Efir Personal Data and Privacy Policy
This Policy explains who processes data in Efir, which data is required to operate the messenger, where it is stored, when it may be shared, and how users can exercise their rights.
Effective: 13 July 2026
1. Controller and scope
- the personal data controller and provider of Efir is Artem Yuryevich Ustinov, an individual; the publisher name in app stores may appear as Artem Ustinov or EFIR LLC;
- privacy, security and account deletion contact: support@efirapp.ru;
- this Policy applies to the Efir apps for iOS and Android, the web service at efirapp.ru, support communications and related server features;
- Efir processes data relating to users, chat and group participants, people in a user’s address book, and people who contact support.
2. Data we process
- account data: phone number and its one-way hash, name, surname, username, profile photo, language, settings, active sessions and an email address if you choose to provide one;
- communications: chats, participants and roles, messages, reactions, delivery and read status, reports, blocks, photos, videos, documents, voice messages and other attachments;
- call data: participants, type, time, duration, status, signalling and diagnostic information. Efir does not offer call recording and does not normally store the content of call audio or video streams;
- device contacts with permission: SHA-256 hashes of normalized phone numbers and the related address-book names are sent to the server; raw phone numbers are not sent as part of contact matching;
- Telegram integration data when voluntarily connected: phone hint, account identifier and status, authorization state, selected channels, subscriptions and data required by TDLib to provide the feed;
- technical data: IP address, request date and time, device type, operating system and app version, device and session identifiers, push and VoIP tokens, network events, crash, performance, security and diagnostic data;
- usage data: feed settings, selected sources, feature interactions, local cache and other data required by the app. Support messages are processed to answer the request;
- Efir does not request special-category or biometric data to identify users. Please do not submit such data in profiles, messages or support requests unless necessary.
3. Why we process data
- to register and verify a phone number, provide an account, authenticate users, manage sessions and protect login;
- to deliver messages, media, calls, reactions, invitations and notifications and synchronize history across devices;
- to find people already using Efir after contact permission is granted and display the contact name selected by the user;
- to connect a Telegram account and build a feed of selected Telegram channels when the user enables this feature;
- to prevent spam, fraud, unlawful content, unauthorized access and technical failures;
- to handle reports and support requests and maintain service quality, compatibility and security;
- to comply with law and binding authority requests and protect the rights of users and the controller.
4. Legal bases and processing operations
- data required for registration and Efir’s core features is processed to enter into and perform the User Agreement at the user’s request;
- where applicable, processing is also based on legal obligations, safety and legitimate interests, a user request, or separate consent when the law requires it;
- accepting the User Agreement and acknowledging this Policy does not itself constitute separate consent for unrelated optional processing that legally requires consent;
- processing may be automated or mixed and may include collection, recording, organization, storage, updating, retrieval, use, transmission, access, anonymization, restriction, deletion and destruction.
5. Messages, media and calls
- messages and attachments are stored on Efir infrastructure and made available to the relevant chat participants; media is delivered through temporary signed links;
- new message text is protected by server-side encryption at rest and decrypted by the server for delivery. This is not end-to-end encryption, and Efir does not claim otherwise;
- call audio and video is transmitted in real time directly or through a technical TURN relay. Call metadata is processed for connection and diagnostics, but Efir does not normally record call content;
- a recipient may save, forward or capture content available to them. Efir cannot control copies created by other users outside the service.
6. Device permissions and local data
- contacts, camera, microphone, photo, video, file and notification access is used only for the stated feature after the relevant system permission is granted;
- permissions can be revoked in iOS or Android settings; related features may then stop working;
- the device may store an authorization token, settings, drafts, messages and media in a limited local cache for faster and offline operation;
- clearing the cache removes local copies but does not delete the account or server messages. Account deletion is a separate action in Efir settings.
7. Recipients and service providers
- Russian infrastructure providers process Efir’s primary database and API;
- Cloudflare R2 provides protected object storage for media and files;
- Google Firebase Cloud Messaging and Apple Push Notification service deliver notifications. Depending on device settings, a notification may contain a sender name, message preview or media preview;
- Giphy receives a search query and ordinary connection data when a user opens GIF or sticker search;
- Telegram and TDLib process connection and channel data only when the Telegram feed is enabled; a separate technical server is used for this integration;
- Apple App Store and Google Play independently process installation, update, store transaction and diagnostic data under their own policies;
- data may be disclosed in response to a valid binding request from an authorized body. Efir does not sell personal data or provide it for third-party behavioral advertising.
8. Data location, international transfers and security
- for Russian citizens, initial recording, organization, accumulation and storage takes place using Efir’s primary database located in Russia;
- certain data and copies may be transferred to or processed outside Russia through Cloudflare, Google, Apple, Giphy, Telegram and foreign technical infrastructure. Applicable international-transfer requirements apply to those operations;
- Efir uses TLS in transit, access controls, authentication, security logging, temporary media links, server-side message encryption at rest and backups;
- no storage or transmission method is completely secure. If an incident is identified, the controller takes mitigation measures and performs notification duties required by applicable law.
9. Retention and deletion
- account data is retained while the account and User Agreement remain active, or while required for the stated purposes and mandatory legal duties;
- when an account is deleted, the phone number, name, username, avatar and other profile identifiers are deleted or anonymized, active sessions and push tokens are revoked, and stored contacts and the Telegram account link are removed;
- messages and submitted content may remain in other participants’ history under “Deleted Account” to preserve conversation integrity. Users may delete content available to them before deleting the account;
- security logs, backups and abuse-prevention data may be retained for up to 90 days, or longer where a specific legal obligation applies;
- an account can be deleted in the app under Settings → Delete account. The alternative process is published at https://efirapp.ru/account-deletion.
10. User rights
- request information about processing and a copy of personal data where provided by law;
- correct profile data and request correction, restriction or deletion of inaccurate or unlawfully processed data;
- withdraw consent where a specific operation is based on consent. Withdrawal does not affect prior lawful processing and does not stop processing based on another lawful ground;
- restrict system permissions, terminate sessions, delete content within the available controls, or delete the account;
- contact the controller at support@efirapp.ru or submit a complaint to the competent data protection authority.
11. Minors
- users must have the legal capacity required to accept the User Agreement. Minors may use Efir with the permission and supervision of a parent or legal guardian where applicable law requires it;
- Efir is not knowingly directed to children under 13. An app-store age rating describes content suitability and does not replace legal guardian requirements;
- a legal guardian who believes a child’s data was obtained unlawfully may contact support@efirapp.ru to request review and deletion.
12. Requests and policy changes
- send privacy requests to support@efirapp.ru and include the account phone number and the nature of the request. Account ownership verification may be required for security;
- the controller responds within the time required by applicable law;
- this Policy may change when the service, providers or law changes. The current version and effective date are published at https://efirapp.ru/privacy;
- material changes affecting user rights may also be announced in the app or by another reasonable method.