iMembers PRIVACY POLICY
SECTION 1. GENERAL PROVISIONS AND APPLICABLE LEGISLATION
This Policy has been developed in accordance with:
- the Law of the Republic of Kazakhstan of 21.05.2013 No. 94-V "On Personal Data and Its Protection" (hereinafter — the Law on PD of the RK);
- the Law of the RK of 10.06.1996 No. 6-I "On Copyright and Related Rights";
- the EU General Data Protection Regulation (GDPR, Regulation 2016/679) — for users from the European Union;
- the California Consumer Privacy Act (CCPA) — for users from the State of California, USA.
Controller (rights holder): Nazerke Saktapbergenova, an individual — an entrepreneurial activity entity in accordance with the legislation of the Republic of Kazakhstan.
SECTION 2. WHAT DATA WE COLLECT AND WHY
2.1. Account data
Upon registration and use of the application, we process:
- Email address — for creating an account, authentication, and communication with the user;
- Password hash — the password is never stored in unencrypted form; bcrypt is used. Recovery of the password in unencrypted form is technically impossible;
- PIN code hash — the PIN is converted into a hash on the device; the server stores only the hash;
- Name (if provided via Apple/Google sign-in), date of registration, date of last sign-in, application version, and platform (iOS / Android).
2.2. Capsule data
The body of a message and the media files of a capsule are encrypted on the device (end-to-end encryption) and transmitted to the server only in encrypted form — the server has no access to their content. The following are processed:
- Encrypted content: text, voice and video recordings, photo and document attachments (PDF and other files) — all as ciphertext;
- Capsule metadata (service data, in open form): name (title), type, date of creation, date and condition of opening, lock status, sender and recipient(s), technical information about attachments (quantity, category/type, size — without access to the content). Do not place confidential information in the name of a capsule;
- Access parameters: for a legacy capsule (Legacy) — the recipient's email, without passport or other documentary data.
2.3. Settings and synchronization
- Theme (Aurora / Dark) and interface language;
- Subscription status and plan (Free / Pro / LifeTime);
- Local notifications about capsule events — enabled by default, generated on the device (no data is sent to the server for local notifications); can be disabled in the app settings;
- Local privacy settings (lock via Face ID / PIN) — stored on the device.
2.4. Technical data
- IP address when accessing the server (in logs — no more than 90 days);
- OS version and device model (for diagnostics);
- Session identifier (for managing sign-ins and tokens).
Processing summary
- Account (email, password/PIN hash) — authentication and access; stored until the account is deleted; basis — contract (Art. 6(1)(b) GDPR).
- Capsules (encrypted content + metadata) — core function; until deletion by the user; basis — contract / consent.
- Settings (theme, language, plan) — synchronization between devices; until the account is deleted; basis — contract.
- Technical (IP, device, sessions) — security and diagnostics; IP — 90 days; basis — legitimate interest.
- Payment (transaction status via Apple/Google) — plan activation; 5 years (tax accounting); basis — legal obligation.
- Contacts (names/emails/phone numbers, added manually or imported from the device when finding friends) — stored only on your device; retained until you delete them, delete the account, or use the panic button; not affected by logging out. When finding friends, the email addresses of the selected contacts are sent to the server transiently only to match registered iMembers users and are NOT stored on the server; basis — consent.
SECTION 3. CROSS-BORDER DATA TRANSFER
The iMembers servers are located outside the Republic of Kazakhstan — in Germany (the European Union). The cloud provider: Hetzner Online GmbH. By using the application, you expressly consent to the cross-border transfer of data in accordance with Art. 22 of the Law on PD of the RK.
Germany (the EU) ensures an adequate level of personal data protection. For users from the EU, processing is governed by the GDPR; transfer outside the EEA, where applicable, is carried out on the basis of standard contractual clauses (SCC).
SECTION 4. DATA SECURITY
4.1. Encryption in transit
- All exchange between the application and the server takes place over TLS 1.2 / 1.3 (HTTPS); unencrypted connections are rejected.
