In short
- Your chats live on your phone. We keep an encrypted copy of what you send, and a copy of the keys that open it.
- We open content only when the law requires it, and each time is approved by two people and recorded. When someone reports a message, their phone sends us what they report.
- Calls are encrypted end to end. We never receive the sound or the picture.
- We do not sell your data, show you advertising, or track you across other companies’ apps.
- You can delete your account in the app at any time.
Who we are
Yamsio is run by Volkstech. In this policy, “we” and “us” mean Volkstech, and “you” means the person using Yamsio. We decide how your personal data is used, which makes us the data user under Malaysia’s Personal Data Protection Act 2010 (the PDPA).
Your Yamsio account is a Volkstech account. Volkstech runs one sign-in service for its apps, so the same account also opens our other apps, such as Kumpun. This policy covers Yamsio, and the sign-in service as Yamsio uses it.
You can reach our Data Protection Officer at support@volkstech.org.
What we collect, and why
Your account. Your email address, name and username, and — if you add them — a phone number and a password, which we store only in a form that cannot be turned back into the password. If you sign in with Apple or Google, the identifier they give us. We use these to create your account, sign you in and help you back in if you are locked out.
Your profile. The name, username, picture, cover picture and bio you choose, and your privacy settings: who may see when you were last online, whether you send read receipts, whether others see that you viewed their diaries. Your kens see your profile, and your settings decide what else they see.
Your kens. Who you became kens with and when, what they chose to share with you when you met, the names you give them, and the groups you sort them into. Yamsio lets you talk only with your kens, so it needs to know who they are.
What you send and post. The content of messages, photos, films, voice notes, files, reactions, posts, comments, diaries, guestbook entries and the words on your page is encrypted on your phone before it is sent (see Encryption). Beside it we keep, not encrypted: who sent it, to which conversation, when it was sent and received, the time zone and the device it was sent from, its type and size, a file’s name, whether it was edited or deleted, and who has received and read it. We use these to deliver what you send, show when it has been read, and keep an accurate record of what was sent, which we need to meet our legal obligations and answer lawful requests.
Your location, only if you turn it on. If you switch on Location in Settings, each message you send records where you were, to about 100 metres. It is kept with that message’s record, as evidence of where it was sent from. It is never shown to other people, Yamsio never uses your location in the background, and you can turn it off at any time.
Groups. A group’s name and picture are not encrypted: its members see them, and we store them as they were set. We also keep a history of who joined, left, was added or removed, and by whom.
Calls. Who called whom, when, for how long, how the call ended, whether it passed through a relay server, and whether someone announced they were recording it. Never the sound or the picture. We use this to ring the other phone, connect the call and show your call history.
Your devices and notifications. An identifier for each installation of Yamsio, its platform and app version, the push tokens Apple and Google issue so that we can notify you, which device is your trusted phone, and security events on your account, such as sign-ins, new devices and changes of trusted phone. We use these to send notifications, keep your account secure, and let only your trusted phone make important changes.
Activity. Whether you are online and when you were last seen, shown to others only as your settings allow. The days on which you opened Yamsio, with your phone’s platform, so that we can count how many people use Yamsio each day; we keep these for 400 days. How many times a song is played is counted without recording who played it.
Reports and blocks. When you report something, your phone sends us what you chose to report — the messages or items, opened on your phone — with your reason and any note. We store them encrypted, and only our moderation staff can open them. We also keep the list of people you have blocked. We use these to keep people safe on Yamsio.
When you contact us. Your email address and what you write. If you use the account deletion form on this website, your email address, and a check by Cloudflare Turnstile that a person, not a program, sent it.
Technical data. Cloudflare, which hosts Yamsio, processes your IP address and the details of each request to deliver and protect the service. Our own statistics about the service count requests by type, country and outcome, never by person.
This website sets no cookies of its own and has no advertising or analytics.
Encryption, and who can see your content
What you send is encrypted on your phone. Messages, photos, films, voice notes, files, reactions, posts, comments, diaries and the words on your page are encrypted on your phone before they leave it, with a key for each conversation, or for your Vuk. We store them encrypted.
We keep a copy of the keys. Yamsio holds a copy of those keys, itself locked with a key that only our servers hold. This means that we are able to open your messages. We do so only when the law requires it — for example, a court order or a valid request from the Malaysian authorities. Each such request is recorded as a case, must be approved by two senior people at Volkstech before anything is opened, and covers only the people, conversations and dates it names.
