Privacy
Most privacy policies are written to be defensible. This one is written to be read, because the promise underneath it, end to end encrypted, is one people reasonably hear as "the server knows nothing", and that is not true of this service or of any other. What follows is what the service holds, what it cannot hold, and what we do about the difference.
Who is responsible
Callifornia is made and run by one person rather than a company, and that person is the operator of your personal data in the sense the law gives the word. Every decision described on this page is theirs, and the address at the bottom reaches them directly rather than a support queue. Write to fmtab2014@gmail.com about anything here, including every request under what you can ask for.
What this covers
Three things that are not the same, and each is named wherever a rule applies to only one of them. The app on your computer. The service it talks to. And this website, a handful of static pages that hand out an installer, which turns out to have a privacy story of its own and gets a section for it. What you may and may not do with any of the three is a separate document, the terms of use.
Who may use Callifornia
People aged 16 and over. Somebody younger may use it only with a parent or guardian agreeing on their behalf. Your age is never asked at sign up, and claiming that it is verified would be exactly the sort of thing this page exists to avoid saying, so instead this is the rule and an account we learn belongs to a child under 16 is deleted along with what it holds.
What the service cannot read
Everything you say and everything you look like inside a conversation is sealed on your computer before it leaves, with keys the server never receives.
- Messages. Stored as ciphertext, whether they were said in a call, in a meeting, or in the chat you keep with a friend outside any call. There is no copy in the clear, no search over them on the server, and no way for us to produce their contents on request, not for you and not for anybody else.
- Reactions. An emoji you put on a message is sealed on your computer under the same key as the message, and stored as one more envelope the service cannot open. What the service keeps beside it is who reacted to which message and when, and not with what.
- Pictures and files sent in a chat. Sealed on your computer under a key made for that one file, and stored as bytes the service cannot open. The key, the file's name and what kind of file it is travel inside the message that carries it, sealed like the message. What the service keeps beside that is which call or chat the file belongs to, who sent it, and how big it is.
- Calls. Audio and video are encrypted on top of the transport, so the media server routes packets it cannot open.
- The key of a call. It travels in the part of a link a browser never sends to any server, or sealed inside an invitation that only the invited friend can open, or sealed to your own account inside your call history so that another computer of yours can open a call this one took. While you are in a call, your computer also hands the service the key sealed to your own account, held in memory only, so that one of your other computers can pick the call up; it is gone the moment you leave. The service relays and stores what it cannot read.
- Your favourites. What you keep for yourself is a conversation like any other with nobody else in it. The notes, the messages you forwarded there and the files are sealed on your computer exactly as they would be in a chat with a friend, and the service holds ciphertext it cannot open. Its key is made on one of your computers and kept on the service once, sealed to your own account, so that your other computers can read what you saved there and nobody else's can.
- The key of a chat with a friend. Made on the computer of whichever of you opened the chat first, and kept on the service in two envelopes. One is sealed to your own account, so that your other computers can read the chat. The other is sealed to your friend's, and signed by whoever sealed it so that they know it came from you. The service cannot open either, and learns nothing else about the key.
- Your history of calls and meetings. Who you called, which meetings you were in, how long each lasted, how it ended, whether it was a call or a meeting, and the key of the room are sealed to your account before they leave your computer, so that all of your computers show the same list. The service keeps those envelopes in order and cannot open one. What it does see beside each of them is when it was, which it records anyway. See the next section.
- Who you pinned and who you muted. The friends you keep on your home screen and the ones whose messages arrive without a card are sealed to your account before they leave your computer, so that every computer of yours shows the same. The service stores the envelope and a number that goes up each time it changes, and tells your other computers when it does.
Encryption is only as good as the keys, and the keys live on your computers. We cannot recover them, which is the honest cost of the arrangement and is spelled out under if you lose your key.
What the service does know
This is the part that usually goes unsaid. None of it is a leftover to be tidied away later. Some of it is structural, and pretending otherwise would be the dishonest half of a privacy policy.
- Your email address. Needed to confirm the account when it is created, to send a reset code, and to let a new computer in when you have no other computer to approve it. Stored in the clear. One thing about it can be learned by others. Signing up with an address a confirmed account already holds is refused, and the refusal says why, because the alternative leaves somebody with an account they can never confirm. So whether an address is registered here can be found out by trying it. How often is limited to a handful of such answers a day for one network, one account or one address. Password recovery answers the same whether an account exists or not.
- Your username, display name and picture. The username is public by design, because it is how people find each other, and search runs over the display name too. The name and the picture are also what the people in a call see beside you. A picture is kept twice: the round crop shown everywhere, and the whole photo it was cut from, scaled down to at most 2048 pixels on its longer side. Anyone who can see the picture can open the whole photo. A picture you remove or replace can still be loaded from its old address for up to five minutes. The Add friend screen also offers a dozen accounts picked at random before anything is typed, so those three fields can reach somebody who was not looking for you by name. Nothing else travels with them, and an account you are already connected to, have asked or have blocked is never offered.
- Who you are connected to. Your friends. Who you talk to is a plain query against the database, even though what you say is not.
- How far you have read. For each room you are in, the service keeps one number: up to which message you have read. It is in the clear, because the service has to compare it and pass it on, to the other people in that room so they can see that you have read, and to your other computers so the count of unread messages follows you. It only ever moves forward, and it is not a log of when you looked.
- Who is ringing whom. A ring is held in the service's memory while it rings: who is calling, whom, into which room, and when it started. A ring into a call lasts forty five seconds, an invitation into a meeting lasts as long as the one who sent it stays in the meeting. A ring nobody answered is written down for the one who was rung, as a missed call with the time and the room key sealed to them, and deleted as soon as it reaches their app. A ring that was answered or declined leaves nothing behind.
- Which friends keep a chat, and when it was written in. A chat with a friend is a room the service knows belongs to the two of you, and every message in it carries the time it was sent, like any other. While you are typing to a friend the service passes that on to them and keeps none of it. A switch in Settings stops it being sent at all.
- Who was in which call, and for how long. Recorded for every room, including rooms joined by link. This is also why your call history is kept here at all, since the timing is already in this database and your own sealed copy of it adds nothing the service did not have.
- How much you say. The number of messages, their size, and the minutes of video. Ciphertext still has a length and a timestamp, and so does a file sent in a chat. The service knows that a message carries a file and how many bytes it is, and nothing about what it is. Each message also keeps the random id your computer gave it, so that a message sent again after a dropped connection is stored once. The id is made fresh for every message and says nothing about it.
- Which messages are pinned. A pin is kept in the clear: which message, who pinned it and when. It has to be, because the list of pinned messages in a chat is a page the service builds, and it cannot pick out what it cannot read. The message itself stays sealed, and only the fact that it is pinned is not.
- How much is in your favourites. The number of messages in your favourites and how many characters of ciphertext they come to, because both are limited and something has to count them. Not what is in them.
- Who is online, and when you last were. Presence itself is live state, and while you are online the service knows it. While the app is put away in the tray, your friends see you as away, though calls and messages still reach you and you still see which of your friends are online. The moment you were last here is not live state: it is written down, and your friends see it beside your name. One value, replaced every time you connect or disconnect and every time the app goes to the tray or comes back from it, so what exists is the most recent moment and never the ones before it. There is a switch for it in Settings; turned off, nobody sees the time and you simply read as away.
- Your IP addresses. In the web server's logs and in the media server's connections.
- Which version you are running. The app asks the update server whether a newer one exists, and that request carries the version and the platform, which is what answering it needs and all it carries.
- Which computers you have added, when they connect and how many of them are signed in. A computer this account has not used before gets a session that opens nothing until the computer you already use approves it, and is then remembered by an eight character name it made up for itself.
And nothing else off your machine. Callifornia does not read your address book, your files, or anything outside its own settings and the camera and microphone you switch on yourself.
Taken together this is metadata, and metadata is not the residue left over once the important part is protected. Who, with whom, and when is frequently enough on its own. Some of it can be reduced, with shorter log retention, no addresses in logs, and a last seen time that is one value overwritten in place rather than a record of when you come and go. The social graph cannot be hidden inside a relational database without a different architecture, and we are not going to claim otherwise.
Why we are allowed to hold it
Two grounds, and nothing is held on a third.
- Because you asked for the service. An account, its friends, its rooms and the timing of its calls exist so that the thing you signed up for can work at all. Take any of it away and there is no call to place. Accepting the terms of use before you download is what puts that arrangement on the record.
- Because you said yes. Crash reports, and nothing else on this page. They are off until you turn them on, off again the moment you turn them off, and refusing costs you nothing.
There is no advertising, no profiling and no scoring of you, so there is no third ground quietly doing the work those usually need.
How long it stays
| What | How long |
|---|---|
| Account, profile, friends, the computers you added | While the account exists, and gone when it is deleted |
| When you were last online | One value, replaced by the next one. Nothing earlier is kept, and it goes with the account |
| An account that never confirms its address | A week, and the username it was holding goes with it |
| A call, its chat and its key | A month after the last sign of life in the room, or the moment whoever started it ends the link |
| A chat with a friend, its messages and its files | As long as you are friends, and gone for both of you the moment either removes the other |
| What you keep in your favourites | As long as the account exists. A message you delete there leaves a marker for a month, so that a computer of yours that was switched off learns it is gone, and then the marker goes too |
| A missed call, waiting to reach your app | Until your app connects and receives it |
| Your sealed call history | Thirty days per call, and sooner if you remove one or switch it off |
| Web server logs, which carry addresses | Fourteen days, then deleted automatically |
| Counters and graphs about how the service is running | Fifteen days. They count requests and errors rather than people |
| Crash reports you chose to send | Until deleted by hand. There is no automatic sweep for these yet, and asking is how yours goes sooner |
What this website does
Separately from the service, because these pages are a different thing with different visitors, most of whom never sign up for anything.
- No cookies and no analytics. Not a lighter analytics, not a self hosted one, none. Nothing here counts you, follows you between pages or reports your visit anywhere, which is also why you have never been asked to dismiss a banner.
- Three small things in your browser's own storage, on your machine and sent nowhere. Which language you picked, which platform the download button should offer, and that you accepted the terms and read this page. Clearing your browsing data removes all three.
- Fonts are served from here, alongside the pages, rather than fetched from a font service. That is deliberate. A font loaded from somebody else's domain hands them the address of every visitor who reads this page, and a page about privacy is a poor place to do that.
- The pages come from GitHub Pages and the installer from Yandex Object Storage, so each of those sees the request that fetched it, in the ordinary way any web server sees the addresses it answers. Neither is asked for anything more.
Who else touches this data
Two, both acting on instructions rather than for themselves, and neither given the data for any purpose of their own.
- Yandex Cloud. The machines the service runs on, the database, the file storage and the mail that carries confirmation and reset codes.
- GitHub. This website and the release files, and nothing about your account, which never reaches it.
There is no advertising network, no analytics vendor and nobody buying anything. Lawful requests are answered with what we hold, which is the list further up and nothing more. Message contents cannot be handed over, because they are not ours to hand over.
Where it is kept
On servers in Russia. Recording, systematising, accumulating, storing, changing and retrieving the personal data of users in Russia all happen in databases located in Russia, which is what the law requires and how it is actually set up rather than a sentence added to satisfy it.
Nothing is transferred to another country. The website deliberately fetches nothing from a foreign service while you read it, and the one place that used to, a font service, was the reason this paragraph could not previously be written.
If you lose your key
The key that opens your conversations exists only on your own computers. This follows directly from the service not having it.
| What happened | Your account | Your conversations |
|---|---|---|
| Forgot your password and reset it by email | comes back | lost |
| Changed a password you still knew | kept | kept, since the key is not tied to the password |
| Reinstalled the app on the same computer | kept | kept, if the system keychain survived |
| A new computer while the old one still works | kept | new calls ring on both, and an old call opens where its link was opened |
| Lost every computer you had | comes back by email | lost for good |
You are told this when you sign up, in the reset email, and again on the reset screen before you confirm. It is not in the small print because it is not a detail.
Crash reports
Sent only if you agree to it, and you are asked once, plainly. What travels is three text files, the version and the error code, the return addresses of the stack that crashed, and the tail of the app's own log. The memory dump the system writes beside them never leaves your computer, because a key in use at the moment of a crash lives in memory, and the service is the one party this whole design keeps keys away from. The dump stays on your disk in case you ever decide to send it yourself.
Keeping it safe
What is actually in place, rather than a sentence about taking security seriously.
- Messages, call media and room keys are sealed on your computer, so the most valuable thing here is not ours to lose
- Passwords are stored as Argon2id hashes with a secret that lives outside the database, so the database on its own is not enough to attack them
- Everything between you and the service travels over TLS. A profile picture, the round crop and the whole photo alike, is served through an address that asks for a session first, though the storage behind that address still answers anyone who knows an object's exact key, which makes a picture the one item on this list that is not yet closed all the way
- A computer this account has not used before opens nothing until an existing one approves it
- Sign in and registration are rate limited, so guessing at passwords is slow rather than free
- The database is backed up on a schedule, and the backups sit with the same provider under the same account
None of this makes a system unbreakable and saying so would be a lie. If something does go wrong in a way that touches your data, you will be told what happened and what it means, on this site and by email where an address is affected.
What you can ask for
All of it by writing to the address below, from the email the account uses so that we can tell it is you. An answer comes within thirty days and usually far sooner.
- Whether anything about you is held at all, and if so what, where it came from, what it is for and who else has seen it
- A copy of it, in a form you can read
- Correction, if something is wrong or out of date, most of which you can also do yourself in the app
- Deletion, of the account and what belongs to it. There is no button for this in the app yet, so for now asking is how it is done, and it is done rather than argued with
- Blocking, if you believe data is incomplete, out of date, obtained unlawfully or not needed for what it was collected for
- Withdrawing consent, which in practice means crash reports, switchable in the app at any moment without asking anybody
- Complaining, to Roskomnadzor or to a court, and you never have to write to us first
Changes to this policy
The date at the top is how you tell. A change that actually affects what is held or what it is used for is announced on this site and in the changelog before it takes effect, and the box before the download asks again so that nobody is carried into a new version without noticing.
Contact
Everything on this page goes to fmtab2014@gmail.com. If something here turns out to be wrong or out of date, that is a bug and we would like to hear about it.