Privacy Policy
camdown, by Koadi Technology LLC. Last updated 6 September 2026.
camdown is a messaging and calling app. It is built so that the people running the service cannot read what you send. This page describes exactly what reaches our servers, what we keep, and for how long.
What we cannot see
Your messages, your attachments, your calls and any status post you share with your friends are end-to-end encrypted. They are encrypted on your device and can only be decrypted on the device of the person you sent them to. We hold no key that opens them. This is not a policy choice we could quietly reverse: there is no copy of your keys on our servers to begin with.
The one exception: a post you make public
When you post a status you choose who it is for. The default is your friends, and that post is encrypted as described above. You can instead choose to post it publicly, which shows it to everyone on camdown under your username.
A public post is not end-to-end encrypted. It cannot be. Its audience includes people you have never met and people who have not joined yet, so there is nobody to encrypt it for. A public post is stored on our servers in readable form, exactly like a profile photo, and we are able to read it. Anyone signed in to camdown can see it, save it, and keep their copy after yours has expired.
Nothing becomes public by accident. It is a choice you make on the post itself, every time, and the app says so before you post. If you would rather this never happened, simply never choose it: everything else on camdown stays encrypted whatever you do here.
What we store
| Data | Why | Kept for |
|---|---|---|
| A one-way cryptographic hash of your phone number | To recognise your account at sign-in and to stop one number registering endlessly. We do not store the number itself. | Until you delete your account |
| Your username, display name, "about" text and profile photo | So people you talk to can identify you. Your profile photo is not end-to-end encrypted; anyone allowed to see your profile can see it. | Until you change or delete it |
| Your public encryption keys | So other people can start an encrypted conversation with you. Public halves only; private keys never leave your device. | Until you delete your account |
| Undelivered messages, as encrypted blobs we cannot read | To hold a message until the recipient's phone comes online | Deleted on delivery, or after 30 days |
| Status posts shared with friends, as encrypted blobs | Same | 24 hours, then deleted |
| Status posts you chose to make public, in readable form | There is no audience to encrypt a public post for, so it is stored the way a profile photo is. We can read it and so can anyone signed in. | 24 hours, then deleted |
| Likes on public posts | To show a count, and to tell the author who liked their post | Until the post expires |
| Call records: who called whom, when, and for how long | To connect the call and show it in your call list, and so that abuse can be looked into. We never record call content. | 90 days |
| A device token from Apple or Google | To wake your phone for a new message or an incoming call | Until you sign the device out |
| Sign-in session records | To keep you signed in and let you sign a device out | Until expiry or sign-out |
| Reports you submit about another user | To review abuse. A report includes the text you chose to send us, in readable form. | While the report is under review |
What we do not do
- No advertising, and no advertising identifiers.
- No analytics or tracking SDKs. There is no third-party analytics in the app.
- We do not sell or share your data with anyone for their own purposes.
- We do not store your contacts. If you let the app check which of your contacts already use camdown, the numbers are hashed, matched, and discarded. Nothing is kept.
- We do not keep your phone number. Only a hash of it.
Who else is involved
Three companies process data on our behalf, and only as much as their job needs:
- ClickSend and Resend deliver the one-time code by text message when you sign in. They see your phone number and the code.
- Apple and Google deliver push notifications. They see a device token and the fact that a notification was sent, never its contents.
- Hetzner hosts our servers in Germany.
Calls
Calls try to connect your two devices directly. When a network makes that impossible, the encrypted audio and video is bounced through a relay server we operate. The relay forwards encrypted packets and cannot decrypt them.
Your choices
- Private username. Set your username to private and nobody can find you by searching. You are reachable only by an invitation you issue.
- Blocking. Blocking someone stops all messages and calls in both directions and deletes anything of theirs still queued for you.
- Delete your account. Settings, then Delete account. This removes your profile, your keys, your queued messages, your status posts and your media from our servers. Messages already delivered to another person's phone are on their phone and we cannot reach them.
Children
camdown is not directed at children under 13, and we do not knowingly create accounts for them.
Security
Everything travels over TLS, and the message content inside it is separately
encrypted end to end. The technical description of the protocol is published in
the project's SECURITY.md. The encryption has not yet been reviewed
by an independent auditor, and we say so rather than implying otherwise.
Changes
If this policy changes in a way that affects what we collect, the app will tell you before the change takes effect.
Contact
Koadi Technology LLC, 44 Country Club Rd Apt 99, Eatontown, New Jersey 07724, United States. Questions, requests for your data, or complaints: support@koaditech.com.