Skip to content
QuietLink 静联
Privacy Policy Terms of Service 中文

QuietLink Privacy Policy

Version: 1.1.0

Published: 23 August 2026

Effective: 23 August 2026

QuietLink (also known in Chinese as “静联”, the “Service”) respects your privacy. This Policy explains how we collect, use, store, disclose, transfer, protect and delete personal data and how you may exercise your rights.

Please read this Policy before registering for or using the Service. Where consent or separate consent is legally required, we will request it through an appropriate process. If you decline information necessary for a core function, we may be unable to provide that function. Declining optional information or permissions will not affect unrelated features.

Summary: Message plaintext, attachment contents and attachment keys are end-to-end encrypted on user devices and are not stored by the server in readable form. To provide accounts, security, relationships, groups, delivery, calls, notifications, public content and operations, we still process account and device information, relationships, routing metadata, ciphertext, public posts and security records. End-to-end encryption does not hide all metadata and cannot eliminate risks from compromised endpoints, screenshots, recipient forwarding or implementation defects.

1. Controller and Scope

  1. Operator and data controller: IDEASPHERE PTE. LTD.
  2. UEN: 202609984N
  3. Registered address: 421 CHOA CHU KANG AVENUE 4, #02-230, KEAT HONG LAUREL, SINGAPORE 680421
  4. Website: https://website.52dly.com/
  5. Customer support, complaints and Data Protection Officer (“DPO”): admin@ideasphereapac.com

This Policy applies to the QuietLink client, server and directly related administration, support and operational functions. Third-party websites, applications, operating systems, app stores or providers that independently determine their purposes and means of processing apply their own privacy rules.

2. Sources of Personal Data

We may obtain personal data:

  1. directly from you when you register, configure a profile, publish content, submit feedback or use features;
  2. automatically from your device during login, synchronisation, calls, notifications or security checks;
  3. from friends, group members or other users when they interact with you; and
  4. from Apple, network providers and infrastructure providers for notifications, connectivity and security operations.

3. Personal Data We Process

3.1 Account and Authentication Data

  • username, display name, avatar colour and an avatar you upload;
  • irreversible password hash;
  • security-question identifiers and separately salted answer hashes; and
  • account creation time, account status and login-session status.

Purposes: account creation and management, authentication, profile display, password or device recovery, deletion and security controls.

The Service currently uses username-and-password registration and does not verify identity using a mobile number or government-issued identification. We may withhold registration, communications or public-posting features in a territory until mandatory identity-verification requirements are satisfied.

3.2 Device, Network and Security Data

  • device identifier, name, type, model, X25519 public key, creation time and last-online time;
  • login attempts, device approvals, password changes and other security events;
  • IP address, network connection information and, in administration contexts, browser or client identifiers; and
  • SHA-256 refresh-token hash, session validity and revocation status.

Purposes: multi-device access, trusted-device approval, session management, anomaly detection, abuse prevention and security auditing. Device encryption private keys remain only on the device and are not uploaded to the server.

3.3 Friends, Groups and Relationships

  • friend requests, contact relationships and invitation status;
  • group name, members, roles, nicknames, membership applications, notices and retention settings; and
  • conversation identifier, membership, read time and related service state.

Purposes: establishing relationships and groups, access control, and synchronising conversations and delivery state.

3.4 Social Posts and Other Public Content

  • text, images, attachments, publication time, selected audience, interactions and associated account identifier; and
  • screenshots, content copies, timestamps, reasons and supporting information voluntarily submitted by a complainant.

Purposes: displaying and managing public content, enforcing audience settings, handling complaints, protecting rights and complying with law. Public content is shown to other users according to the audience you choose. Do not publish personal or sensitive data that you are not authorised to disclose.

3.5 Nearby Features and Location Data

When you actively use a location-based feature such as Nearby and grant system permission, we may process device-provided coordinates, accuracy and time, or an approximate region inferred from IP, to calculate nearby results, prevent abuse and maintain security.

You may withdraw location permission in system settings. Nearby may then stop working, but unrelated functions are unaffected. The feature screen and system notice describe precision, background use and retention. The Service should not continuously collect precise location when you are not using a relevant feature.

3.6 End-to-End Encrypted Communications and Routing Metadata

  • encrypted message envelopes, including protocol version, sending and receiving device-key identifiers, nonce, ciphertext and authentication tag;
  • sender, conversation, receiving device, logical message identifier, delivery sequence, creation time, edit and recall state; and
  • encrypted attachment object, ciphertext size, declared content type, conversation and access relationship.

Purposes: routing, storing, retrying, synchronising, editing, recalling and deleting ciphertext. The server does not hold message or attachment decryption keys.

