Sinhela Chat — Privacy Policy
Last updated: 31 August 2026 (encryption on by default) · Contact: nipuna.makalanda@gmail.com
Sinhela Chat is a messaging app. This page says plainly what we store, what we can see, and what you control. If anything here changes, the date above changes with it.
What we store
- Account: your email address, username, display name, and optional profile details (photo, bio, region) you choose to add.
- Messages and media you send, so they can be delivered and synced to your devices. Deleting a message for everyone removes it from the server. For end-to-end encrypted chats — the default — what we store is unreadable ciphertext: encrypted message text, and encrypted files whose keys never reach us.
- Moments and Status posts you publish, visible per the audience rules shown when posting. Status stories expire automatically.
- News comments and reactions, visible to all signed-in users.
- Device push tokens, so notifications reach your phone.
- Call metadata (who called whom, when). Call audio/video travels peer-to-peer or through our relay and is never recorded.
What we do NOT do
- No ads, no selling or sharing of your data with third parties.
- No reading of your contacts book without you adding a contact yourself.
- No tracking SDKs or analytics beyond basic server logs.
- No location collection. The district you pick for emergency alerts is stored on your phone and never sent to us: a warning goes out with the districts it covers, and your phone decides whether it applies to you.
Stickers
Sticker packs you import are kept against your account so they appear in your gallery and nobody else's. The stickers you actually send are messages, and are encrypted like any other message.
Third parties we rely on
- Supabase (database, authentication) and DigitalOcean (our server) host the data above.
- Google Firebase Cloud Messaging delivers push notifications (it sees the notification payload).
- Translation providers receive the text of a message only when you tap Translate.
- The news feed is fetched from public news sites by our server; news sites never see who reads them.
Your controls
- Block anyone from their profile; they are not told.
- Report messages, comments, posts or people; reports go to the operator for action.
- Delete your account in the app under Me → Delete account: your profile, messages, media and contacts are permanently removed from the server.
- Switch encryption off for a chat from its menu (it is on by default), verify a chat's safety numbers, and back up your chats to your own Google Drive, encrypted, under Me → Chat backup.
What encryption does not hide
Even with end-to-end encryption, our servers necessarily see metadata: which accounts exchange messages, when, how big a message or file is, and its type. Encryption protects the contents, not the fact that a conversation happened. Calls are a separate case: their audio and video are always encrypted and are never recorded, but we do keep a record of who called whom and when.
Retention
Data is kept while your account exists. Expired stories and dead push tokens are cleaned automatically. Server backups, where present, age out on their own schedule.
Children
Sinhela Chat is not directed at children under 13 and we do not knowingly collect their data.