Reports. When someone in a conversation reports a message, their phone sends us the messages they chose. We do not use the keys to look at the rest of the conversation.
Every access is recorded. Each time our staff open reported content or export content for a legal request, it is written to a log that cannot be changed, with the person who did it and the reason.
What our staff see without opening anything. To run Yamsio and keep it safe, authorised staff can see account details such as your email, username and profile, your devices, and the records around your messages — who, when, how many and how large — but not what they say.
Calls are encrypted end to end between the phones. We never receive the sound or the picture, so we cannot record it or hand it over. When two phones cannot connect directly, the call passes through a Cloudflare relay, which forwards encrypted data it cannot read.
Notifications. When a notification carries a message, the words travel sealed and are opened on your phone; Apple or Google deliver it without being able to read them. The name of the person who wrote travels with it, unless you set previews to show nothing.
On your phone. Yamsio keeps your chats in an encrypted database on your phone. A backup you export is locked with a passphrase you choose, and we never receive it. When you link another screen, your phone sends it your chats through our servers, encrypted with a key that only those two devices share; each piece is deleted as soon as it is collected, and all of it within an hour.
Who we share it with
The people you choose. Your kens see your profile and what you share with them. The members of a conversation see its messages. Who sees your posts, diaries and galleries is up to you.
Companies that run parts of Yamsio for us, bound by contract to use your data only for that:
- Cloudflare — hosting, the database, file storage, the call relay, and the check on this website’s forms;
- Google (Firebase Cloud Messaging) — notifications on Android, and message notifications on iPhone;
- Apple (Apple Push Notification service) — calls ringing on iPhone;
- Apple and Google — sign-in, only if you choose to sign in with them.
Authorities, when the law requires it, as described under Encryption. We check that each request is lawful and give only what it covers.
A new owner. If Volkstech is reorganised or sold, your data may pass to the new owner, who must keep to this policy.
We do not sell your personal data, use it for advertising, or track you across other companies’ apps and websites.
Where your data is processed
Cloudflare runs a worldwide network, and Google and Apple run their notification services worldwide, so your data may be stored and processed outside Malaysia. We use these providers because they are bound by contract to protect it to a standard at least equal to the PDPA.
How long we keep it
| What | How long |
|---|---|
| Messages, encrypted, and their records | Up to 7 years after they were sent, and longer only while a legal case requires it |
| The copy of the keys | As long as the messages it opens |
| A message deleted for everyone | Hidden from everyone at once. The encrypted copy is kept like any other message, up to 7 years |
| Photos, films and files sent in chats | Kept encrypted. Deleting one removes it from every chat; the encrypted file stays in our storage |
| Call records, and who joined or left a group | Up to 7 years, with the conversation’s messages |
| Posts, comments, guestbook entries, your page | Until you delete them. A deleted one is hidden at once; its encrypted words stay in our records |
| Diaries | Seen by your kens for a day, then kept in your own archive until you delete them |
| Your profile, kens and settings | Until you change them or delete your account |
| Days on which you used Yamsio | 400 days |
| Notification tokens | Until you sign out on that device or delete your account |
| What we hold to deliver to a device that was offline | 30 days |
| A file you started to send but did not finish | 24 hours |
| Reports | The record of a report and its decision: kept. What was reported: 180 days after the decision, a year when it concerned a child’s safety |
| After you delete your account | See Delete your account |
Your rights
Under the PDPA, you can:
- ask what personal data we hold about you, and for a copy of it;
- correct it — most of it, such as your profile and settings, you can correct yourself in the app;
- ask us to send your data to you or to another service;
- withdraw your consent, or ask us to stop or limit how we use your data, where the law allows — though Yamsio cannot work without some of it;
- delete your account, in the app or on our account deletion page.
Write to support@volkstech.org from the email address of your account. We reply within 21 days, and we do not charge for it. If you are not satisfied with our answer, you can complain to the Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi) at pdp.gov.my.
How we keep it safe
Encryption as described above; staff access limited by role and recorded; important changes to your account allowed only from your trusted phone. If a breach of your data is likely to cause you significant harm, we will tell you and the Personal Data Protection Commissioner as the PDPA requires.
Children
Yamsio is for people aged 16 and over. If we learn that an account belongs to someone younger, we close it. Our child safety standards explain how we protect children and how to report a concern.
Changes to this policy
When we change this policy, we publish the new version here with a new date. If a change matters to how your data is used, we tell you in the app before it applies.
Contact
Our Data Protection Officer: support@volkstech.org.