Privacy policy
Hiroq is operated by Intraverse Software Ltd. Contact dev@hiroq.app about privacy or your data. Last updated: 11 September 2026.
What we process
When you enroll, we store your chosen display name (a nickname is fine), a generated device identifier, public key and a hash of your device credential. We store pairings, invitation expiry information, blocking choices and, on iPhone, the push token and push environment needed for background reception. We use these records to authenticate your phone and connect only authorized contacts.
The communication server processes connection information, including IP addresses and session identifiers, to route and troubleshoot connections. We do not use location permissions or create a location history. If you submit a safety report, we store the text you choose to send, your device identifier, the reported device identifier and submission time. If you email us, our email service processes your email address and message.
Voice and encryption
Live voice and application control messages use end-to-end encryption between paired phones. Private conversation keys stay on those phones and are shared in the private pairing code. Our server does not record or transcribe conversations. Connection metadata, display names and push-notification metadata are not end-to-end encrypted. A recipient can hear and independently record speech; Hiroq cannot prevent that.
Service providers and hosting
The default Hiroq backend and LiveKit media service are self-hosted in the United Kingdom. Apple processes Push to Talk notifications, including the sender display name and channel identifiers. Apple and Google distribute the apps and may process store diagnostics according to their own policies and your device settings. Apple iCloud Mail hosts dev@hiroq.app and processes support correspondence, including your email address and message. We do not include advertising or tracking SDKs, sell personal data or use speech to train AI.
If you choose a different self-hosted server, its operator also controls the records sent to it. Obtain that operator’s privacy terms before enrolling or changing servers. The app warns before sending credentials to a different server.
Permissions and your choices
Microphone access is used to transmit speech. Camera access is used to scan a pairing code; you can paste a code instead. Bluetooth access enables headset routing on Android. Network access connects your phone to the service; on iPhone, local-network access is relevant only to locally hosted servers. An active Android conversation uses a visible foreground notification with a Leave action. You can leave a conversation or revoke permissions in system Settings.
Retention and deletion
Device and pairing records remain until you remove the pairing or delete the device identity. Blocking records remain until unblocked or an involved device identity is deleted. Used or expired pairing invitations are periodically removed. Safety reports are retained for up to 30 days unless removed sooner by device-data deletion. Operational logs are limited by configured rotation and used for service reliability and security; they do not contain speech or pairing secrets.
Use Privacy, safety and help → Delete my Hiroq data to delete this phone’s live server records and local credentials. This ends its conversations. A restricted deletion/blocking ledger retains the identifiers needed to honor these requests across restoration for seven days. Routine server backups are restricted to administrators and expire after seven days; restoration must honor subsequent deletion requests before the service returns online. Copies already held by other people, such as an independently saved pairing code or recording, cannot be remotely erased. Old pairing codes no longer authorize a deleted channel.
Your rights and requests
You can request access, correction or deletion, and raise a privacy concern at dev@hiroq.app. See data deletion for the process without the app. We verify control of the relevant identity before acting; never send your credential or pairing code. Where applicable, you may complain to your local data-protection authority, including the UK Information Commissioner’s Office.
Young users
Hiroq is intended for people aged 13 and older, not children under 13. If local law requires parental permission for a young person’s use or data processing, obtain that permission before enrolling. Contact us if you believe an under-13 child has enrolled so we can investigate and remove the records.