Privacy Policy
Last updated: 2026-09-22
Diyo connects people through QR codes. You do not create an account and you never give us your name, phone number or e-mail address. This page explains exactly what the app and our server store, why, and for how long.
What we do NOT collect
- No name, phone number, e-mail address or contacts.
- No advertising and no third-party analytics or tracking SDKs in the app.
- No background location. Your location is never stored (see "Location" below).
What the server stores
- Anonymous device identity: when you install Diyo, our server creates a random identifier for your phone. The app keeps it, together with a secret and a signing key, in Android Keystore. On the server we keep only a hash of the secret, a hash of your PIN, a recovery identifier and the time of your last sign-in.
- Messages: the content you send in a line (text, form answers, star ratings, references to photos or videos), the time, and the IP address it was sent from. The IP address is kept for security and is never shown to other people. Messages are not end-to-end encrypted.
- QR codes you create: name, type, duration, form fields, keywords, and — only if you use these features — the map pin location you choose, the Nearby radius and the link-preview (showcase) title, description, welcome text, language and image.
- Photos and videos you upload: photos are converted to WebP and their metadata (including GPS/EXIF) is removed. Videos are shortened and compressed on your phone before upload. Files are served from our content server at an unguessable address.
- @profile (optional, Premium): the handle, display name, bio, profile type and photo you choose. A profile is public by your choice.
- Reports: the reported QR or profile, the reason, your optional details, and the IP address the report was sent from.
- Purchases: the Premium features on your device identity and the store reference.
What stays on your phone
- Your line history, folders and rules, form templates, saved/liked marks, appearance and language settings are stored only on your phone. Deleting the app deletes them.
How long we keep it
- A message stays on the server until it has been delivered. Once every participant of the line has received it and 24 hours have passed, it is deleted from the server. A message that has not been delivered yet is kept until it is delivered.
- When a line is closed, the line and its messages are deleted from the server.
- Expired or revoked QR codes are deleted, together with their map pins.
- Uploaded files that were never attached to a message or post are deleted after 24 hours.
- The server database is backed up once a day.
Location
- Location is used only when you choose to: to check your distance for a Nearby QR, to search "near me", or to pin your QR at your current position. It is sent for that single request and is not stored. When you pin a QR on the map, the pin coordinates are stored as part of that QR until you remove the pin or the QR ends.
Permissions
- Camera: to scan QR codes. Camera images are not uploaded.
- Location: only for the features above.
- Photos: chosen through the system photo picker; the app sees only the photos you pick.
- Storage (Android 9 and older only): to save downloaded media to your gallery.
Who we share it with
- We do not sell your data and we do not share it for advertising.
- Traffic reaches our server through Cloudflare. Purchases are processed by Google Play.
- We may disclose data where required by law.
Your controls
- Leave or mute any line at any time; leaving a one-to-one line closes it and deletes it from the server. Revoke any QR you created. Remove your map pin. Delete the app to remove all data on your phone.
Security
- All connections use HTTPS. Every request from the app is signed with a per-device key and protected against replay. Your recovery QR together with your PIN is the only way to move your identity to a new phone; keep it outside your phone.
Changes
- If this policy changes, the date at the top of this page changes.