The server can still know accounts, relationships, conversation membership, devices, communication times, ciphertext sizes, delivery states and network information, but cannot use those items alone to directly read end-to-end encrypted plaintext.

3.7 Voice Messages and Calls

  • participant and conversation identifiers, call time and state;
  • SDP/ICE signalling required to establish WebRTC calls;
  • temporary online and mute state for group calls; and
  • country or region code derived from the public IP for TURN selection.

Voice media ordinarily travels between participating devices using WebRTC DTLS-SRTP. Where required by network conditions, a TURN service in Hong Kong relays encrypted media. We do not record voice calls. A country or region code used for TURN selection is ordinarily used only for that connection and is not persistently linked to the account.

3.8 Push and Notification Data

  • APNs device token and device-notification relationship;
  • choices concerning background messages, incoming calls, security notices and notification previews; and
  • minimised notification data required for delivery.

Purposes: delivery of messages, calls and security notices through Apple Push Notification service (“APNs”). We design notification payloads to avoid end-to-end encrypted message plaintext. Foreground sounds and vibration preferences are stored locally.

3.9 Points and Virtual-Item Data

  • points balance, cards, cosmetic items, saved items and virtual-item state;
  • point earning, gifting, redemption, store spending and card-trade records; and
  • virtual-item acquisition time, validity and usage state.

Purposes: calculating point balances, providing virtual items, carrying out redemptions and card trades, preventing fraud and handling related disputes. The current version does not support cash top-ups, real-money purchases or Apple in-app purchases. Points and cards cannot be withdrawn, redeemed for cash or traded for real money.

3.10 Feedback, Complaints and Support

When you submit feedback, a report or an account appeal, we process its category and explanation, voluntary contact details, account or content identifier, necessary public-content snapshot, handling state, outcome and support notes. For a report concerning an end-to-end encrypted message, the app submits the message identifier, sender and conversation identifier by default and does not automatically upload message plaintext.

Purposes: responding to enquiries, handling reports, diagnosing issues, improving the product, responding to security incidents and keeping necessary service records. Do not submit passwords, security-question answers, device private keys or unrelated message plaintext.

To prevent harassment and abuse, we also process the identifiers of the blocking and blocked accounts, the block time and any reason voluntarily provided. Public display names, social posts and comments may be matched against operator-configured rules so that publication is rejected or queued for human review; this filtering does not apply to end-to-end encrypted private-message plaintext.

3.11 System Permissions

The Service may request:

  • Camera: QR scanning, taking or sending images;
  • Photos or files: selecting attachments, sending files or saving content you choose to download;
  • Microphone: recording voice messages or making voice calls;
  • Notifications: messages, calls and security alerts;
  • Location: Nearby and related location features; and
  • Network: connecting to servers, synchronising ciphertext and establishing calls.

The operating system manages permissions. You may withdraw them in system settings. The relevant feature may then stop working, but unrelated functions are unaffected.

4. Purposes and Legal Bases

We process personal data only for reasonable and necessary purposes described to you, including:

  1. creating, authenticating and managing accounts and performing our contract with you;
  2. establishing relationships and groups and routing, synchronising and retaining ciphertext;
  3. providing social posts, Nearby, QR scanning, calls, notifications, points and virtual items;
  4. protecting accounts, devices, networks and the Service and preventing fraud, attacks and abuse;
  5. responding to support, complaints, deletion and privacy-rights requests;
  6. complying with law, app-store requirements and lawful requests from competent authorities; and
  7. other clearly disclosed purposes with your consent.

Legal bases may include performance of our contract with you, consent or separate consent, legal obligations, protection of legitimate interests, and other grounds permitted by applicable law. We do not sell personal data, use end-to-end encrypted communication plaintext for advertising profiles, or conduct automated marketing based on private communications.

5. Local Storage and End-to-End Encryption

  1. The native client generates an account-specific local data key and stores it in the system Keychain/Keystore. Message payloads are encrypted using AES-256-GCM before storage in the local database; the data key is not stored with the database.
  2. The native client may cache attachment ciphertext in an account-isolated manner. Decrypted media is ordinarily handled only as needed for the feature. Content you choose to save to Photos or Files is managed by you and the operating system.
  3. Conversation-open passwords, attachment-preview password hashes and foreground preferences remain on the device and are not uploaded.
  4. The web version does not currently promise encrypted offline message persistence. The device system, screenshots, downloads, backups or malware may access content after you decrypt and view it.
  5. When you actively log out or delete the account, the client follows product rules to clear the corresponding local ciphertext, pending queue, synchronisation cursor, attachment ciphertext cache and local data key.

