden from other users unless you allow it in Privacy settings.
First and last name, username, gender, date of birthYour profile. Name and username are visible to people who find you; gender and date of birth are not shown to others. Date of birth is used to confirm you are at least 13.
Profile photo, status (bio), group names, descriptions and photos (optional)Shown to other users according to your Privacy settings.
Contacts you add in Zamin, blocked users, chat and group membership, privacy and notification settingsTo run chats, groups, stories and blocking. We do not upload your phone's address book.
Encrypted messages, files and storiesStored only as ciphertext so they can be delivered to your devices. We see only technical metadata: sender, chat, time, size, and whether a message carries a photo, video, voice message or file.
Call recordsWho called whom, when, voice or video, and the result (answered, missed…), for your call history. The audio and video themselves are encrypted end to end and never recorded.
Online status and last seen timeShown to others only as allowed by your Privacy settings.
Device push tokens (Firebase Cloud Messaging, Apple VoIP)To deliver notifications and ring your phone for calls.
IP address and request logsSecurity, abuse prevention and troubleshooting. Logs never contain message content, tokens or request bodies.
Reports you send about other usersTo review abuse.

Permissions (camera, microphone, photos, location) are used only when you choose an action that needs them — for example taking a photo, recording a voice message, making a call or sharing your location. Your location is never collected in the background and is sent only inside an end-to-end encrypted message.

3. End-to-end encryption and security

  • Each phone creates its own keys (X25519 and Ed25519). Private keys never leave your phone's secure storage (iOS Keychain / Android Keystore).
  • Messages and files are encrypted on your phone with XChaCha20-Poly1305 and can be decrypted only on the recipients' phones. Calls are encrypted with WebRTC (DTLS-SRTP).
  • Photos are re-encoded on your phone before sending, which removes hidden metadata such as GPS location.
  • Your profile data is additionally encrypted in our database (AES-256-GCM); all traffic uses HTTPS/TLS.
  • Because only your phones hold the keys, messages cannot be restored on a new phone or after reinstalling the app.

4. Service providers

  • Google Firebase (Google LLC): verifies your phone number by SMS and delivers push notifications. Google processes your phone number and push tokens. Notification text for encrypted chats does not contain message content — only the sender's or group's name and a generic line such as “🔒 New message”.
  • Apple (Apple Push Notification service): delivers notifications and incoming-call alerts on iPhone.
  • DigitalOcean: hosts our servers in New York, United States, where your account data is stored.

These providers act on our instructions and may process data in the United States and other countries. We do not share your data with anyone else, except where required by law. Because content is end-to-end encrypted, we are technically unable to hand over the content of messages.

5. How long we keep data

  • Account and profile: until you delete your account.
  • Encrypted messages and files: until the sender deletes them, the chat is removed, or the account is deleted.
  • Stories: 24 hours. Uploads that are never sent: deleted after 1 day.
  • Sign-in sessions: expire after 30 days without use.
  • Server logs: web server logs 14 days, application logs up to 30 days.

6. Your choices and rights

  • Edit your profile and privacy settings in the app (Account → Privacy, Notifications).
  • Block or report users from their profile.
  • Delete your account: My profile → Delete account, then confirm with the SMS code. Your account, profile, uploaded files, stories and sessions are deleted immediately and permanently, and your phone-number sign-in is removed from Firebase.
  • For access, correction or any privacy request, email info@zamin.app. We reply within 30 days.

7. Children

Zamin is not intended for children under 13, and registration requires a date of birth showing age 13 or older. If you believe a child under 13 has an account, contact us and we will delete it.

8. Changes

We will post any changes on this page and update the date above. Significant changes will also be announced in the app.

Yangilangan sana: 2026-yil 27-sentyabr · Operator: Abbosjon Dev (“Zamin”) · Aloqa: info@zamin.app

1. Qisqacha

  • Xabarlaringiz, rasm, video, ovozli xabar, fayl, joylashuv, kontakt kartalari va hikoyalaringiz uchidan-uchiga shifrlanadi. Biz ularni o'qiy olmaymiz.
  • Faqat ilova ishlashi uchun zarur ma'lumotni yig'amiz. Ma'lumotingizni sotmaymiz, reklama ko'rsatmaymiz va sizni kuzatmaymiz.
  • Hisobingiz va ma'lumotlaringizni istalgan vaqt ilova ichida o'chirishingiz mumkin.

2. Qanday ma'lumot yig'iladi

  • Telefon raqami — ro'yxatdan o'tish va SMS kod bilan kirish uchun. Maxfiylik sozlamalarida ruxsat bermasangiz, boshqalarga ko'rinmaydi.
  • Ism, familiya, username, jins, tug'ilgan sana — profil uchun. Jins va tug'ilgan sana boshqalarga ko'rsatilmaydi; tug'ilgan sana 13 yoshdan kattaligingizni tasdiqlash uchun kerak.
  • Profil rasmi, holat, guruh nomi va rasmi (ixtiyoriy) — maxfiylik sozlamalaringizga ko'ra ko'rsatiladi.
  • Zamin'dagi kontaktlaringiz, bloklanganlar, chat va guruh a'zoligi, sozlamalar. Telefoningizdagi kontaktlar kitobi yuklanmaydi.
  • Shifrlangan xabar, fayl va hikoyalar — faqat shifrlangan holda saqlanadi. Biz faqat texnik ma'lumotni ko'ramiz: kim, qaysi chatga, qachon, hajmi va unda rasm/video/ovoz/fayl borligi.
  • Qo'ng'iroqlar tarixi — kim kimga, qachon, ovozli yoki video, natijasi. Ovoz va tasvirning o'zi shifrlanadi va hech qachon yozib olinmaydi.
  • Onlayn holat va oxirgi faollik — maxfiylik sozlamalaringizga ko'ra.
  • Push tokenlar (Firebase, Apple VoIP) — bildirishnoma va qo'ng'iroq signallari uchun.
  • IP manzil va so'rov loglari — xavfsizlik va nosozliklarni aniqlash uchun. Loglarda xabar mazmuni, tokenlar yoki so'rov tanasi yozilmaydi.

Kamera, mikrofon, galereya va joylashuvga ruxsat faqat siz tegishli amalni tanlaganingizda ishlatiladi. Joylashuv fonda yig'ilmaydi va faqat shifrlangan xabar ichida yuboriladi.

3. Shifrlash va xavfsizlik

Har bir telefon o'z kalitlarini yaratadi; maxfiy kalitlar telefonning himoyalangan xotirasidan chiqmaydi. Xabar va fayllar telefonda XChaCha20-Poly1305 bilan shifrlanadi, qo'ng'iroqlar WebRTC (DTLS-SRTP) bilan. Rasmlar yuborishdan oldin telefonda qayta kodlanadi va GPS kabi yashirin ma'lumotlardan tozalanadi. Profil ma'lumotlari bazada qo'shimcha AES-256-GCM bilan shifrlanadi, barcha aloqa HTTPS orqali. Kalitlar faqat telefonlarda bo'lgani uchun yangi telefonda eski xabarlarni tiklab bo'lmaydi.

4. Xizmat ko'rsatuvchilar

Google Firebase — SMS orqali raqamni tasdiqlash va push bildirishnomalar (raqamingiz va push tokenlar Google'da qayta ishlanadi; shifrlangan chat bildirishnomalarida xabar matni bo'lmaydi, faqat yuboruvchi yoki guruh nomi va “🔒 Yangi xabar”). Apple — iPhone'da bildirishnoma va qo'ng'iroq signallari. DigitalOcean — serverlarimiz Nyu-Yorkda (AQSh), hisob ma'lumotlari shu yerda saqlanadi. Qonun talab qilgan holatlardan tashqari ma'lumotlaringiz boshqa hech kimga berilmaydi; xabarlar mazmunini esa texnik jihatdan bera olmaymiz.

5. Saqlash muddatlari

  • Hisob va profil — hisobni o'chirguningizcha.
  • Shifrlangan xabar va fayllar — yuboruvchi o'chirguncha, chat yo'qolguncha yoki hisob o'chirilguncha.
  • Hikoyalar — 24 soat. Yuborilmagan yuklamalar — 1 kun.
  • Kirish sessiyalari — 30 kun ishlatilmasa tugaydi.
  • Server loglari — veb-server 14 kun, ilova loglari 30 kungacha.

6. Sizning huquqlaringiz

Profil va maxfiylik sozlamalarini ilovada o'zgartirasiz, foydalanuvchilarni bloklash yoki shikoyat qilishingiz mumkin. Hisobni o'chirish: Mening profilim → Hisobni o'chirish → SMS kod. Hisobingiz, profilingiz, fayllaringiz, hikoyalaringiz va sessiyalaringiz darhol va butunlay o'chiriladi, Firebase'dagi kirish ma'lumotingiz ham o'chiriladi. Boshqa so'rovlar uchun info@zamin.app ga yozing — 30 kun ichida javob beramiz.

7. Bolalar

Zamin 13 yoshgacha bo'lgan bolalar uchun mo'ljallanmagan. 13 yoshgacha bo'lgan bola hisob ochganini bilsangiz, bizga yozing — hisobni o'chiramiz.

8. O'zgarishlar

O'zgarishlar shu sahifada e'lon qilinadi va yuqoridagi sana yangilanadi. Muhim o'zgarishlar ilova ichida ham bildiriladi.