Legal & Trust Hub

The small print, said clearly.

Jurisdiction:
GlobalDPDP 2023DPDP Rules 2025GDPRCCPA

Privacy Policy

Last Updated: August 2, 2026
Effective Date: August 10, 2026
TL;DR: We encrypt your data so we cannot read it. We do not store your messages, calls, contacts, or location. We do not sell your data. We do not run ads. Privacy is the product.

1. Introduction & Data Fiduciary Identity

This Privacy Policy explains, in clear and plain language, how MyOnne Amora Private Limited ("we," "us," "our," or "MyOnne") processes your digital personal data when you use our application, website, and related services (collectively, the "Services"). We have written this notice to comply with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), as well as the General Data Protection Regulation ("GDPR") for EU users and the California Consumer Privacy Act ("CCPA") for California residents.

Under the DPDP Act, we are the Data Fiduciary. Under the GDPR, we are the Data Controller. Under the CCPA, we are the Business.

2. Definitions

  • Data Principal: You, the individual to whom the personal data relates (DPDP Act, Section 2(j)).
  • Data Fiduciary / Controller: MyOnne Amora Private Limited, the entity that determines the purpose and means of processing your personal data.
  • Personal Data: Any data about an individual who is identifiable by or in relation to such data (DPDP Act, Section 2(t)).
  • Processing: Any automated operation or set of operations performed on digital personal data, including collection, storage, use, and erasure (DPDP Act, Section 2(x)).
  • Consent: A free, specific, informed, unconditional, and unambiguous indication of your wishes, by which you agree to the processing of your personal data for a specified purpose (DPDP Act, Section 4).

3. What We Do NOT Collect or Store

Due to our Zero-Knowledge architecture, we strictly do not collect, store, access, or process the following data: at any point, for any reason:

  • Message Content: All text messages, voice notes, photos, videos, documents, and Vault items are End-to-End Encrypted (E2EE). We do not store message content on our servers in any readable form.
  • Call Audio & Video: Voice and video calls are peer-to-peer encrypted. We do not record, store, or have access to call audio or video content.
  • Contact Lists: We never ask for, upload, or access your phone's address book or contact list.
  • Precise Location Data: We do not track GPS coordinates, cell tower data, or any location metrics.
  • Advertising Identifiers: We use zero advertising SDKs, no ad tracking IDs (GAID/IDFA), and no cross-site or cross-app tracking.
  • Analytics Identifiers: We do not use client-side analytics that identify or profile individual users. We do not deploy pixels, fingerprinting scripts, or behavioural analytics tools.

When the purpose of any transient processing is complete (for example, routing an encrypted packet), the data is erased immediately. We do not retain any of the above data unless required by law.

4. What We Minimally Collect & Whether It Is Required or Optional

We process only what is strictly necessary to operate the service. Below is an exhaustive list:

DataPurposeRequired / OptionalRetention
Encrypted User IDAccount identification and authenticationRequiredUntil account deletion
Authentication TokensSecure session managementRequiredSession duration
Device Pairing FingerprintsPublic cryptographic keys to establish E2EE tunnel between you and your partnerRequiredUntil unpair or account deletion
Basic Delivery TelemetryConnection status to route encrypted packets (does not include message content)RequiredTransient: erased immediately after delivery
Crash ReportsFully anonymised, non-identifying diagnostic logs to fix bugsOptional (opt-in only)90 days, then permanently deleted

We do not collect or process any data beyond what is listed in this table. Every item in this table is limited to the specific purpose stated. We do not repurpose your data.

5. Purpose of Processing & Lawful Basis

We process your data solely to provide, secure, and improve the MyOnne service. We do not use your data for advertising, profiling, behavioural targeting, or any purpose unrelated to operating the service. The lawful bases for processing are:

  • DPDP Act (India): Your explicit consent (Section 6) and legitimate uses specified in Section 7 (e.g., performance of a contract, compliance with law).
  • GDPR (EU): Performance of a Contract (Art. 6(1)(b)), Legitimate Interests (Art. 6(1)(f)), and Consent (Art. 6(1)(a)) where applicable.
  • CCPA (California): Business purposes as defined under CCPA §1798.140(e).

