Privacy Policy — Veceira
1) Who we are
Veceira is provided by Saifullah Ahad ("we", "us", "our"). Questions, safety concerns, and privacy requests may be sent to www.saifullah.ai@gmail.com. Our website is saifullah.ai.
2) What Veceira does
Veceira provides a personal timestamped trip record and an invite-only family workflow for allocating indivisible duties among 2–8 accepted members. There is no public directory, public profile, public feed, or chat.
3) Information kept only on your device
- Personal trip records: what you did, who it was for, start and end time, duration, and an optional note. These records are not uploaded.
- Your selected answer sentence: the chosen sentence position is retained locally so the app can create required protocol shares. The service receives encrypted signals and proofs, not that plaintext position.
- Security and preferences: an App PIN salt and one-way hash, biometric-lock preference, limited-preview setting, theme, reduced-motion choice, and sync metadata. Android performs biometric matching; Veceira does not receive biometric templates.
- Cryptographic material: installation signing keys, the device-held strict-majority threshold share used for group counts, and any unused single-slot invite secrets created on this device. Invite secrets are never uploaded.
4) Information processed for group features
- Membership: group name, member-chosen display names, random group/member identifiers, invite lookup identifiers, join requests and approvals, join order, active status, signing public keys, threshold public material, sealed key shares, and standing. The service never receives an invite secret or a hash/verifier of it.
- Shared duties: duty title, who it is for, due time, proposed and median weight, state, creator, assigned member, completion/confirmation/dispute state, settlement, and server timestamps.
- Sealed allocation: encrypted acceptance vectors, zero-knowledge proofs, aggregate ciphertexts, aggregate counts, valid threshold decryption shares, clearing-boundary relations, and payload digests.
- Safety: contextual reports, reported duty/member references, a content digest and context, block relationships, review status, and report time.
- Service security: a random session nonce, idempotency identifiers, rate-limit counters, revoked-session records, and a Firebase registration token used for data wake-ups.
Veceira does not ask for an email address, phone number, legal name, postal address, contacts, location, photo, video, audio, calendar, financial information, health information, advertising ID, or social login.
5) What other group members can learn
Accepted members see the group and duty text, display names, group events, assignment, confirmations, and standing changes. After allocation, the group learns the clearing sentence, who is going, and that everyone else answered at or above that sentence—nothing more. The service never receives or stores anyone’s plaintext private sentence. In a two-person group, either person can infer the other person’s answer from the clearing count; larger groups require a strict majority of key shares.
Duty text and member names are not end-to-end encrypted from the service. Do not place secrets or sensitive personal information in a duty title, recipient field, member name, or group name.
6) Why information is used
- Create and maintain an invite-only family group.
- Validate sealed answers, count acceptances, allocate a duty, and settle confirmed turns exactly once.
- Synchronise devices, preserve server-authoritative deadlines, and retry queued changes.
- Deliver data wake-ups and keep the group current while its screen is open.
- Review reports, apply blocks, prevent abuse and replay, protect users, and meet legal safety duties.
7) Service providers and disclosure
- Cloudflare Workers, Durable Objects, D1, and KV operate the API, group coordinator, database, rate limits, and service logs. Cloudflare may process standard connection details such as IP addresses for delivery and security.
- Firebase Cloud Messaging processes an app-instance registration token and routing metadata to wake a device for group changes. Veceira uses data messages, not advertising notifications.
- Accepted group members receive the shared content and protocol result described above.
We do not sell personal information. Veceira includes no advertising or behavioural-analytics SDK. We may preserve or disclose narrowly necessary information when required by law or to address fraud, abuse, security incidents, threats, or child-safety concerns.
8) Security and retention
Network traffic uses HTTPS or WSS. Each member place has an independent invite secret with at least 128 bits of secure randomness. A slow PBKDF2-HMAC-SHA256 derivation seals its key share, and the service stores no value that can verify guesses for that secret. Existing-member approval, signed sessions, cryptographic proofs, replay protection, per-invite rate limits, and server timestamps protect group operations. Share private invite links only with their intended family members.
Personal trip records remain on the device until you delete them, clear app storage, or uninstall. The service mints exactly the configured number of sealed shares and permanently deletes every unused share when invitations close. A departing member’s sealed share is deleted rather than returned to the invite pool, and the cryptographic group is archived. A successful in-app cloud deletion also removes the member’s encrypted answers, decryption shares, clearing reveals, reports, blocks, push token, display name, and public key; redacts that name from history; and removes text from duties created by that member. An inactive placeholder and non-personal audit structure may remain so conserved group history and anti-replay protections continue. A revoked session nonce may remain for up to 90 days. Provider security logs follow the provider’s operational retention.
9) Your controls and deletion
- Delete any personal trip or all personal trips inside the app.
- Leave a group; remaining standing is redistributed exactly and the departure is recorded.
- Use Settings and safety → Delete group account and cloud data, then tap again to confirm.
- Report a duty or member and block another accepted member from the duty record.
- Disable the optional App PIN, biometric lock, preview limit, dark theme, or reduced motion at any time.
Account and data deletion instructions
Child Safety Standards
10) Children’s privacy and safety
Veceira is a general family coordination utility and is not directed to children under 13 or the equivalent minimum age in a jurisdiction. A family organiser should invite only people they know. Child sexual abuse and exploitation, grooming, solicitation, sexualised content involving minors, and any use that endangers a child are prohibited. Use the contextual in-app report control or email the child-safety contact. See the complete standards linked above.
11) International processing, changes, and contact
Cloud services may process information outside your country. We may update this policy when Veceira’s practices or legal obligations change; the current effective date will remain at this URL.
Saifullah Ahad
Email: www.saifullah.ai@gmail.com
Website: https://saifullah.ai
Location: Dhaka, Bangladesh