Privacy Policy
Last Updated: March 24, 2026
This Privacy Policy explains how MessagingFox ("we," "our," or "us") collects, uses, shares, and protects your personal data when you use our messaging application and related services across web and mobile platforms. It applies to users worldwide, with specific provisions for users in the European Union/EEA (GDPR), the United States, and India (DPDP Act 2023).
1. Who We Are (Data Controller)
MessagingFox is the data controller responsible for your personal information.
Contact us at:
- Email: contact@messagingfox.com
- Data Protection Officer (DPO): dpo@messagingfox.com
- Address: MessagingFox, Second Floor, Yamuna Arcade, Kallai Rd opposite to Whiteline Hotel, Palayam, Kozhikode, Kerala 673004
- EU Representative (GDPR Art. 27): [EU Rep Name & Address]
2. Data We Collect
2.1 Account Information
- Full name and username
- Email address and/or phone number
- Profile photo (optional)
- Password (stored in hashed/encrypted form)
2.2 Message & Communication Data
- Messages, files, images, and media you send or receive
- Message metadata: timestamps, delivery status, read receipts
- Group membership and contact lists
2.3 Device & Technical Data
- IP address and approximate location
- Device type, operating system, and app version
- Browser type (for web users)
- Crash logs and diagnostic data
2.4 Usage Data
- Features accessed and session duration
- Notification preferences
- In-app actions and interaction patterns
2.5 Payment Information (if applicable)
- Billing name and address
- Payment method (processed by third-party payment provider — we do not store full card numbers)
3. How We Use Your Data
We process your personal data based on the following legal grounds:
3.1 Contract Performance (GDPR Art. 6(1)(b))
- To create and manage your account
- To deliver and sync messages across devices
- To provide customer support
- To process payments for premium features
3.2 Legitimate Interests (GDPR Art. 6(1)(f))
- To detect and prevent fraud, spam, and abuse
- To improve service security and reliability
- To analyze usage trends and improve the product
- To enforce our Terms of Service
3.3 Consent (GDPR Art. 6(1)(a))
- To send you marketing emails and promotional updates (opt-in only)
- To use non-essential cookies and analytics trackers on our website
- To send push notifications
You may withdraw consent at any time via Settings > Notifications or by emailing us.
3.4 Legal Obligation (GDPR Art. 6(1)(c))
- To comply with applicable laws, court orders, or regulatory requests
- To retain certain records as required by financial or tax regulations
4. Data Retention
We retain your data only for as long as necessary:
- Account data: retained while your account is active, deleted within 30 days of account closure
- Messages: deleted from our servers 30 days after account deletion (end-to-end encrypted messages may only exist on your device)
- Usage/analytics logs: retained for up to 12 months
- Payment records: retained for 7 years for legal compliance
- Backup data: purged within 90 days of deletion request
5. Data Sharing & Third Parties
We do not sell your personal data. We share data only in limited circumstances:
5.1 Service Providers
- Cloud infrastructure: [e.g., AWS / Google Cloud]
- Analytics: [e.g., Firebase Analytics, Mixpanel]
- Customer support: [e.g., Intercom, Zendesk]
- Payment processing: [e.g., Stripe, Razorpay]
- Push notifications: [e.g., Firebase Cloud Messaging, APNs]
5.2 Legal Requirements
We may disclose your data when required by law, regulation, legal process, or enforceable governmental request.
5.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred. We will notify you via email or in-app notice before your data is transferred and becomes subject to a different privacy policy.
6. International Data Transfers
Your data may be transferred to and processed in countries other than your own. For transfers from the EU/EEA, we use:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
For transfers involving Indian users, we comply with the Digital Personal Data Protection (DPDP) Act, 2023.
7. Your Rights
7.1 Rights for All Users
- Access: Request a copy of your personal data
- Correction: Update inaccurate or incomplete data
- Deletion: Request deletion of your account and associated data
- Portability: Download your data in a machine-readable format (JSON/CSV)
- Opt-out: Unsubscribe from marketing communications at any time
7.2 Additional Rights for EU/EEA Users (GDPR)
- Right to restrict processing
- Right to object to processing based on legitimate interests
- Right not to be subject to solely automated decision-making
To exercise these rights, go to Settings > Privacy > My Data, or email contact@messagingfox.com. We will respond within 30 days (GDPR: 1 month).
7.3 Rights for California Users (CCPA/CPRA)
- Right to know what personal information is collected and how it is used
- Right to delete personal information
- Right to opt-out of sale or sharing of personal information (we do not sell data)
- Right to non-discrimination for exercising privacy rights
To submit a California privacy request, email contact@messagingfox.com with the subject: 'CCPA Request'.
7.4 Rights for Indian Users (DPDP Act 2023)
- Right to access information about processed data
- Right to correction and erasure
- Right to grievance redressal
- Right to nominate another person to exercise rights on your behalf
8. Cookies & Tracking (Web)
Our web application uses cookies and similar tracking technologies:
- Essential cookies: Required for login sessions and security (cannot be disabled)
- Analytics cookies: Help us understand how users interact with MessagingFox (opt-in)
- Marketing cookies: Used to serve relevant ads or promotions (opt-in)
You can manage cookie preferences via our Cookie Settings banner on first visit, or at any time in Settings > Privacy > Cookie Preferences.
9. Children's Privacy
MessagingFox is not directed to children under the age of 13 (or 16 for users in the EU/EEA, or as required by local law). We do not knowingly collect personal data from minors. If you believe a child has provided us with personal information, please contact us at contact@messagingfox.com and we will delete it promptly.
10. Security
We implement appropriate technical and organizational measures to protect your data, including:
- TLS/SSL encryption for all data in transit
- Encryption at rest for stored data
- End-to-end encryption for messages (where enabled)
- Access controls and regular security audits
- Incident response procedures
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours (as required by GDPR) and affected users without undue delay.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Sending an email to your registered address
- Displaying a prominent notice in the app
- Updating the 'Last Updated' date at the top of this page
Continued use of MessagingFox after changes take effect constitutes acceptance of the revised policy.
12. Contact Us & Complaints
For any privacy-related questions or to exercise your rights:
- Email: contact@messagingfox.com
- DPO: dpo@messagingfox.com
- Response time: within 30 days
EU/EEA users have the right to lodge a complaint with their local Data Protection Authority (DPA). A full list of EU DPAs is available at: https://edpb.europa.eu
Indian users may contact the Data Protection Board of India once operational.