Under the DPDP Act, consent must be free, specific, informed, unconditional, and unambiguous, and must be limited to what is necessary for the stated purpose. Here is how we handle consent:

  • How we obtain consent: When you create a MyOnne account, we present this Privacy Policy as a clear notice explaining what data we process, why, and your rights. You provide consent by explicitly accepting this notice during account creation.
  • What you consent to: Only the specific processing described in Section 4 (above) for the purposes described in Section 5 (above). Nothing more.
  • How you withdraw consent: You may withdraw your consent at any time, as easily as you gave it. To withdraw consent:
    • Open the app → Settings → Privacy → Withdraw Consent & Delete Account, or
    • Email dpo@myonne.com with the subject line "Consent Withdrawal."
  • Effect of withdrawal: Upon withdrawal of consent, we will erase all your personal data within 30 days, except where retention is required by law (see Section 8). Withdrawal does not affect the lawfulness of processing that occurred before you withdrew.

7. Data Storage & Security

All data at rest is encrypted using industry-standard encryption. To comply with Indian data localisation requirements, data for Indian users is stored exclusively in servers physically located within India. We employ multiple layers of security including encryption at rest and in transit, access controls, regular security audits, and incident response procedures.

Because of our Zero-Knowledge architecture, even in the unlikely event of a server compromise, your message content, call audio/video, contact lists, and location data cannot be accessed: we never had them.

8. Data Retention & Erasure

We follow a strict data minimisation and erasure policy:

  • Account metadata: Retained only while your account is active. Deleted within 30 days of account deletion or consent withdrawal.
  • Transient delivery data: Erased immediately once the encrypted packet is delivered or the connection is closed.
  • Crash reports (opt-in): Automatically deleted after 90 days.
  • On account deletion: When you initiate account deletion via Settings, all associated cryptographic keys are destroyed immediately, rendering any remaining encrypted blobs permanently inaccessible. The encrypted blobs are purged from our servers within 30 days.
  • Legal retention: In accordance with the DPDP Act, we retain data beyond the stated period only when necessary for compliance with a specific legal obligation (e.g., a court order). When that legal obligation ends, the data is erased.

9. Your Rights as Data Principal (DPDP Act: India)

Under Chapter III of the DPDP Act, 2023, you have the following rights:

  • Right to Access Information (Section 11): You may request a summary of your personal data being processed by us and the processing activities carried out.
  • Right to Correction & Erasure (Section 12): You may request correction of inaccurate or misleading personal data, completion of incomplete data, updating of data that is out of date, and erasure of data that is no longer necessary for the purpose for which it was processed.
  • Right to Grievance Redressal (Section 13): You have the right to file a complaint with our Grievance Officer and receive a response within 30 days. If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India.
  • Right to Nominate (Section 14): You may nominate an individual to exercise your rights under the DPDP Act in the event of your death or incapacity.

10. How to Exercise Your Rights

You can exercise your DPDP rights through any of the following mechanisms:

  • In-App: Open MyOnne → Settings → Privacy. From here you can:
    • View a summary of your data (Right to Access)
    • Request data correction (Right to Correction)
    • Delete your account and all associated data (Right to Erasure)
    • Withdraw consent (see Section 6)
    • Export a machine-readable archive of your account metadata (Data Portability)
  • By Email: Send your request to dpo@myonne.com. Include your registered User ID (visible in Settings) and the specific right you wish to exercise. We will verify your identity and respond within 30 days.
  • Nominate: To nominate someone to exercise your rights, email dpo@myonne.com with the nominee's full name and contact details.

