Terms & privacy

What we hold, and what we do with it.

Rindit is operated by Genexsus Technology LLC, a company registered in the United States. "We" throughout these pages means Genexsus Technology LLC, and it is the company answerable for the data described below. Write to [email protected].

Draft, not reviewed. These were written by the people who built Rindit, not by a lawyer, and have not been checked by one. They describe what we intend. They are not a substitute for proper legal review before Rindit is offered to the public, and nothing here is a contract while that is still true.

Who may use Rindit

You must be 13 or older. If you tell us you are younger, the account is deleted and the date of birth is not kept — not in the account, and not in our logs. Recording that a number belongs to a child is itself a fact about a child.

Do not use Rindit to send bulk unsolicited messages, to harass people, or to distribute content that is illegal where you are. The full list, and how to report a post or block a person, is in the community rules.

Who can read your messages

Messages are not end-to-end encrypted unless you turn it on. By default they are stored on our servers in a form the servers can read. In practice that means we can read them, and so could anyone who obtained access to our database or was legally required to be given it.

Any conversation can be encrypted, from the menu in its header, and a group can as well as a one-to-one. Once it is, the messages — and the photos, video and voice notes in them — are sealed on your device, and we store something we cannot read. We cannot produce those messages for anyone, including a court, because we do not hold the keys and there is no copy of them anywhere but on the devices in the conversation. Turning it on cannot be undone.

The connection between your device and Rindit is encrypted, which protects what you send in transit. It does not protect it once it arrives.

Encryption hides what was said. It never hides that it was said: who you talk to, when, and how often is visible to us in every conversation, encrypted or not.

What we collect

  • Your phone number or your email address — whichever names your account. One of the two, and you choose which. There is no password.
  • A second address, if you add one. An account named by a number can attach an email so passcodes can arrive there instead. It is never a second way to name the account, and nobody can find you by it — it is where a code is sent, and nothing else.
  • What you send — messages, posts, photographs, voice notes — and who you sent it to.
  • Your devices, so messages reach all of them and you can sign one out.
  • Your graph: contacts, friends, follows, the groups you are in. This is the part Rindit holds on purpose, and it is what makes the social side work.
  • Operational measurements — error rates, timings, how the app was opened. Not tied to what you said.

We do not sell it. Rindit is free and is paid for by advertising, which is a different thing — see below.

Advertising

Rindit is free, and advertising is how it is paid for. You will see ads in the app. Saying so here rather than in a paragraph nobody reaches is the same rule the rest of this page follows.

Advertising can never reach an encrypted conversation. That is not a promise, which is why it is worth more than one: the messages in an encrypted conversation are sealed on the devices in it, and our servers hold something they cannot read. There is nothing there for an advertising system to use, and no setting of ours could change that.

Advertising is never targeted using your messages or your social graph. Not the content of what you send, encrypted or not; not who you message; not who you are friends with, who you follow, or which groups and communities you belong to. None of it is used to choose which ads you see, and none of it is sold or shared with an advertiser.

This one is a commitment, not a property, and the difference is worth being clear about. The encrypted-conversation limit above holds whatever we decide, because we do not have the keys. This one holds because we say so. You cannot verify it from outside, and an app that blurred the two would be using the part it cannot break to lend credibility to the part it can. If it ever changes, it changes here first, in plain words, before it changes in the product.

How long things are kept

Retention, as the software actually behaves
WhatHow long
Messages, posts and commentsUntil you delete them, or delete your account. There is no automatic expiry.
Stories24 hours, then removed rather than hidden.
Messages waiting for a device that is offlineUp to 30 days, then dropped.
Sign-in passcodesFive minutes.
A signed-in session30 days, renewed while you use it.
BackupsA deleted item may persist in a backup for a period after deletion.

Deleting, and taking things with you

  • Delete a message for everyone and the words are removed from our database, not marked hidden.
  • Delete your account and the messages you sent go from other people's conversations too.
  • Export everything in one file: your account, your posts, and the messages you sent. Not the messages other people sent you — those are their words, and a file you can forward to anybody should not carry them.

Your rights

If you are in California, the CCPA and CPRA give you rights to know what is held about you, to have it deleted, and to correct it. The export and deletion above are how those are exercised, and they are available to everybody rather than only where the law requires them.

These pages will be reviewed by a lawyer before Rindit is offered to the public or takes any payment. When that happens this notice goes, and what replaces it will be something we can stand behind.