TIHO / PRIVACY
Tiho Privacy Policy
Updated October 7, 2026
Data we process
To run Tiho, we store your account ID, nickname, optional display name and profile photo, device details, contacts, blocks, and contact requests. A phone number or email address is not required to register. Your nickname, name, and photo may be visible to other users through search and conversations.
Messages and history are transmitted to and stored on the server in encrypted form. The server processes information needed for delivery and synchronization, including conversation participants, identifiers, timestamps, and message status. The server does not receive message plaintext. Keys and some conversation data are stored on your device.
For call history, the server stores participants, direction, start, answer and end times, outcome, and read status. This metadata is not end-to-end encrypted; audio, video, and call keys are not recorded in history. Destroying your history removes your own call records from the live database.
Your IP address is processed when you connect to the website or API. The API log records the HTTP method, route pattern, status, duration, and request ID without message text, request bodies, or authentication secrets. The website uses no analytics or cookies.
Your device PIN is verified without sending the code itself: the server stores OPAQUE protocol records, the device protection mode (no PIN, a normal PIN, or normal and panic PINs), the error count, and the device lockout time. The log of PIN sign-in attempts, sessions and protection mode changes (device, time, outcome) is kept for 30 days; records of previous PINs are not kept after a change. Until a device moves to the new scheme, the previous account PIN verification record (salt and verifier) is kept. The server knows when a sign-in used the panic code: for an alert it stores the sender's account and device, the time and sign-in attempt number, the recipient list needed for routing and the encrypted packets for them, as well as your encrypted settings with recipients and their texts. Alert texts are not visible to the server; alert push notifications contain only generic text without the name or instruction. An encrypted packet is kept for the recipient until they delete it: after deletion the server erases the packet and, after 30 days, the deletion marker. If the recipient removed you from contacts before saving the alert, the packet is deleted after the one-hour delivery period. Information about the sender and alert time is kept while recipients still have records or deletion markers, or for one day if the recipient list was empty; the end time of the one-day limit on a new alert is kept until it passes.
Why we use and share data
We use data for registration, nickname search, contacts, message delivery, device synchronization, service protection, and notifications. Profile information is shown to other users within Tiho's features. We do not use data for advertising.
If mobile notifications are enabled, we store a device push token and send necessary information to Firebase Cloud Messaging and, on iOS, Apple Push Notification service. Message notifications contain no message text; a new-device notification includes the device name.
Technical diagnostics
The app automatically sends technical reports about unexpected errors whether or not you are signed in. A report contains only a fixed error code, the operation stage, platform, app version and build number, and a random diagnostic installation identifier. This identifier is stored separately from your account and does not grant access to it.
Reports may contain sanitized stack frames: only known app source files, method names, and line and column numbers. Raw stack text, local paths, and exception text are not transmitted. Reports do not contain messages, secure storage records, PINs, keys, authentication secrets, nicknames, device names, or account and registered-device identifiers. Repeated reports of the same code for an installation and build are suppressed. An automatic retention period for reports has not yet been set.
Retention and security
Account data and encrypted history remain on the server; a general retention period has not yet been set. Backup retention has not yet been set either, so data removed from the live database may remain in backups.
We use secure connections, store the server-side authentication secret as a hash, and encrypt messages on devices. End-to-end encryption does not hide nicknames, photos, or conversation metadata.
Your controls
You can change or remove your name and photo, delete individual messages, revoke a device, and remove local data when signing out. Signing out does not delete your account or server data. Deleting a message may not remove copies saved by another user outside Tiho. The account deletion request process is described on a separate page.
Questions and requests
To request information about your data, correction, or deletion, email us:
right.dev.solution@gmail.com