CIPHER

Privacy Policy

Effective Date: September 11, 2026 · Version 2026-09-11

1. General Provisions

1.1. This Privacy Policy ("Policy") describes how VEXNODE LLC processes and protects personal data of users ("you", "User") of the CIPHER mobile application ("App").

1.2. By installing, registering in, or continuing to use the App, you acknowledge that you have read and understood this Policy. Where this Policy requires your explicit consent (see Section 2C), you will be asked to provide it affirmatively in-app before the corresponding processing begins.

1.3. Data Controller:

1.4. Scope. This Policy applies to all users globally. Users in the European Economic Area (EEA) and the United Kingdom are covered by the GDPR / UK GDPR rights described in Section 9.

2. Data We Collect

2A. Required Account Data:
  • Phone number — for account creation, authentication, and account recovery.
  • Email address — for service notifications and account recovery.
  • Username — for in-app identification.
  • Date of birth — to verify that you are 18 or older (see Section 11). Only your age is stored; the exact date is not retained after verification.
2B. Optional Identity Verification (KYC):
  • Photograph of a government-issued identity document.
  • Short video recording of the User's face following on-screen instructions ("liveness video").

Purpose. KYC is optional and is requested only (i) to confirm that a person is real and unique before features that move in-app value are unlocked (transfers, marketplace, raids), (ii) to deter duplicate and fraudulent accounts, and (iii) where verification is required by applicable law. It is not used for profiling, advertising, or scoring.

Where the documents are stored. Your identity document and liveness video are encrypted by the application itself with AES-256-GCM before being written to our own PostgreSQL database, hosted for us by Render (United States, see Section 5). Encryption keys are held by VEXNODE LLC and are not accessible to the hosting provider. The documents are never uploaded to, or previewed in, any third-party messaging or storage service.

Who reviews them. Review is performed by authorised VEXNODE LLC personnel in an internal, access-controlled review panel operated on our own infrastructure. The decrypted document is displayed only inside that panel for the duration of the review; every access is authenticated and written to an audit log. Our review notification channel (Telegram) receives only the fact that a submission exists — an identifier, country and date — and never the document itself.

2C. Biometric Data (Special Category — GDPR Article 9):
  • On-device biometrics (Face ID / Touch ID / fingerprint): used solely to unlock the CIPHER Vault on your device. This data is processed entirely within your device's secure enclave by the operating system; CIPHER does not receive, transmit, or store the biometric template itself.
  • KYC liveness video: contains facial imagery which, when processed for unique identification, qualifies as biometric data for the purposes of GDPR Article 9.

Legal basis: your explicit consent under GDPR Article 9(2)(a), obtained in-app before the KYC flow begins.

Withdrawal of consent. You can withdraw your KYC / biometric consent at any time. The primary withdrawal path is the in-app control (Profile → KYC → Withdraw consent), which purges KYC records and reverts your account to the unverified state without requiring account deletion. If that control is unavailable to you, you may also email ciph.official@gmail.com with the request. As a final fallback, full account deletion (Section 9A) also withdraws all consents. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

Retention: the identity document and liveness video exist only for as long as the review takes. The moment a decision (approval or rejection) is recorded, the document and video files are deleted permanently from our database. What we keep afterwards is strictly the minimum needed to prevent one person registering many accounts and to evidence the decision: a one-way SHA-256 hash of each file (from which the file cannot be reconstructed), its type and size, the decision, the rejection reason if any, and the relevant dates. A submission that has not yet been reviewed is retained until it is reviewed or until you withdraw consent or delete your account, whichever comes first. Withdrawing consent or deleting your account additionally erases the retained hashes and decision record (Section 9A).