4.2. End-to-end encryption of content
- The body of a message and the media files of capsules are encrypted on the device before sending using the libsodium library (XChaCha20-Poly1305); the key of each capsule is transmitted to the recipient in an X25519 sealed-box, and integrity is confirmed by an Ed25519 signature. The server stores only ciphertext and has NO access to the content.
- Metadata (name, time and condition of opening, participants) is processed in open form and is NOT protected by end-to-end encryption.
- The backup of the encryption keys is protected by the user's passphrase (Argon2id) and is not transmitted to the server in unencrypted form.
- If you lose the passphrase for your key backup, all previously encrypted capsules become permanently inaccessible. The Company has no technical ability to recover their content, including upon a lawful court request. Resetting end-to-end encryption in settings destroys the keys — access to previously encrypted capsules is lost forever.
- The databases and media storage on the server side are additionally encrypted by the provider's means (at-rest).
4.3. Access management and authenticity
- Authentication on the server is via JWT tokens with a limited validity period (access — minutes, refresh — days).
- Access to the server database is restricted on the principle of least privilege; suspicious activity (multiple failed sign-ins) is restricted automatically.
- The authenticity of the other party is confirmed by a "safety number" (TOFU pinning of the public key) — you can verify it in person.
SECTION 5. TRANSFER OF DATA TO THIRD PARTIES
We do not sell your personal data and do not transfer it to third parties for commercial purposes. Transfer is possible only in the following cases:
- Apple Inc. / Google LLC — purchase (subscription) status; payment processing via the App Store / Google Play under their own policies;
- The server's cloud provider (Hetzner Online GmbH) — storage of encrypted data; acts as a data processor;
- Government authorities — upon a lawful request from a court or an authorized body in accordance with legislation;
- A business successor — upon a sale or restructuring, with prior notice to users.
SECTION 6. USERS' RIGHTS
6.1. Rights under the legislation of the RK (Law on PD, Art. 8)
- The right of access — to receive information about the composition and purposes of the processing of your data;
- The right to rectification — to demand the correction of inaccurate data;
- The right to erasure — to delete your account and all associated data from the server (see Section 7);
- The right to withdraw consent — to withdraw consent to the processing of data;
- The right to complain — to apply to the authorized body for the protection of personal data of the RK.
6.2. Additional rights for users in the EU (GDPR, Art. 15–21)
- The right to data portability — to receive your data in a machine-readable format;
- The right to restriction of processing;
- The right to object to processing on the basis of legitimate interest.
To exercise your rights, write to support@imembers.app. The response period is 15 business days (Law on PD of the RK) / 30 calendar days (GDPR).
SECTION 7. ACCOUNT AND DATA DELETION
You can delete your account at any time via Settings → Account. Upon deletion:
- all capsules and media files are deleted from the server within 30 days;
- the password and PIN code hashes are deleted immediately;
- the email is retained in anonymized form in the audit log for 90 days, after which it is destroyed;
- payment data is retained for 5 years in accordance with tax legislation.
Account deletion is irreversible. The contents of capsules cannot be restored after deletion. Upon account deletion, the encryption keys are destroyed and cannot be recovered.
SECTION 8. CHILDREN
The application is not intended for persons under 13 years of age (under 16 years of age — in EU countries). If we become aware that a child's data was obtained without parental consent, we will delete it immediately.
SECTION 9. DATA BREACH NOTIFICATION
In the event of a security incident affecting users' personal data, we undertake to:
- notify the affected users by email within 72 hours of detection (GDPR, Art. 33–34);
- notify the authorized data protection body in accordance with applicable legislation;
- take measures to remedy the consequences and prevent recurring incidents.
SECTION 10. CHANGES TO THE POLICY
We have the right to update this Policy. The current version is posted in the application and on the imembers.app website. We notify you of material changes (affecting the composition of data or the purposes of processing) by email no less than 14 days before they take effect.
SECTION 11. CONTACT INFORMATION
- Data controller: Nazerke Saktapbergenova, an individual.
- Jurisdiction: the Republic of Kazakhstan.
- Email for all matters concerning personal data and the exercise of your rights: support@imembers.app.
- Response period: 15 business days (RK) / 30 calendar days (GDPR).
Contact email
support@imembers.app