Privacy Policy

What Yamsio collects, why, where it is kept, who can see it, and your rights.

Last updated

On this page
  1. Who we are
  2. What we collect, and why
  3. Encryption, and who can see your content
  4. Who we share it with
  5. Where your data is processed
  6. How long we keep it
  7. Your rights
  8. How we keep it safe
  9. Children
  10. Changes to this policy
  11. Contact

In short

  • Your chats live on your phone. We keep an encrypted copy of what you send, and a copy of the keys that open it.
  • We open content only when the law requires it, and each time is approved by two people and recorded. When someone reports a message, their phone sends us what they report.
  • Calls are encrypted end to end. We never receive the sound or the picture.
  • We do not sell your data, show you advertising, or track you across other companies’ apps.
  • You can delete your account in the app at any time.

Who we are

Yamsio is run by Volkstech. In this policy, “we” and “us” mean Volkstech, and “you” means the person using Yamsio. We decide how your personal data is used, which makes us the data user under Malaysia’s Personal Data Protection Act 2010 (the PDPA).

Your Yamsio account is a Volkstech account. Volkstech runs one sign-in service for its apps, so the same account also opens our other apps, such as Kumpun. This policy covers Yamsio, and the sign-in service as Yamsio uses it.

You can reach our Data Protection Officer at support@volkstech.org.

What we collect, and why

Your account. Your email address, name and username, and — if you add them — a phone number and a password, which we store only in a form that cannot be turned back into the password. If you sign in with Apple or Google, the identifier they give us. We use these to create your account, sign you in and help you back in if you are locked out.

Your profile. The name, username, picture, cover picture and bio you choose, and your privacy settings: who may see when you were last online, whether you send read receipts, whether others see that you viewed their diaries. Your kens see your profile, and your settings decide what else they see.

Your kens. Who you became kens with and when, what they chose to share with you when you met, the names you give them, and the groups you sort them into. Yamsio lets you talk only with your kens, so it needs to know who they are.

What you send and post. The content of messages, photos, films, voice notes, files, reactions, posts, comments, diaries, guestbook entries and the words on your page is encrypted on your phone before it is sent (see Encryption). Beside it we keep, not encrypted: who sent it, to which conversation, when it was sent and received, the time zone and the device it was sent from, its type and size, a file’s name, whether it was edited or deleted, and who has received and read it. We use these to deliver what you send, show when it has been read, and keep an accurate record of what was sent, which we need to meet our legal obligations and answer lawful requests.

Your location, only if you turn it on. If you switch on Location in Settings, each message you send records where you were, to about 100 metres. It is kept with that message’s record, as evidence of where it was sent from. It is never shown to other people, Yamsio never uses your location in the background, and you can turn it off at any time.

Groups. A group’s name and picture are not encrypted: its members see them, and we store them as they were set. We also keep a history of who joined, left, was added or removed, and by whom.

Calls. Who called whom, when, for how long, how the call ended, whether it passed through a relay server, and whether someone announced they were recording it. Never the sound or the picture. We use this to ring the other phone, connect the call and show your call history.

Your devices and notifications. An identifier for each installation of Yamsio, its platform and app version, the push tokens Apple and Google issue so that we can notify you, which device is your trusted phone, and security events on your account, such as sign-ins, new devices and changes of trusted phone. We use these to send notifications, keep your account secure, and let only your trusted phone make important changes.

Activity. Whether you are online and when you were last seen, shown to others only as your settings allow. The days on which you opened Yamsio, with your phone’s platform, so that we can count how many people use Yamsio each day; we keep these for 400 days. How many times a song is played is counted without recording who played it.

Reports and blocks. When you report something, your phone sends us what you chose to report — the messages or items, opened on your phone — with your reason and any note. We store them encrypted, and only our moderation staff can open them. We also keep the list of people you have blocked. We use these to keep people safe on Yamsio.

When you contact us. Your email address and what you write. If you use the account deletion form on this website, your email address, and a check by Cloudflare Turnstile that a person, not a program, sent it.

Technical data. Cloudflare, which hosts Yamsio, processes your IP address and the details of each request to deliver and protect the service. Our own statistics about the service count requests by type, country and outcome, never by person.

This website sets no cookies of its own and has no advertising or analytics.

Encryption, and who can see your content

What you send is encrypted on your phone. Messages, photos, films, voice notes, files, reactions, posts, comments, diaries and the words on your page are encrypted on your phone before they leave it, with a key for each conversation, or for your Vuk. We store them encrypted.

