Privacy

In force from 10 October 2026

Most privacy policies are written to be defensible. This one is written to be read, because the promise underneath it, end to end encrypted, is one people reasonably hear as "the server knows nothing", and that is not true of this service or of any other. What follows is what the service holds, what it cannot hold, and what we do about the difference.

Who is responsible

Callifornia is made and run by one person rather than a company, and that person is the operator of your personal data in the sense the law gives the word. Every decision described on this page is theirs, and the address at the bottom reaches them directly rather than a support queue. Write to fmtab2014@gmail.com about anything here, including every request under what you can ask for.

What this covers

Three things that are not the same, and each is named wherever a rule applies to only one of them. The app on your computer. The service it talks to. And this website, a handful of static pages that hand out an installer, which turns out to have a privacy story of its own and gets a section for it. What you may and may not do with any of the three is a separate document, the terms of use.

Who may use Callifornia

People aged 16 and over. Somebody younger may use it only with a parent or guardian agreeing on their behalf. Your age is never asked at sign up, and claiming that it is verified would be exactly the sort of thing this page exists to avoid saying, so instead this is the rule and an account we learn belongs to a child under 16 is deleted along with what it holds.

What the service cannot read

Everything you say and everything you look like inside a conversation is sealed on your computer before it leaves, with keys the server never receives.

Encryption is only as good as the keys, and the keys live on your computers. We cannot recover them, which is the honest cost of the arrangement and is spelled out under if you lose your key.

What the service does know

This is the part that usually goes unsaid. None of it is a leftover to be tidied away later. Some of it is structural, and pretending otherwise would be the dishonest half of a privacy policy.

And nothing else off your machine. Callifornia does not read your address book, your files, or anything outside its own settings and the camera and microphone you switch on yourself.

Taken together this is metadata, and metadata is not the residue left over once the important part is protected. Who, with whom, and when is frequently enough on its own. Some of it can be reduced, with shorter log retention, no addresses in logs, and a last seen time that is one value overwritten in place rather than a record of when you come and go. The social graph cannot be hidden inside a relational database without a different architecture, and we are not going to claim otherwise.

Why we are allowed to hold it

Two grounds, and nothing is held on a third.

There is no advertising, no profiling and no scoring of you, so there is no third ground quietly doing the work those usually need.

How long it stays

What How long
Account, profile, friends, the computers you added While the account exists, and gone when it is deleted
When you were last online One value, replaced by the next one. Nothing earlier is kept, and it goes with the account
An account that never confirms its address A week, and the username it was holding goes with it
A call, its chat and its key A month after the last sign of life in the room, or the moment whoever started it ends the link
A chat with a friend, its messages and its files As long as you are friends, and gone for both of you the moment either removes the other
What you keep in your favourites As long as the account exists. A message you delete there leaves a marker for a month, so that a computer of yours that was switched off learns it is gone, and then the marker goes too
A missed call, waiting to reach your app Until your app connects and receives it
Your sealed call history Thirty days per call, and sooner if you remove one or switch it off
Web server logs, which carry addresses Fourteen days, then deleted automatically
Counters and graphs about how the service is running Fifteen days. They count requests and errors rather than people
Crash reports you chose to send Until deleted by hand. There is no automatic sweep for these yet, and asking is how yours goes sooner

What this website does

Separately from the service, because these pages are a different thing with different visitors, most of whom never sign up for anything.

Who else touches this data

Two, both acting on instructions rather than for themselves, and neither given the data for any purpose of their own.

There is no advertising network, no analytics vendor and nobody buying anything. Lawful requests are answered with what we hold, which is the list further up and nothing more. Message contents cannot be handed over, because they are not ours to hand over.

Where it is kept

On servers in Russia. Recording, systematising, accumulating, storing, changing and retrieving the personal data of users in Russia all happen in databases located in Russia, which is what the law requires and how it is actually set up rather than a sentence added to satisfy it.

Nothing is transferred to another country. The website deliberately fetches nothing from a foreign service while you read it, and the one place that used to, a font service, was the reason this paragraph could not previously be written.

If you lose your key

The key that opens your conversations exists only on your own computers. This follows directly from the service not having it.

What happened Your account Your conversations
Forgot your password and reset it by email comes back lost
Changed a password you still knew kept kept, since the key is not tied to the password
Reinstalled the app on the same computer kept kept, if the system keychain survived
A new computer while the old one still works kept new calls ring on both, and an old call opens where its link was opened
Lost every computer you had comes back by email lost for good

You are told this when you sign up, in the reset email, and again on the reset screen before you confirm. It is not in the small print because it is not a detail.

Crash reports

Sent only if you agree to it, and you are asked once, plainly. What travels is three text files, the version and the error code, the return addresses of the stack that crashed, and the tail of the app's own log. The memory dump the system writes beside them never leaves your computer, because a key in use at the moment of a crash lives in memory, and the service is the one party this whole design keeps keys away from. The dump stays on your disk in case you ever decide to send it yourself.

Keeping it safe

What is actually in place, rather than a sentence about taking security seriously.

None of this makes a system unbreakable and saying so would be a lie. If something does go wrong in a way that touches your data, you will be told what happened and what it means, on this site and by email where an address is affected.

What you can ask for

All of it by writing to the address below, from the email the account uses so that we can tell it is you. An answer comes within thirty days and usually far sooner.

Changes to this policy

The date at the top is how you tell. A change that actually affects what is held or what it is used for is announced on this site and in the changelog before it takes effect, and the box before the download asks again so that nobody is carried into a new version without noticing.

Contact

Everything on this page goes to fmtab2014@gmail.com. If something here turns out to be wrong or out of date, that is a bug and we would like to hear about it.