Privacy Policy

Last Updated: November 24, 2025

Welcome to Smoke ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, store, and protect your data when you use the Smoke mobile application (the "App").

Key Privacy Principles

  • We collect minimal personal information
  • Your messages are end-to-end encrypted
  • We never sell your data to third parties
  • You control your data and can delete your account at any time

Information We Collect

1. Account Information

When you create an account, we collect:

We DO NOT Collect

  • Email addresses
  • Phone numbers
  • Real names (unless you choose to use one as your display name)
  • Payment information
  • Social media accounts

2. Messages and Content

3. Friend Connections

4. Device Information

5. Technical Information

We automatically collect certain technical information:

How We Use Your Information

Primary Services

  1. Account Creation & Authentication: To create and authenticate your account
  2. Message Delivery: To deliver encrypted messages between you and your friends
  3. Push Notifications: To notify you of new messages, friend requests, and other app events
  4. Friend Management: To enable you to add, accept, and manage friend connections
  5. Screenshot Alerts: To notify senders when recipients take screenshots or screen recordings

Security & Improvements

  1. Fraud Prevention: To detect and prevent abuse, spam, and malicious activity
  2. Bug Fixes: To identify and fix technical issues
  3. App Improvements: To understand how the app is used and improve features

Data Storage and Security

Encryption

Data Storage

We use Google Firebase to store and process your data:

Security Measures: All data is stored in secure Google Cloud data centers with industry-standard security measures including encryption at rest, encrypted data transmission (HTTPS/TLS), regular security audits, and access controls.

Data Retention

Data Sharing and Third Parties

We DO NOT

  • Sell your personal information to advertisers or data brokers
  • Share your messages with third parties (we can't - they're encrypted!)
  • Use your data for advertising purposes
  • Share your data with social media companies
  • Provide your data to government agencies except when required by law

Third-Party Services We Use

Google Firebase (Google LLC)

Purpose: Cloud infrastructure, database, storage, authentication, push notifications

Data Shared: User profiles, encrypted messages, friend connections, device tokens

Privacy Policy: firebase.google.com/support/privacy

Apple Push Notification Service (Apple Inc.)

Purpose: Delivering push notifications on iOS devices

Data Shared: Device push token, notification content

Privacy Policy: apple.com/legal/privacy

Your Privacy Rights

Access Your Data

You can view all your account information within the app:

Profile → Settings → View your username, display name, and account details

Delete Your Account

You can permanently delete your account and all associated data:

  1. Go to Profile → Settings
  2. Tap "Delete Account"
  3. Confirm deletion

What Gets Deleted

  • Your username and display name
  • Your public encryption key
  • All your encrypted messages
  • All your friend connections
  • Your push notification tokens
  • Your account recovery codes

What Happens After Deletion

  • Your friends will no longer see you in their friend list
  • All messages you sent will become unreadable (encryption keys are destroyed)
  • This action is permanent and cannot be undone

Account Recovery

Data Portability

Currently, we do not offer a data export feature. If you would like a copy of your data, please contact us at support@chiseltheory.com.

Children's Privacy

The Smoke app is not intended for children under the age of 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal information from children under 13.

If we discover that we have inadvertently collected information from a child under 13, we will delete that information immediately.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support@chiseltheory.com.

International Data Transfers

Your data may be transferred to and stored in countries other than your country of residence, including the United States, where Google Firebase servers are located.

These countries may have different data protection laws than your country. However, we take steps to ensure your data receives an adequate level of protection in accordance with this Privacy Policy and applicable laws.

By using Smoke, you consent to the transfer of your information to the United States and other countries where we or our service providers operate.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

How we notify you:

We encourage you to review this Privacy Policy periodically.

Security Measures

We implement industry-standard security measures to protect your data:

Technical Measures

Operational Measures

Your Security Responsibilities

Please note: No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.

California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  1. Right to Know: You can request information about the personal data we collect, use, and share
  2. Right to Delete: You can request deletion of your personal data (with certain exceptions)
  3. Right to Opt-Out: We do not sell personal information, so there is nothing to opt-out of
  4. Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights

To exercise these rights, contact us at support@chiseltheory.com.

European Privacy Rights (GDPR)

If you are in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR):

Legal Basis for Processing

We process your data based on:

Your GDPR Rights

  1. Right of Access: Request a copy of your personal data
  2. Right to Rectification: Request correction of inaccurate data
  3. Right to Erasure: Request deletion of your data ("right to be forgotten")
  4. Right to Restrict Processing: Request limitation on how we use your data
  5. Right to Data Portability: Request transfer of your data to another service
  6. Right to Object: Object to our processing of your data
  7. Right to Withdraw Consent: Withdraw consent at any time

To exercise these rights, contact us at support@chiseltheory.com.

You also have the right to lodge a complaint with your local data protection authority.

Data Breach Notification

In the event of a data breach that affects your personal information, we will:

  1. Notify affected users within 72 hours of discovering the breach
  2. Describe the nature of the breach and data affected
  3. Provide guidance on steps you can take to protect yourself
  4. Notify relevant regulatory authorities as required by law

We continuously monitor our systems for potential security incidents.

Technical Details for Transparency

For technically-minded users, here are the specific details of our encryption and security implementation:

Encryption Specification

  • Algorithm: X25519 key exchange + XSalsa20 stream cipher + Poly1305 MAC (libsodium)
  • Key Size: 256-bit keys
  • Key Generation: Cryptographically secure random number generator (SecRandomCopyBytes)
  • Key Storage: iOS Keychain with kSecAttrAccessibleWhenUnlockedThisDeviceOnly

Authentication

  • Method: Firebase Anonymous Authentication
  • Session Management: Firebase Auth tokens with automatic refresh
  • No Password: Your account is tied to your device's encryption keys

Message Lifecycle

  1. Message encrypted on sender's device using recipient's public key
  2. Encrypted message sent to Firebase Cloud Firestore
  3. Push notification sent to recipient via Firebase Cloud Messaging
  4. Recipient decrypts message using their private key (stored in Keychain)
  5. Message automatically deleted after 48 hours

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

support@chiseltheory.com

We aim to respond to all privacy inquiries within 30 days.

Consent

By creating an account and using the Smoke app, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.

If you do not agree with this Privacy Policy, please do not use the Smoke app.