Privacy Policy - Nirokh

Effective date: 31 August 2026

No call recordingAudio is never saved or uploaded.
No advertisingNo advertising or analytics SDK is included.
In-app deletionKeys and routing data can be deleted from More.

1) What Nirokh does

Nirokh is provided by Saifullah Ahad. It lets people build a trusted circle by pairing phones face to face, then exchange an expiring cryptographically signed Yes or No presence check during a suspicious live voice call. It also provides a saved-number callback action.

2) Data Nirokh handles

To provide pairing and live verification, Nirokh sends the following to its protocol service:

Nirokh does not send contact names, phone numbers, call audio, call content, camera images, private cryptographic keys, the local display name, App PIN, or proof-history notes to the protocol service.

The display name, one callback contact selected through Android's single-contact picker, paired public identity, and up to 100 proof-history results are kept in encrypted app storage on the device. The App PIN is stored only as a salted SHA-256 hash with a random 16-byte salt. The plain PIN is never stored.

3) Camera, notifications, and phone access

4) How data is used

Protocol data is used only to register a device's public identity and push route, prove reciprocal pairing, route signed verification messages between paired devices, deliver verified trusted-circle warnings, evaluate session evidence, prevent abuse, and fulfill deletion or unpairing requests. Nirokh does not build advertising profiles, sell data, use data for cross-app tracking, or analyze call content.

5) Service providers and sharing

No feedback is sent until you press Send. Nirokh includes no advertising, analytics, social-media, or crash-reporting SDK.

6) Retention and deletion

Verification envelopes are retained for no more than 24 hours so the service can deliver results and enforce daily abuse limits, then deleted automatically. Active public-key records, push tokens, and pairing edges remain while the device identity is active.

Choose More → Delete Nirokh identity → Delete permanently to remove the phone's local keys, pairing, callback contact, proof history, and App Lock material and to immediately erase its server-side public keys, push token, verification sessions, and pairing edges. The service retains only a minimal opaque deleted-device tombstone for up to 30 days to prevent accidental resurrection and complete cleanup; it contains no public key, push token, relationship, contact detail, or message. Uninstalling without first using in-app deletion removes local data but cannot notify the server, so use the in-app control first.

7) Security boundaries

Transport uses HTTPS. On Android 9 and 10, the required Ed25519 and X25519 private seeds are encrypted with an AES-256-GCM key generated by Android Keystore; Nirokh describes this accurately as KEYSTORE_WRAPPED, not as native non-exportable Ed25519/X25519. This release has no production Green path: a valid signed Yes is Amber because it does not prove the familiar voice is on the exact live channel.

8) Children

Nirokh is intended for adults and is not directed to children under 13. It has no public profile, chat, feed, discovery, or user-generated-content feature. If you believe a child provided personal information through optional feedback, contact us so it can be removed.

9) International processing

Cloudflare, Google Firebase, and Web3Forms may process technical data in countries other than yours. Data is limited to what is described here and protected in transit.

10) Changes

This policy may change when Nirokh's behavior or legal requirements change. The current version will remain at https://privacy.saifullah.ai/nirokh.html with a revised effective date.

11) Contact

Saifullah Ahad
Email: www.saifullah.ai@gmail.com
Website: https://saifullah.ai
Phone: +880 1711-134346
Location: Dhaka, Bangladesh