2D. Automatically Collected Data:
  • Device identifier (non-advertising) and basic device characteristics (OS version, device model) — for security, abuse prevention, and technical support.
  • Approximate country — derived from your IP address or, where granted, from the Location permission.
  • Push notification token — to deliver push notifications if you have opted in.
  • App activity data — features you use, screens you view, session duration, and technical errors; used in aggregate to improve the App.
  • Precise location (GPS): used only when you grant the Location permission, exclusively to render the in-app World Map feature. Location data is processed by Google Maps SDK on your device and is not retained by CIPHER beyond the current session unless explicitly stated in-app.
2E. End-to-End Encrypted Chat Data:

Messages sent through the CIPHER encrypted chat feature are encrypted on the sender's device using the Curve25519/XSalsa20-Poly1305 construction and can only be decrypted by the intended recipient(s). VEXNODE LLC cannot access, read, or recover the plaintext content of these messages. We store only the opaque ciphertext, routing metadata (sender, recipient, timestamp), and message-level nonces required to deliver the message.

2F. Device Permissions We Request:

The App requests the following Android / iOS runtime permissions. Each is requested only for the purpose described below, and each can be granted or denied independently in your device settings. Denying a non-essential permission simply disables the corresponding feature.

  • Camera — to scan QR codes (for invites and in-app payments) and to capture the identity-document photograph and liveness video during optional KYC.
  • Microphone (RECORD_AUDIO) — to record the audio track of the KYC liveness video.
  • Audio settings (MODIFY_AUDIO_SETTINGS) — routine Android permission used by the audio-playback library to route sound to the correct output during in-app audio cues. No audio is recorded under this permission.
  • Location (ACCESS_COARSE_LOCATION / ACCESS_FINE_LOCATION) — optional; used exclusively to render the in-app World Map feature. See Section 2D for retention.
  • Biometric (USE_BIOMETRIC / USE_FINGERPRINT) — to unlock the on-device CIPHER Vault via your device's secure enclave. No biometric template ever leaves the device. See Section 2C.
  • Notifications (POST_NOTIFICATIONS) — to deliver service notifications (session events, reward reminders) if you have opted in. Tokens are stored as described in Section 2D.
  • Vibration (VIBRATE) — short in-app haptic feedback. No data is collected.

The App does not request access to your contacts, SMS, call log, external storage, or background location.

3. Purpose and Legal Basis of Processing

We process personal data only where we have a lawful basis to do so. For users covered by the GDPR / UK GDPR, the applicable legal basis is stated below next to each purpose.

4. Data Storage, Protection, and Retention

4.1. Personal data is stored on servers operated by reputable cloud providers (see Section 5), protected by TLS in transit and by provider-managed encryption at rest.

4.2. Access to personal data is limited to authorized personnel who are bound by confidentiality obligations.

4.3. KYC documents and liveness video are stored separately from account data and encrypted by the application with AES-256-GCM under keys held by VEXNODE LLC. They are accessible only through an authenticated internal review panel, are never transmitted to a third-party service, and are deleted as soon as the verification decision is recorded (Section 2C).

4.4. Retention periods:

5. Service Providers (Processors) and International Transfers

5.1. We do not sell your personal data and we do not share it with third parties for their own marketing purposes.

5.2. We engage the following categories of service providers (data processors) who process personal data only on our documented instructions:

Infrastructure and Operations:
  • Render (United States) — application server hosting and the managed PostgreSQL database in which all account data and (until the verification decision) the application-encrypted KYC files are stored. Render hosts the database; it does not hold our application-level encryption keys.
  • Telegram (Telegram FZ-LLC) — internal operational notifications to our review team. It receives only a submission identifier, country and date. No identity documents, photographs or liveness videos are sent to Telegram.
  • Expo (Expo Application Services) (United States) — over-the-air updates and push notification delivery.
  • Google Maps Platform — map tiles and geocoding for the World Map feature.

The current release of the App does not integrate any third-party advertising network. If and when we introduce in-app advertising in a future release, this Privacy Policy will be updated to name the advertising SDK(s) used, the data they collect, and the legal basis for that processing, and you will be prompted to review the updated Policy in-app before ads appear.

5.3. International transfers. Some of the providers listed above are located in the United States. When we transfer personal data of EEA / UK users outside the EEA / UK, we rely on the European Commission's Standard Contractual Clauses (SCCs) or on adequacy decisions where available, together with supplementary technical and organizational measures (TLS in transit, encryption at rest, access controls, logging).

5.4. Public authorities. We may disclose personal data to competent public authorities where we are legally required to do so, provided that the request is lawful, specific, and proportionate.

6. In-App Virtual Currency ($CIPH)

6.1. $CIPH is an in-app virtual currency used exclusively within the App. $CIPH is not a cryptocurrency, is not a token issued on any blockchain, is not traded on any exchange, and is not transferable to wallets or services outside the App. $CIPH has no real-world monetary value and cannot be exchanged for cash, fiat currency, goods, or services outside the App.

6.2. Your $CIPH balance is an internal ledger entry maintained on our servers. No personal data beyond your account identifier is required to operate this ledger.

6.3. For full terms governing $CIPH, please see the Terms of Service.

7. Encrypted Features

7.1. End-to-End Encrypted Chat. Messages sent through the CIPHER chat feature are encrypted on the sender's device using Curve25519 key agreement and XSalsa20-Poly1305 authenticated encryption. Only the intended recipient(s) can decrypt the plaintext. We store ciphertext and routing metadata only and cannot read your messages.

7.2. CIPHER Vault. Notes stored in the CIPHER Vault are encrypted locally on your device using AES-256 with a key derived from a password you choose. The encrypted blob is synchronized to our servers so you can restore it on a new device; we cannot decrypt the contents.

7.3. If you lose your chat keys or your Vault password, we are unable to recover your data. Please use the in-app backup features where offered.

8. Raids and Social Features

8.1. The App may include "Raid" and similar social features where Users can interact with other inactive accounts.

8.2. In these features, other Users only see:

8.3. Your real identity, phone number, email, and KYC data are never shown to other Users.

8.4. Clan membership may provide partial protection from raids. Prolonged inactivity may reduce this protection; the exact mechanics are described in-app.

9. Your Rights

Subject to applicable law, you have the following rights regarding your personal data:

To exercise any of these rights, contact: ciph.official@gmail.com. We respond within 30 days; where a request is complex or we receive many requests, we may extend this by a further 60 days and will inform you of the extension.

9A. Account Deletion Process

9A.0. Requesting deletion of KYC data only. You do not have to delete your account to have your identity data erased. Email ciph.official@gmail.com from the address registered on your account, or use the in-app control (Profile → KYC → Withdraw consent), stating your in-app username. We verify that the request comes from the account holder, erase any pending document and the retained KYC decision record, and revert the account to the unverified state. We confirm completion by email within 30 days (extendable by up to 60 further days for complex requests, in which case we tell you why). No fee is charged. If you are unsatisfied with the outcome, you may lodge a complaint with your local supervisory authority (Section 9.2).

9A.1. You can request full account deletion at any time. There are two ways:

9A.2. 30-Day recovery window. Upon your request, your account is frozen for 30 days. During this window:

9A.3. After 30 days, the following occurs automatically:

9A.4. Some information may persist in backups for up to 90 days before backup rotation removes it, and in legally required records (e.g., tax records) for the period required by law. These residual copies are not used for any operational purpose.

10. Cookies and Analytics

10.1. The App does not use browser cookies (it is a native mobile application).

10.2. We collect aggregate, feature-level telemetry (e.g., how often a feature is used, session length, error counts) to improve the App. This telemetry is linked to a stable in-app account identifier but is not combined with advertising identifiers or sold.

11. Age Restrictions

11.1. The App is intended exclusively for persons aged 18 and older.

11.2. We do not knowingly collect personal data from persons under 18. If we become aware that a user is under 18, we will deactivate the account and delete the associated personal data in accordance with Section 9A.

11.3. If you are a parent or guardian and believe your child has created an account, please contact ciph.official@gmail.com.

12. Policy Changes

12.1. We may update this Policy from time to time. The current version is identified by the Effective Date and Version string at the top of this page.

12.2. When changes are material, we will prompt you to review and re-accept the updated Policy inside the App before continuing to use affected features.

12.3. Continued use of the App after minor, non-material changes constitutes acceptance of the updated Policy.

13. Contact

For any privacy-related question or to exercise any right described in this Policy: