Privacy Policy
Last updated:
This policy explains what data the Pairs application (the “App”) processes, for which purposes, with whom it is shared and what rights you have. Pairs is designed so that the content you share with your partner is unreadable to anyone but the two of you — including us.
1. Data controller
The controller is Arkode, based in Mexico (“Arkode”, “we”). You can reach us about any privacy matter at contacto@arkode.mx.
2. Summary
- All content (text, images, voice notes) is end-to-end encrypted on your device. We never receive plaintext or the keys to decrypt it.
- Our servers act only as a relay: they store encrypted messages until the other person receives them, then delete them. A message never stays longer than 30 days.
- Your full history lives on your devices and, if you enable it, in an encrypted backup in your own Google Drive or iCloud account, which we cannot access.
- We use no analytics, tracking tools, third-party crash reporting or advertising.
- You can export your history, unlink from your partner or delete your account at any time from the App.
3. What data we process
We process only the data required for the App to work:
- Account data: user identifier, email address and sign-in provider (email and password, Google or Apple). Managed by Firebase Authentication.
- Public encryption keys: your X25519 public key and its version number. The private key is generated and stored only in your device's secure storage; we never receive it.
- Couple data: the couple identifier, its two members, status and creation date. Invitations are stored as a single-use hash that expires after ten minutes.
- Encrypted messages in transit: the ciphertext, nonce, note type (text, image, audio or nudge) and, where applicable, the path to the encrypted media file, plus send and delivery timestamps. We cannot read any of this content.
- Push notification tokens: to let you know you have a new note. The notification never contains the content, and you can choose to hide even the App's name.
- Purchase status: whether the couple holds the one-time purchase, who made it, the product identifier and the date. We verify it with RevenueCat.
- Synced privacy preferences: only the option to hide the notification body.
What we do not process: the content of your notes, your photos or audio in the clear, your contacts, your location, advertising identifiers, or usage and behavioural data.
4. Purposes and legal basis
- Providing the service you request: creating your account, pairing you with your partner, relaying encrypted messages and sending notifications (performance of a contract).
- Verifying the one-time purchase and the couple's access (performance of a contract).
- Protecting the security of the service, for example through access rules, app attestation and rate limits (legitimate interest).
- Complying with legal obligations that apply to us.
5. How encryption works
Each person has an identity key pair generated on their device. From your own private key and your partner's public key a shared key is derived (X25519), and every note is encrypted with it (XChaCha20-Poly1305) before leaving the phone. Media files are compressed and encrypted with a random per-file key; that key travels inside the encrypted note.
When pairing, the App shows a safety code that both of you must compare in person. If either of you changes keys (for example when recovering an account), the other sees a visible “safety code changed” notice.
6. Retention and deletion
- Encrypted messages and files in the relay: deleted when the other person confirms receipt. As a safety net, they expire automatically 30 days after creation.
- Account and couple data: kept for as long as your account exists.
- When you unlink: all remote couple data (messages, files, invitations) is deleted. Your local history remains on your device.
- When you delete your account: your user, notification tokens, remote couple data and purchase record on our server are deleted. See how to delete your account.
- Local history: lives on your device under your control; it is removed when you uninstall the App or clear its data.
- Cloud backup: managed by you in your own Google Drive (app data folder) or iCloud account. We can neither view nor delete it.
7. Providers and third parties
We use providers that process data on our behalf. None of them receives the content of your notes in the clear.
- Google Firebase (Google LLC): authentication, database and storage for encrypted messages in transit, cloud functions, push notifications (Firebase Cloud Messaging) and app attestation. Servers may be located in the United States.
- RevenueCat (RevenueCat, Inc.): verification of the one-time purchase made through the App Store or Google Play. It receives an App user identifier and the transaction data provided by the store.
- Apple and Google as sign-in providers (if you choose that option), app store and billing providers.
- Google Drive or iCloud, only if you enable backups: the encrypted copy is stored in your own account. The App requests the minimum permission (
drive.appdata), which grants no access to the rest of your files.
We do not sell personal data or share it for advertising. We may disclose data where required by law, always limited to what we hold: account data and encrypted content we cannot decrypt.
8. Device permissions
- Camera: only to scan invitation and recovery QR codes. Images are not stored.
- Photos: to pick images you want to send. They are compressed and encrypted locally.
- Microphone: to record voice notes. Audio is encrypted before upload.
- Notifications: to alert you about new notes without revealing content. Optional; disabling them does not affect syncing.
- Biometrics (Face ID, Touch ID, fingerprint): optional, for the App lock and to protect keys in secure storage. Verification is performed by the operating system; we never receive biometric data.
9. Security
Beyond end-to-end encryption, the access rules of our database and storage allow only the two members of a couple to read or write their data. Private keys are kept in the system's secure storage (Keychain or Keystore) and, if you enable the App lock, require biometric authentication.
A consequence of this design is that we cannot recover your content if you lose your devices and your recovery phrase. Keep it somewhere safe.
10. Children
Pairs is intended for adult couples. It is not directed at people under 18 and we do not knowingly collect data from minors. If you believe a minor has created an account, write to us and we will delete it.
11. Your rights
Under Mexico's Federal Law on the Protection of Personal Data Held by Private Parties and, where applicable, other laws such as the GDPR, you may exercise your rights of access, rectification, cancellation and objection (ARCO), as well as withdraw consent and request portability.
Many of these rights can be exercised directly from the App: export your history, unlink or delete your account. For any other request, write to contacto@arkode.mx from the email address linked to your account. We will respond within 20 business days.
Note that, because content is end-to-end encrypted, we cannot access, modify or hand it over: export happens from your own device.
12. International transfers
Our providers may process data outside your country, mainly in the United States. This concerns only account data and encrypted content. Providers apply contractual and security safeguards in line with applicable law.
13. Changes to this policy
If we materially change this policy, we will say so on this page and, where appropriate, inside the App. The date of the last update appears at the top.
14. Contact
Arkode · Mexico · contacto@arkode.mx