Privacy Policy
What Nsibi collects, why, who sees it, how long we keep it, and how to get it back or get rid of it.
Last updated . Published by Nsibi, Toronto, Ontario, Canada.
On this page(16 sections)
- 1. Who we are
- 2. The short version
- 3. What we collect
- 4. What we do with it
- 5. What we never do
- 6. Encrypted chats, and where encryption stops
- 7. Camera, photos and face effects
- 8. Who else sees it
- 9. Why we are allowed to use it
- 10. Where your information is
- 11. How long we keep it
- 12. Your rights and your choices
- 13. Children and teenagers
- 14. How we protect it
- 15. Changes to this policy
- 16. Contact us
This policy explains how Nsibi handles your information across the Nsibi app on Android and iOS, Nsibi Web, and our websites at nsibi.app.
It is written to be read. Where a section could be one honest sentence, it is one sentence.
1. Who we are
Nsibi is the controller of the information described here. We are a business registered in Ontario, Canada under Business Identification Number 1001736279, with our principal place of business at 3080 Yonge Street, Unit 6060, Toronto, Ontario M4N 3N1, Canada.
For anything about your data, write to hello@nsibi.chat or to the postal address above.
2. The short version
- Your chats and calls are end-to-end encrypted. We cannot read them, and that is a property of how they are built, not a policy we could change our minds about.
- What you publish - posts, comments, status, live broadcasts and their replays - is not encrypted. We can read it, and we have to in order to rank it, show it and moderate it.
- We do not sell your data, we do not show ads, and there is no advertising or analytics SDK inside Nsibi that tracks you across other apps or websites.
- Your contact list is not uploaded. Your phone hashes each number and asks us only whether a match exists.
- Face effects run on your phone. Nothing that describes your face is sent to us, and nothing here identifies you biometrically.
- You can delete your account from inside the app, and section 12 says exactly what goes and what stays.
3. What we collect
- Your account
- Your phone number, which is your account identity, and a display name. Optionally a profile photo, a short bio and a city label if you add them. Your date of birth, which we ask for at signup and use to apply age limits. An email address if you give us one, which is optional, unverified, and used only to send you receipts and notices about your money.
- Finding people you know
- Your phone can look up whether a number in your address book is on Nsibi. It does this by sending us a one-way hash of the number rather than the number, and we answer only with whether a match exists. We do not upload, store or index your address book.
- Messages and calls
- We carry the encrypted form of your messages and hold it until your devices have it, and for no longer than ninety days in any case. We handle who a message is for and roughly when it was sent, because delivering it requires that. We never have the content. For calls we handle the signalling that connects them and issue short-lived relay credentials for difficult networks; the call itself flows between the devices on it.
- Your keys and your backup
- The public halves of your device keys, so that other people can start an encrypted session with you. Your chat backup, if you make one, is a blob encrypted with a key only you hold. We store it and cannot open it.
- What you publish
- Posts and the photos and videos in them, captions, hashtags, comments, statuses, live broadcasts and clips cut from them, the sounds you use, and who you follow, like and block. This is not encrypted.
- Your live replays
- When you host a live broadcast, we record it and keep the recording for you as a replay: the picture and sound your viewers saw, including anyone who joined you on stage and the other hosts in a match. Only you can watch it in the app, and you can save a copy to your phone. Replays are kept by default. Turn off Save LIVE replay before you go live and that broadcast is not recorded; your choice carries over to your next live. An invitation to join your stage says that you keep a replay. Like the broadcast itself, the recording is not encrypted.
- How you use Nsibi
- Which posts we showed you, how long you watched each one, what you skipped, and what you liked, shared or said you were not interested in. We turn this into an interest profile so that your feed is yours rather than a chart. Also the app version, your device model and operating system, and a crash report when something goes wrong.
- Where you are
- What we hold is a country and, if you allowed it, a city name. We work the country out from your device time zone and from the network your request arrives on, and we use it to show you things from near you and to offer the right payment methods. If you grant the location permission, your phone reads a coarse fix, looks up the country and city on the device, and sends us only those two labels. Your coordinates are not transmitted and we do not store a location history.
- A location you share in a chat
- Sharing your place in a conversation sends your coordinates to the people in that chat, inside an ordinary end-to-end encrypted message. It is protected exactly like the rest of the conversation, and we cannot read it.
- Money
- A record of coins you bought, gifts you sent or received, earnings credited to you, withdrawals you made, and the payment method type and country. Card numbers, mobile money PINs and bank credentials go to the payment provider and never to us. If you make a donation on our website we collect the name, email address and message you type into that form.
- Notifications
- A push token for each device you have Nsibi on, and the language that device is set to, so that a notification arrives in the language you read.
- Safety
- Reports you file and reports filed about you, and what we did about them. Where you file an ownership claim over a sound, the evidence you upload with it.
4. What we do with it
- To run the service: deliver messages, connect calls, carry live video, store what you post and show it to the people you posted it to.
- To let you sign in and to keep the account yours, which is what the code by SMS is for.
- To decide what to show you in the feed, which is what the watch and interest data is for.
- To apply age limits, which is what the date of birth is for.
- To take payments, pay out earnings, and keep the financial records the law requires us to keep.
- To keep people safe: to act on reports, to detect fraud, spam and abuse, and to enforce our Terms of Service.
- To fix the app, using crash reports and error logs.
- To tell you about something that affects your account or your money, and to answer you when you write to us.
- To comply with the law, and to respond to a lawful request from an authority that we are required to answer.
5. What we never do
- We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
- We do not show ads in Nsibi, and there is no third-party advertising network inside the app.
- We do not track you across other apps or websites. Nsibi shows no App Tracking Transparency prompt on iOS because there is nothing for it to ask about.
- We do not read your messages, because we cannot.
- We do not use your face, your voice or your body to identify you, and we do not build a biometric template of you.
- We do not use your content to train a general-purpose artificial intelligence model for anyone else.
6. Encrypted chats, and where encryption stops
Chats and calls are end-to-end encrypted with the Double Ratchet, through an audited implementation. The keys are generated on your device and never leave it, so the message we carry is sealed and stays sealed while it is with us. The same applies to files you send in a chat, to your chat backup, and to the text your phone puts on your lock screen, which your own phone decrypts.
Encryption covers your conversations. It does not cover what you publish. Posts, comments, statuses and live broadcasts are readable by our servers, because ranking, search, delivery to the right audience and moderation all need the content. Treat a post as public even when its audience is limited.
Our security page explains this in more detail, including a plain list of what is not encrypted.
7. Camera, photos and face effects
Nsibi asks for your camera, microphone and photo library only when you use a feature that needs them, and you can refuse. On iOS and Android you can change your mind later in your system settings.
Beauty effects, filters, backgrounds and try-on items work by finding the shape of your face and separating you from what is behind you. That runs entirely on your phone, in the app. The face landmarks and the person mask are used to draw the frame and are then discarded. They are never uploaded, never stored, and never used to identify you or anyone else.
What does leave your phone is the finished picture or video, if you choose to post, send or broadcast it.
9. Why we are allowed to use it
If you are in a place with a data protection law that asks for a legal basis, such as the United Kingdom, the European Economic Area or a country with a comparable regime, these are ours.
- To perform our contract with you
- Running your account, delivering messages, connecting calls, showing your posts to your audience, and taking and making payments.
- Our legitimate interests
- Keeping Nsibi safe and free of fraud and abuse, fixing the app, ranking your feed so it is useful, and understanding at an aggregate level how the product is used. We balance this against your interests, and you can object as set out in section 12.
- Legal obligation
- Keeping financial records, responding to lawful requests, and meeting the rules that apply to age limits and to reporting child sexual abuse material.
- Consent
- Camera, microphone, photo library, contacts and notification permissions. You give it in the system prompt and you can take it back in your device settings.
10. Where your information is
We are based in Ontario, Canada, and we and our providers process information in Canada, in Europe and in the United States. That means your information may be transferred out of the country you live in.
Where we transfer information out of the United Kingdom or the European Economic Area, we rely on the transfer mechanisms the law provides, including the European Commission's standard contractual clauses and, for Canada, its adequacy decision.
11. How long we keep it
- Encrypted messages on our servers
- Until your devices have collected them, and no more than ninety days in any case. Your own phone keeps your history for as long as you keep it there. Disappearing messages go on the schedule you set.
- Your account and your posts
- Until you delete them or delete your account.
- The recording buffer behind a live broadcast
- Thirty minutes. It exists so a viewer can cut a clip from the moment that just happened, and it is never played back to anyone.
- A clip you cut but never posted
- Twenty-four hours, after which the file is deleted.
- Live replays
- Thirty days from the end of the broadcast, then deleted from our storage, along with any video prepared for saving. You can delete one sooner at any time, from Settings, then LIVE replays. A copy you saved to your phone stays on your phone.
- The video segments a live is delivered in
- Most viewers receive a live as short video segments through our content delivery network. They are deleted two to three days after they were made, whether or not the broadcast is kept as a replay.
- Feed and interest data
- For as long as your account exists. It is deleted when you delete your account.
- Financial records
- For as long as the law requires us to keep them, which is usually several years, in an anonymised form once the account is gone.
- Safety reports
- For as long as we need them to keep people safe, including after the reported account is deleted. Otherwise deleting an account would be the cheapest way to erase a record of what it did.
12. Your rights and your choices
Depending on where you live, you have some or all of these rights. We do not charge for exercising them and we do not treat you differently for it.
- Get a copy of the information we hold about you.
- Correct it if it is wrong. Most of it you can edit yourself in the app.
- Delete it. Delete your account from the You tab, then Account, then Delete account, and follow the steps.
- Object to us using it under our legitimate interests, or ask us to restrict what we do with it.
- Take it with you, in a machine-readable form, where the law gives you that right.
- Withdraw a permission you gave, in your device settings.
- Complain to a regulator, without going through us first.
Deleting your account destroys your profile, your posts and statuses, your live replays, your device keys, your encrypted backup and your interest profile. What survives is deliberate and short: messages you sent that sit in other people's conversations, the financial ledger, and reports filed about the account. Your account row is emptied into an anonymous tombstone and your phone number is released so it can sign up fresh. Our account deletion page lists this in full, and the app shows it again before you confirm.
To make a request, write to hello@nsibi.chat from the email address on your account, or from any address if you tell us the phone number. We may need to verify that the account is yours before we act, which for a phone-number account usually means proving you control the number.
We answer within thirty days, or sooner where the law requires it.
13. Children and teenagers
Nsibi is not for children under 13, and it is not for anyone under the minimum age set by the law where they live if that is higher. We do not knowingly collect information from them.
If you are between 13 and 17, your account starts more private: your posts go to your followers rather than to everyone unless you change it, and content we consider mature is kept out of what we recommend to you. Direct messages are available from 16, and hosting a live broadcast, sending or receiving a gift, and anything involving money are available from 18.
If you believe a child under 13 has an account here, tell us at hello@nsibi.chat and we will look into it and close it.
14. How we protect it
Chats, calls and backups are end-to-end encrypted, with the keys held on your device. Traffic between your device and our servers is encrypted in transit. Media files you can only reach by permission are served behind expiring, signed URLs rather than from an open directory. Access to production systems is limited to the people who need it and separated by role, so that no single staff account can do everything.
No service is perfectly secure. If a breach affects you we will tell you and the relevant regulator, as the law requires.
If you have found a security problem in Nsibi, please report it to hello@nsibi.chat rather than posting it, and give us a chance to fix it.
15. Changes to this policy
When this policy changes we update the date at the top of the page. Where a change is material, we tell you in the app or by email before it takes effect, so that you can decide what to do about it.
This policy is published in English. Where we provide a translation, it is for convenience, and the English version governs if the two differ.
16. Contact us
Write to us at hello@nsibi.chat, or by post at 3080 Yonge Street, Unit 6060, Toronto, Ontario M4N 3N1, Canada.
If you are in Canada and you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada. If you are in the United Kingdom or the European Economic Area, you can complain to your national data protection authority.
Nsibi
Registered in Ontario, Canada. Business Identification Number 1001736279.
3080 Yonge Street, Unit 6060Toronto, Ontario M4N 3N1Canada