
Last updated: 15 August 2026 | Effective: 15 August 2026
Nexever Private Limited, 3rd Floor, The Design Place, Plot no. A-28k, Phase 7, Industrial Area, Sector 73, Sahibzada Ajit Singh Nagar, Punjab 160055, India ("we", "us") is the controller of personal data processed through Ninja Private Messenger (the "Service") — the "Data Fiduciary" under Indian law and "Personal Information Handling Business Operator" under Japanese law.
This policy explains what we collect, why, how long we keep it, who we share it with, and your rights.
| Data | Purpose |
|---|---|
| Email address | Account creation, identity, recovery, service notices |
| Username and display name | Identifying you to other users |
| Profile photo (optional) | Display to your contacts |
| Social login identifier, where used | Authentication |
| Phone number (legacy accounts only — no longer collected for new registrations) | Identity and recovery for accounts created before email-based registration was introduced |
End-to-end encryption protects the content of your communications. It does not mean we hold no information about you. We process:
| Data | Purpose |
|---|---|
| IP address and approximate location derived from it | Security, abuse prevention, enforcing geographic restrictions on calling features, fraud detection |
| Device information — model, OS, app version, device identifiers | Delivery, compatibility, diagnostics, abuse prevention |
| Push notification token | Delivering notifications |
| Connection and session logs — connection times, session duration | Security, abuse detection, service operation |
| Message and call metadata — sender and recipient account identifiers, timestamps, message size, call duration | Routing and delivery |
| Encrypted payloads (ciphertext) held in transit and until delivery or expiry | Delivery |
| Abuse reports and safety signals | Investigating breaches of the Terms |
| Purchase records | Billing and support |
We cannot read the content of your messages or calls. We do process the above.
3.1 Content. Message, call and file content is encrypted on your device and decrypted on the recipient's device. In normal operation it is not accessible to us, our hosting provider, or anyone intercepting the connection.
3.2 Metadata. Encryption does not hide the information in section 2.2 — that two accounts communicated, when, from what IP, on what device. Where we hold this, it may be subject to a lawful order (section 7).
3.3 Devices. Encryption protects data in transit and on our servers. It does not protect a device that is compromised, unlocked, backed up to a third-party service, or in someone else's hands.
3.4 Recipients. Anyone you communicate with can retain, screenshot, photograph or record what you send. The Service attempts to restrict screenshots and screen recording on supported platforms, but these measures can be defeated and are not a guarantee.
3.5 Local storage. Content and media may be stored on your device — application caches, media directories, notification previews — until removed by you or the operating system.
| Purpose | Basis (GDPR, where applicable) | Basis (DPDP Act) |
|---|---|---|
| Providing the Service, delivering messages and calls | Contract | Consent / legitimate use |
| Account security, fraud and abuse prevention | Legitimate interests | Legitimate use |
| Enforcing our Terms, including geographic and sanctions restrictions | Legitimate interests / legal obligation | Compliance with law |
| Responding to lawful orders and complaints | Legal obligation | Compliance with law |
| Service improvement and diagnostics | Legitimate interests | Consent |
| Service and security notices | Contract / legitimate interests | Legitimate use |
Where we rely on consent you may withdraw it at any time. Withdrawal does not affect prior processing, and withdrawing consent for essential processing may mean we cannot continue providing the Service.
| Data | Retention |
|---|---|
| Message and call content | Deleted automatically after 24 hours by default, or the shorter period you set. Undelivered messages deleted on expiry. |
| Account information | While your account is active |
| Registration records after account deletion | 180 days, as required by the Indian IT Rules 2021, then deleted |
| Connection, session and metadata logs | 365 days |
| Abuse reports and enforcement records | 365 days — to enforce our Terms and defend claims |
| Records subject to a legal obligation or preservation order | As required by law |
| Purchase records | As required by tax and accounting law |
The automatic deletion of message content after 24 hours does not delete your account records. Both operate on different data.
We do not sell, rent or trade your personal data.
6.1 Service providers (processors)
| Provider | Purpose | Data |
|---|---|---|
| OVH — data centre in Singapore | Server infrastructure and hosting | Infrastructure-level access to section 2 categories; communication content remains encrypted |
| Stripe | Payment processing for in-app purchases on Android | Payment card details are collected and processed by Stripe directly under its own privacy policy — we do not receive or store your full card number. We receive transaction records (amount, date, item, payment status). |
| Apple Push Notification Service / Google Firebase Cloud Messaging | Delivering push notifications | Push token, notification payload |
| Apple | In-app purchase processing on iOS | Purchase and platform account data, under Apple's own policies |
| Google Firebase — analytics and crash reporting | Crash reports, diagnostics and aggregated usage analytics | Device and app information (model, OS, app version), crash logs, diagnostic data and usage events — never the content of your communications |
| Google AdMob SDK | No ads are served. The SDK is present in the app but advertising is disabled — see section 13 | May initialise on launch and process device identifiers; see section 13 |
Each processor is bound to process data only on our instructions and to apply appropriate security measures.
6.2 Authorities. See section 7.
6.3 Corporate transactions. In a merger, acquisition or sale of assets, data may transfer to the acquiring entity subject to this policy or one no less protective. We will notify you.
Correction to our previous policy. An earlier version of this policy and our Terms stated that we do not share any user data with third parties. That statement was inaccurate — it did not account for the service providers above or for our obligations to respond to lawful orders. This section replaces it.
7.1 When we disclose. Where we receive a valid, binding legal order from a competent authority with jurisdiction over us, or where disclosure is necessary to comply with law, protect any person's safety, or investigate a breach of our Terms.
7.2 What we can produce. Subject to a valid order, subscriber and account information and metadata of the kinds described in section 2.2 and retained per section 5.
7.3 What we cannot produce. Because message and call content is end-to-end encrypted and we do not hold decryption keys, we are generally unable to produce the content of communications, even under a valid order, and we cannot retrospectively decrypt content already deleted.
We do not represent that we are able to resist a lawful order, and we do not represent that we hold no data.
7.4 Child safety. Content and conduct involving the sexual exploitation of children is reported to the relevant authorities and associated records preserved. This is not a matter of discretion.
7.5 Preservation. We may preserve records where required by law, on receipt of a preservation request from an authority, or where we reasonably believe preservation is necessary to investigate serious harm.
7.6 Notice to you. Where lawfully permitted, and where it would not prejudice an investigation or endanger a person, we will endeavour to notify you of a request for your data.
7.7 Law enforcement contact: admin@ninjapvtmsg.com
We operate globally, and our users are located around the world. Wherever you use the Service from:
These countries may have data protection laws that differ from those of your country. We apply the same protections to every user regardless of location: end-to-end encryption of communication content, encryption of data in transit, access controls, and contractual data protection commitments from our hosting and service providers.
By creating an account and using the Service, you consent to your data being transferred to and processed in the locations described above. Where the law of your country requires a specific legal basis or additional safeguards for international transfer, we rely on this consent together with the contractual safeguards described in this policy. If you do not agree to this transfer, please do not use the Service.
We implement technical and organisational measures appropriate to the risk, including end-to-end encryption of communication content, encryption in transit, access controls, and encryption at rest for certain stored fields.
No system is completely secure. We cannot guarantee the security of your data.
Breach notification. Where a personal data breach occurs we will notify the relevant supervisory authority — including the Data Protection Board of India and the Personal Information Protection Commission of Japan, as applicable — and affected users, within the timeframes required by applicable law.
Subject to applicable law and verification of your identity, you may:
Contact contact@ninjapvtmsg.com. We respond within the period required by applicable law and in any event without undue delay.
Supervisory authorities. You may complain to the Data Protection Board of India, the Personal Information Protection Commission (Japan), or your local data protection authority.
You may delete your account at any time in the app settings. On deletion:
Deletion is irreversible. Copies of messages already delivered to other users remain on their devices and are outside our control.
The Service is for users aged 18 and over. It is not directed to children and we do not knowingly collect personal data from anyone under 18.
If you believe a person under 18 has provided us with personal data, contact contact@ninjapvtmsg.com and we will delete the account and associated data. This reflects the requirements of the DPDP Act 2023 regarding children and equivalent provisions elsewhere.
We do not display advertising in the Service, and we do not share your data with advertisers.
For transparency: the app currently contains the Google AdMob software development kit (SDK), which is disabled — no advertisements are requested or shown. Because the SDK is present in the app, it may initialise when the app starts and process limited device information (such as device identifiers) in accordance with Google's privacy policy. We do not use this for advertising, and we are working to remove the SDK from a future version of the app.
If we ever enable advertising, we will update this policy before doing so and obtain your consent where required by applicable law. Advertising providers would never receive the content of your encrypted communications.
The Service may link to third-party sites or services. We are not responsible for their privacy practices. Review their policies before providing data.
We may update this policy. Where a change is material we will notify you in-app or via your registered contact details before it takes effect. The "Last updated" date always reflects the current version.
| Purpose | Contact |
|---|---|
| Privacy and data protection | contact@ninjapvtmsg.com |
| Grievance Officer (IT Rules 2021) | Amandeep Singh contact@ninjapvtmsg.com 3rd Floor, The Design Place, Plot no. A-28k, Phase 7, Industrial Area, Sector 73, Sahibzada Ajit Singh Nagar, Punjab 160055, India Acknowledgement within 24 hours; resolution within 15 days |
| Representative in Japan (APPI) | Not yet appointed — under review |
| Abuse and safety reports | admin@ninjapvtmsg.com |
| Law enforcement | admin@ninjapvtmsg.com |
Controller: Nexever Private Limited, 3rd Floor, The Design Place, Plot no. A-28k, Phase 7, Industrial Area, Sector 73, Sahibzada Ajit Singh Nagar, Punjab 160055, India