We keep a copy of the keys. Yamsio holds a copy of those keys, itself locked with a key that only our servers hold. This means that we are able to open your messages. We do so only when the law requires it — for example, a court order or a valid request from the Malaysian authorities. Each such request is recorded as a case, must be approved by two senior people at Volkstech before anything is opened, and covers only the people, conversations and dates it names.

Reports. When someone in a conversation reports a message, their phone sends us the messages they chose. We do not use the keys to look at the rest of the conversation.

Every access is recorded. Each time our staff open reported content or export content for a legal request, it is written to a log that cannot be changed, with the person who did it and the reason.

What our staff see without opening anything. To run Yamsio and keep it safe, authorised staff can see account details such as your email, username and profile, your devices, and the records around your messages — who, when, how many and how large — but not what they say.

Calls are encrypted end to end between the phones. We never receive the sound or the picture, so we cannot record it or hand it over. When two phones cannot connect directly, the call passes through a Cloudflare relay, which forwards encrypted data it cannot read.

Notifications. When a notification carries a message, the words travel sealed and are opened on your phone; Apple or Google deliver it without being able to read them. The name of the person who wrote travels with it, unless you set previews to show nothing.

On your phone. Yamsio keeps your chats in an encrypted database on your phone. A backup you export is locked with a passphrase you choose, and we never receive it. When you link another screen, your phone sends it your chats through our servers, encrypted with a key that only those two devices share; each piece is deleted as soon as it is collected, and all of it within an hour.

Who we share it with

The people you choose. Your kens see your profile and what you share with them. The members of a conversation see its messages. Who sees your posts, diaries and galleries is up to you.

Companies that run parts of Yamsio for us, bound by contract to use your data only for that:

  • Cloudflare — hosting, the database, file storage, the call relay, and the check on this website’s forms;
  • Google (Firebase Cloud Messaging) — notifications on Android, and message notifications on iPhone;
  • Apple (Apple Push Notification service) — calls ringing on iPhone;
  • Apple and Google — sign-in, only if you choose to sign in with them.

Authorities, when the law requires it, as described under Encryption. We check that each request is lawful and give only what it covers.

A new owner. If Volkstech is reorganised or sold, your data may pass to the new owner, who must keep to this policy.

We do not sell your personal data, use it for advertising, or track you across other companies’ apps and websites.

Where your data is processed

Cloudflare runs a worldwide network, and Google and Apple run their notification services worldwide, so your data may be stored and processed outside Malaysia. We use these providers because they are bound by contract to protect it to a standard at least equal to the PDPA.

How long we keep it

WhatHow long
Messages, encrypted, and their recordsUp to 7 years after they were sent, and longer only while a legal case requires it
The copy of the keysAs long as the messages it opens
A message deleted for everyoneHidden from everyone at once. The encrypted copy is kept like any other message, up to 7 years
Photos, films and files sent in chatsKept encrypted. Deleting one removes it from every chat; the encrypted file stays in our storage
Call records, and who joined or left a groupUp to 7 years, with the conversation’s messages
Posts, comments, guestbook entries, your pageUntil you delete them. A deleted one is hidden at once; its encrypted words stay in our records
DiariesSeen by your kens for a day, then kept in your own archive until you delete them
Your profile, kens and settingsUntil you change them or delete your account
Days on which you used Yamsio400 days
Notification tokensUntil you sign out on that device or delete your account
What we hold to deliver to a device that was offline30 days
A file you started to send but did not finish24 hours
ReportsThe record of a report and its decision: kept. What was reported: 180 days after the decision, a year when it concerned a child’s safety
After you delete your accountSee Delete your account

Your rights

Under the PDPA, you can:

  • ask what personal data we hold about you, and for a copy of it;
  • correct it — most of it, such as your profile and settings, you can correct yourself in the app;
  • ask us to send your data to you or to another service;
  • withdraw your consent, or ask us to stop or limit how we use your data, where the law allows — though Yamsio cannot work without some of it;
  • delete your account, in the app or on our account deletion page.

Write to support@volkstech.org from the email address of your account. We reply within 21 days, and we do not charge for it. If you are not satisfied with our answer, you can complain to the Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi) at pdp.gov.my.

How we keep it safe

Encryption as described above; staff access limited by role and recorded; important changes to your account allowed only from your trusted phone. If a breach of your data is likely to cause you significant harm, we will tell you and the Personal Data Protection Commissioner as the PDPA requires.

Children

Yamsio is for people aged 16 and over. If we learn that an account belongs to someone younger, we close it. Our child safety standards explain how we protect children and how to report a concern.

Changes to this policy

When we change this policy, we publish the new version here with a new date. If a change matters to how your data is used, we tell you in the app before it applies.

Contact

Our Data Protection Officer: support@volkstech.org.