qiuqiu — Privacy Policy

Effective: 2026-05-30. Last updated: 2026-05-30.

This Privacy Policy describes how the qiuqiu instant-messaging service ("we", "us", "the App") collects, uses, shares, and protects information when you use our iOS app, Android app, or any other client we publish. By creating an account or using the App you agree to these terms.

1. What we DO NOT do

We open with the things we deliberately do not do, because they are the most common concerns:

2. Information we collect

CategoryWhat it includesWhy we need it
Account data Phone number (if registered via SMS), username, password (stored only as a bcrypt hash), nickname, optional avatar URL, optional short bio, and an optional email address if you bind one. Identify and authenticate your account. A bound email address is used only to send you a verification code when you bind it and to let you recover your password; we do not send marketing email.
Messages & calls The text, photos, voice clips, video, files, and stickers you send in chats; voice-call setup metadata (start time, end time, peer ID — call audio is peer-to-peer via WebRTC and not stored). Deliver your messages to the recipient and let you read your own chat history.
Community posts Public posts you author in the Community feed, including any photos, tags, and comments. Power the public feed surface.
Friend graph The user IDs you accepted as friends, optional remark, group-room memberships, blocked-users list. Show your friend list and route messages.
Device info Device identifier you generate inside the App, OS / app version, APNs / FCM push token. Deliver push notifications and let you manage signed-in sessions (Profile → Login Devices).
Sign-in context IP address, user-agent, timestamp of each successful sign-in. Detect and warn you about anomalous sign-ins (e.g. a new IP after a 24h gap).
Diagnostics Anonymous crash reports, only if you opt in via your OS settings (iOS → Settings → Privacy → Analytics; Android → Settings → Google → Usage & diagnostics). Find and fix crashes.

3. How we use the information

4. Sharing

We share information only as required to operate the service or as required by law:

We do not sell your personal information.

5. Where your data is stored

Production data is stored on servers in Singapore (Vultr SGP1). Backups are retained encrypted in the same region. We may move to additional regions in the future and will update this section when we do.

6. How long we keep it

7. Your rights

From inside the App you can at any time:

Users in jurisdictions with applicable data-protection laws — including the EU/UK (GDPR), California (CCPA/CPRA), China (PIPL), and Vietnam (PDPL) — may additionally request access, rectification, deletion, restriction, or data portability beyond the in-app controls by emailing the address in section 11.

8. Moderation & user-generated content

We have a zero-tolerance policy for objectionable content and abusive behavior, including hate speech, harassment, threats, spam, and sexual content involving minors. We act on user reports within 24 hours by deleting the reported content and, where the report is upheld, suspending or permanently ejecting the offending account.

Reporting and blocking mechanisms are surfaced on every message, profile, and post in the App. Blocking a user removes their content from your feed instantly and is also recorded as an internal report so our moderation team can review repeat offenders.

9. Children

qiuqiu is not directed to children under 13 (or the equivalent minimum age in your jurisdiction) and we do not knowingly collect data from them. If you believe a child has provided us data, please contact us and we will delete it.

10. Security

All network traffic is encrypted in transit with TLS 1.2 or higher. Account passwords are stored only as bcrypt hashes — no plaintext. Voice and video call media flows between peers via WebRTC and is never stored on our servers. It travels directly peer-to-peer whenever the two networks allow it; when they do not, it is relayed through Cloudflare's TURN service, which forwards the encrypted stream without being able to read it. Stored messages and media are not end-to-end encrypted at this time; we have access to them as required to operate moderation and abuse-response features described in section 8. We will state any change to end-to-end encryption status clearly here when it ships.

11. Contact

Questions, requests, or data-rights enquiries: [email protected].

12. Changes

We will update this page when our practices change. Material changes will be surfaced in-app via a re-acceptance prompt the next time you sign in.

Back to home