Privacy
A good community starts with trust.
ictima is operated by Cryptosam LLC, the controller of your account and community data. Address: 7901 4th N, STE 300, St. Petersburg, Florida 33702, United States. Privacy contact: info@ictima.com. This policy covers the website and our Android and iOS apps.
Last updated: 2026-10-07
What is stored
Supabase handles your email, password authentication and persistent account. If you choose Google sign-in, Google shares your account identifier, email and basic profile information with Supabase. Apple sign-in shares an account identifier and your real or private relay email. We do not request access to Gmail, Drive or contacts. The community stores your profile, room memberships, topics, messages, reports and moderation records. Direct messages are accessible to conversation participants through access controls; they are not end-to-end encrypted.
Live media and providers
Cloudflare relays audio only when you join a voice session. This application does not implement media recording. Transport encryption is not an end-to-end encryption promise. Your device requests microphone permission before capture. Server-side limits and moderation can stop a stream.
Friendships and voice calls
We store friendship and message-request decisions, call participants, call status and timestamps to provide private conversations, prevent abuse and show your records. Accepting a friendship allows messages and voice-call requests; you can disable calls, remove friends or block a person. We do not upload your address book. Voice calls use Cloudflare to relay encrypted audio in transit; they are not recorded, transcribed or sent to OpenAI. This is not an end-to-end encryption claim. Friendship and call records are included in account data exports. Account deletion disables these connections and removes identifying profile details; pseudonymous records may remain under the retention rules below. Optional call notifications store an account-linked device token. Apple APNs or Google FCM receives that token, a call ID, expiry and a short-lived ringing-status/decline credential, without message text, names or audio. Disabling notifications or signing out revokes this device. Delivery jobs are removed after one day; inactive device records expire within 90 days. Device metadata is included in your profile export.
Message notifications and unread counts
Optional message notifications use Apple APNs or Google FCM. We store your account-linked device token, notification preferences and the last-read position in each private conversation to deliver alerts and calculate unread counts. Previews are off by default: notifications contain no message text or sender name. If you enable previews, the sender’s display name and up to 160 characters of the message are sent to Apple or Google and may appear on your lock screen. You can turn previews off, disable notifications or revoke devices in Settings. Already in-flight notifications cannot be recalled. Read positions are not shown to other users. These settings and read positions are included in your data export and erased on account deletion. Browser push additionally stores your subscription endpoint and encryption keys. Your browser provider (Apple, Google or Mozilla) delivers the encrypted notification, including the same optional preview when enabled. Browser subscriptions are revoked on sign-out and account deletion.
Firebase Analytics
Android and iOS use Google Analytics for Firebase only after you allow analytics. It measures app sessions, screen categories and completed actions. You can turn it off in Help & safety; this stops future collection but does not erase previously collected Google data. Google processes app-instance identifiers, device/app information and approximate location. We do not send message content, room names, searches, email addresses, usernames or account IDs to Analytics. Advertising personalization and advertising identifier collection are disabled in this integration. Privacy requests: info@ictima.com. Firebase Analytics is not integrated into the website.
OpenAI Moderation
Profile photos stay private until a safety review. If you explicitly allow it when uploading, the resized photo is sent to OpenAI for automated moderation; we do not include your name, email or messages. If you decline, or the check is inconclusive or unavailable, an administrator reviews it. Automated checks can make mistakes and do not monitor live audio. You can remove your photo, report content and appeal a moderation decision. Rejected images are removed; an accepted appeal may require a new upload. OpenAI data practices: https://developers.openai.com/api/docs/guides/your-data.
With your explicit permission, room messages, topic titles and bodies, and replies are checked by OpenAI before publication. We send only the submitted text, without attaching account identifiers or conversation history; personal details you type are still part of that text. Direct messages are not sent to OpenAI. Reported direct messages and necessary context may be reviewed by authorized administrators. If the check flags content or is unavailable, the text is not published and your draft is kept. Automated checks can make mistakes; contact info@ictima.com for help. We do not automatically suspend accounts based on these checks or monitor live audio. Saved for all rooms on your account, on web and mobile. Change anytime in Settings → Privacy → Content moderation. Without this permission, you can still read, listen and send direct messages. New room posts need permission.
Google AdMob
The mobile Discover list may display Google AdMob ads. AdMob may process IP-derived approximate location, device identifiers, ad interactions and diagnostics for advertising, measurement and fraud prevention. We do not supply messages, searches or account details to AdMob. Initial ads are requested without personalization. Where required, a Google consent form appears before requesting ads; available choices can be changed from Help & safety under Advertising privacy. Non-personalized ads can still use identifiers. Learn how Google uses data: https://policies.google.com/technologies/partner-sites.
Profile photo
Selected profile photos are resized, stripped of source metadata and stored privately in Cloudflare R2. Authorized community members can view them. Removing a photo immediately removes access; physical cleanup can be delayed by provider failures.
Retention and requests
Account and community data are stored in our self-hosted Supabase. Cloudflare provides network security, CAPTCHA, live audio and private photo storage; AWS SES delivers account emails. The providers described on this page may process data outside your country. Active content has no automatic expiry. Account deletion closes access immediately and starts removal of login credentials, identifying profile details, your message/topic content and photos; pseudonymous relationship records and other members’ content may remain. Provider outages can delay completion. Logical backups expire after 30 days. In Profile → Settings you can export your data, manage permissions and initiate account deletion under Account & safety. Withdrawing a permission stops future processing within that permission; it does not recall previous transfers. For access, correction, deletion or other privacy-rights requests, contact info@ictima.com. Depending on your location, you may also complain to your data protection authority.
Policy version: 2026-10-05