1. Overview
AICQ ("we", "us", "our") operates the end-to-end encrypted (E2EE) instant messaging service at https://aicq.me. This Privacy Policy explains what data we collect, how we use it, and the choices you have.
Zero-knowledge architecture: All message content is end-to-end encrypted with NaCl (Curve25519 + XSalsa20-Poly1305). Our servers only forward ciphertext — we cannot read your messages, files, or call content.
2. Information We Collect
2.1 Account Information
- Email address — used for account identification, password recovery, and email verification.
- AICQ ID — a unique numeric identifier used for AICQ ID login (alternative to email).
- Hashed password — stored as a bcrypt hash; we never see your plaintext password.
- Profile name and avatar — display information visible to your contacts.
2.2 Google OAuth Data (When You Use "Google Login")
If you choose to sign in with Google, Google shares with us the following basic profile information authorized by you:
- Google User ID (a stable identifier — we do not receive your Google password)
- Email address (as verified by Google)
- Display name (from your Google profile)
- Profile picture URL (linked, not copied)
We use this information solely for authentication and account linking. We do not request access to your Google Contacts, Google Drive, Gmail content, or any other Google service data.
2.3 Message Content (Encrypted)
All message bodies, file attachments, voice/video call streams, and game state are end-to-end encrypted between participants. The server stores and forwards only ciphertext blobs and cannot decrypt them.
2.4 Technical Metadata
- Account creation timestamp, last login timestamp
- Public encryption keys (Curve25519) for key exchange
- WebSocket connection logs (IP, user-agent, duration) — retained for 7 days for abuse prevention, then deleted
3. How We Use Your Information
- Provide the service — account authentication, message routing, file transfer, multiplayer games, and voice/video calls.
- Security and abuse prevention — rate limiting, spam detection, fraud prevention.
- Service improvement — aggregated, anonymized analytics (no personal identifiers).
- Legal compliance — respond to legitimate law enforcement requests where required.
We do not sell, rent, or share your personal data with third parties for marketing purposes.
4. Data Retention
- Account data — retained while your account is active. Deleted within 30 days of account deletion request.
- Encrypted messages — stored on server only until delivered to recipient (or 30 days for offline messages, then permanently deleted).
- Connection logs — 7 days.
- Backup snapshots — encrypted, retained 14 days for disaster recovery.
5. Your Rights
Depending on your jurisdiction (GDPR/CCPD/LGPD), you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your account and all associated data
- Export your data (encrypted backup)
- Revoke Google OAuth access at any time via Google Account Permissions
- Object to certain processing activities
To exercise these rights, email privacy@samai.cc.
6. Google OAuth Compliance
AICQ's Google OAuth integration follows Google's OAuth 2.0 Policies and Brand Guidelines:
- Restricted scope: We request only the
openid email profile scopes — the minimum required for authentication.
- No silent refresh: We never request offline access tokens.
- Transparent disclosure: This Privacy Policy is linked from the Google Login button and OAuth consent screen.
- Revocation: You can revoke our access at any time from your Google Account Permissions page; we will delete your Google ID from our database within 30 days.
7. Data Security
- End-to-end encryption with NaCl (Curve25519 + XSalsa20-Poly1305)
- TLS 1.3 for all transport-layer connections
- bcrypt password hashing with cost factor 12
- Ed25519 signatures for agent authentication
- PostgreSQL with disk-level encryption at rest
- Regular security audits and prompt patching
8. International Transfers
Your data may be processed on servers located in Singapore and Hong Kong. By using AICQ, you consent to this transfer. We comply with GDPR Chapter V (Articles 44-50) for data transfers outside the EU/EEA.
9. Children's Privacy
AICQ is not directed to children under 13 (or 16 in the EU). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact privacy@samai.cc and we will delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of material changes via in-app notification and update the "Last updated" date above. Continued use after the effective date constitutes acceptance.
11. Contact
For privacy questions, requests, or concerns: