This Privacy Policy explains how Blackbone SRL ("Blackbone", "we", "us", or "our"), a company registered in Romania, processes information in connection with the Blackbone Messengerapp for iOS, macOS and web ("the App" or "the Service"). Blackbone SRL is the data controller under Regulation (EU) 2016/679 (GDPR).
Short version: your direct one-to-one conversations and their attachments are end-to-end encrypted — we cannot read them. We run our own infrastructure, use no third-party analytics or advertising SDKs, and never sell your data.
1. Data we process
- Account data: display name, username, optional phone number, optional profile photo, optional status text.
- Content: messages, images, files, voice messages. Stored only as long as needed to deliver them. Direct one-to-one chats and their files are end-to-end encrypted (X25519 key agreement + ChaCha20-Poly1305); we store only ciphertext and cannot decrypt it. Group and channel messages are transport-encrypted (TLS) but readable by the server to deliver them.
- Technical data: push notification token, session and device records, and minimal server logs needed for security and operation.
- Contacts matching (optional):if you use "find contacts", phone numbers from your address book are hashed/normalized and checked against registered users to show who is already on Blackbone. This runs only when you initiate it.
We collect no more than necessary and do not sell your data.
2. What we do NOT collect
- The content of your end-to-end encrypted direct chats and calls
- Advertising identifiers (IDFA) or cross-app tracking data
- Analytics or telemetry from inside the App — there is no analytics SDK
- Your browsing history or data unrelated to the Service
3. Purposes and legal bases (GDPR)
- Providing the Service (delivering messages, calls, groups) — performance of a contract (Art. 6(1)(b)).
- Security and abuse prevention — legitimate interest (Art. 6(1)(f)).
- Push notifications — consent, revocable from device settings (Art. 6(1)(a)).
- Legal obligations — where applicable law requires (Art. 6(1)(c)).
4. Calls
Audio and video calls use WebRTC and are encrypted with DTLS-SRTP. Media may traverse a Blackbone relay (TURN) server so that two devices on different networks can connect. Call content is not recorded or stored.
5. Push notifications
We use Apple Push Notification service (APNs) to alert you about new messages and incoming calls. For end-to-end encrypted chats, the push contains no message preview (only "New message"). You can disable notifications in your device settings at any time.
6. Storage and retention
Undelivered messages are retained only as long as needed for delivery. You can delete your account from the App; on deletion we remove your associated data, except where retention is required by law. Media you send is stored to allow delivery and, for direct chats, is stored only as encrypted blobs.
7. Third parties and infrastructure
The Service runs on infrastructure operated by Blackbone (self-hosted servers in the European Union) and uses Apple services (APNs, and Apple's App Store / TestFlight for distribution). We use these strictly to operate the Service. We do not share your data for marketing. The App contains no third-party advertising or analytics SDKs.
8. International transfers
Our servers are located in the European Union. Where Apple processes data (e.g. push delivery), it may do so under its own privacy framework and safeguards.
9. Your rights (GDPR)
You have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data. You may also lodge a complaint with the Romanian supervisory authority (ANSPDCP) or your local authority. Because direct chat content is end-to-end encrypted, we cannot produce its plaintext even on request.
10. Security
Passwords are hashed, sessions are secured, two-factor authentication (TOTP) is available, and direct chats use end-to-end encryption. Optional in-app controls let you block screenshots/screen recording and enable disappearing messages. No system is 100% secure.
11. Children
The Service is not directed to persons under 16 and we do not knowingly process data about children under 16.
12. Changes to this policy
We may update this policy from time to time. The "Last updated" date above reflects the latest version. Material changes will be announced inside the App.
13. Contact
Blackbone SRL · Romania
Email: office@blackbone.ro
Data protection (GDPR): dpo@blackbone.ro