11. GDPR-Specific Rights (for EU Users)

If you are in the European Economic Area, you have the right to:

  • Access (Art. 15)
  • Rectification (Art. 16)
  • Erasure / Right to be Forgotten (Art. 17)
  • Restriction of Processing (Art. 18)
  • Data Portability (Art. 20)
  • Object to Processing (Art. 21)
  • Lodge a complaint with your local Supervisory Authority (Art. 77)

12. CCPA Rights (for California Residents)

California residents have the right to know what personal information is collected, the right to delete, the right to correct, and the right to opt-out of the "sale" or "sharing" of personal information. We do not sell or share your personal information. We do not use your data for cross-context behavioural advertising.

13. Children's Privacy: 18+ Only

MyOnne is strictly for users aged 18 and above. We do not permit individuals under the age of 18 to create accounts. Under the DPDP Act (Section 9), a child is defined as any person under the age of 18. The Act requires verifiable parental consent before processing a child's personal data and prohibits tracking, behavioural monitoring, and targeted advertising directed at children.

Rather than implement a verifiable parental consent mechanism, we have chosen the simplest and strongest compliance posture: MyOnne does not allow users under 18. If we discover that a user is under 18, the account will be terminated immediately and all associated data will be erased.

14. Cross-Border Data Transfers

Data for Indian users is stored within India. If data must be transferred internationally (for example, for EU users whose data may be processed through our global infrastructure), such transfers are conducted subject to adequate safeguards, including Standard Contractual Clauses (SCCs) for EU transfers and compliance with any DPDP Act notifications regarding restricted territories as notified by the Central Government.

We will not transfer your personal data to any country or territory that has been restricted by the Central Government under the DPDP Act without your explicit consent and applicable legal safeguards.

15. Third-Party Services

We use essential third-party cloud infrastructure providers (e.g., AWS, GCP) bound by strict Data Processing Agreements (DPAs). These providers process encrypted data on our behalf and cannot access your message content, call audio/video, contacts, or location data: we do not let your data stay on our servers. Your data is secured on your own device.

We do not share your personal data with any third party for advertising, marketing, or profiling purposes.

16. Data Breach Notification

In the unlikely event of a personal data breach:

  • We will notify the Data Protection Board of India as required under the DPDP Act and DPDP Rules.
  • We will notify CERT-In (Indian Computer Emergency Response Team) within 6 hours as required by the CERT-In Directions, 2022.
  • For EU users, we will notify the relevant Supervisory Authority within 72 hours as required by GDPR Art. 33.
  • We will notify affected Data Principals (you) without undue delay, clearly describing the nature of the breach, the data involved, the measures we are taking, and the steps you can take to protect yourself.

Due to our Zero-Knowledge architecture, even in a breach scenario, your message content, call recordings, contacts, and location data cannot be compromised: we never held them.

17. Grievance Officer

In accordance with the DPDP Act, 2023 and DPDP Rules, 2025, we have appointed a Grievance Officer to address your concerns about data processing. You may contact the Grievance Officer for any questions about how we process your data, to exercise your rights, or to lodge a complaint:

  • Name: Souvik Maiti, Grievance Officer & Data Protection Officer
  • Email: dpo@myonne.com
  • Response Period: We will acknowledge your grievance within 48 hours and provide a resolution within 30 days of receipt.
  • Escalation: If you are not satisfied with our response, you have the right to file a complaint with the Data Protection Board of India established under the DPDP Act.

18. Changes to This Policy

We may update this Privacy Policy from time to time. When we make significant changes, we will:

  • Update the "Last Updated" and "Effective Date" at the top of this page.
  • Notify you via an in-app notice at least 7 days before the changes take effect.
  • Where the changes materially affect your consent, we will seek fresh consent before continuing to process your data under the updated terms.

19. Contact Information

MyOnne Amora Private Limited
8, Sri Ramulavari Street, kandadu, Tirupati district, Andhra Pradesh, 517619.

General Enquiries: support@myonne.com
Data Protection / Grievance Officer: dpo@myonne.com
Legal: dpo@myonne.com
Trust & Safety / Abuse Reports: report@myonne.com