6. Retention and Deletion

  1. We retain account, device, relationship, group, public-content, points and virtual-item data while the account is active and as necessary to provide the relevant functions.
  2. Refresh sessions ordinarily remain valid for up to thirty (30) days and rotate when used. Account deletion, sign-out from all devices or security action revokes relevant sessions.
  3. Message ciphertext and encrypted attachments follow conversation retention settings, which ordinarily include 1 day, 7 days, 30 days or continuous retention, subject to actual configuration. Scheduled deletion may have a short processing delay.
  4. Location data is ordinarily processed only while needed for a nearby feature. If security or abuse prevention requires a record, we restrict retention to the shortest necessary period.
  5. Security, audit, feedback and complaint records are retained for the shortest period necessary for security, compliance and disputes, ordinarily no longer than one hundred eighty (180) days, unless law requires otherwise or a dispute remains unresolved.
  6. Points and virtual-item records are retained while the account is active and the relevant functions are provided. Records concerning fraud investigations or disputes are retained for the shortest necessary period.
  7. When account deletion takes effect, we immediately disable the account and revoke login sessions and delete or anonymise associated personal data within a reasonably necessary period. Exceptions apply to data required by law or needed for security incidents, fraud investigations, transaction disputes or protection of legal rights. Such data is restricted and deleted or anonymised once the purpose ends.
  8. Local deletion affects only the current device. Recall or server retention deletion cannot erase content already saved, downloaded, captured or copied by another recipient.

We do not retain personal data indefinitely merely for an uncertain future use. When a purpose no longer exists and there is no business or legal need, we cease retention or remove identifiability.

7. Disclosure, Processors and Public Sharing

  1. We do not sell personal data or provide it to advertisers or data brokers.
  2. To provide hosting, storage, notifications, network relay, security and technical support, we may engage Hong Kong infrastructure providers, Apple and other necessary providers to process a minimum amount of information. We use contracts, access controls, encryption and least-privilege requirements to limit processing and require protection no less than this Policy and applicable law.
  3. Depending on the feature, friends, group members, the audience of social posts, Nearby participants and call participants may see your display name, avatar, public content, group information, interaction information or approximate nearby status.
  4. If a merger, restructuring, asset transfer or similar event transfers personal data, we will notify users as required and require the recipient to continue this Policy or provide equivalent protection. A material change in purpose or means will trigger renewed consent where required.
  5. We publicly disclose personal data only with consent, where you choose to make it public, or as permitted by law. For lawful requests by competent authorities, we verify authority and process and provide only what is legally required and technically available. Because of end-to-end encryption, we generally cannot provide private-communication plaintext or device private keys.
  6. We do not currently integrate advertising, behavioural analytics or third-party crash analytics SDKs. If that changes, we will update this Policy and app-store privacy declarations and obtain consent where required.

8. International Transfers and Overseas Processing

  1. Production servers, databases, attachment storage and TURN services are located in Hong Kong; the controller is in Singapore; and Apple provides APNs. Information may therefore be processed or transferred among Hong Kong, Singapore and locations where Apple or its providers operate for accounts, communications, support, security, purchases and notifications.
  2. We conduct reasonable diligence on overseas providers and use contractual and security measures and data minimisation to require a level of protection comparable to the Singapore Personal Data Protection Act (“PDPA”).
  3. If the Service is directed to users in mainland China and personal data collected or generated there is provided to Hong Kong, Singapore or another overseas territory, we will, before enabling the relevant service, complete any applicable security assessment, certification, standard contract or other required process, notify users of the overseas recipient, contact details, purposes, means, categories and rights procedure, and obtain separate consent where required.
  4. We may withhold registration, communications, Nearby, social posting, purchases or other relevant features in a territory until its international-transfer requirements have been satisfied.

9. Your Rights and Choices

Subject to applicable law, you may:

  1. request access to personal data we hold about you and information about its use or disclosure during the applicable period;
  2. request correction or completion of inaccurate or incomplete data;
  3. delete local messages and manage trusted devices, notifications, permissions and conversation retention;
  4. withdraw consent, without affecting the lawfulness of earlier processing, while recognising that the relevant function may no longer be available;
  5. request deletion, anonymisation, restriction of processing or account deletion;
  6. request an explanation of this Policy or a specific processing activity; and
  7. complain about our response and lodge a complaint with a competent regulator.

Some rights can be exercised in app settings. Account deletion can be initiated through “Me — Settings — Account Security — Delete Account” and may require the password, security-question answers or other account information. Other requests may be sent to admin@ideasphereapac.com.

To protect accounts and others, we may request reasonable identity verification. Where permitted by law, we may restrict or refuse requests that would reveal another person’s data, obstruct an investigation, breach legal obligations or are manifestly unreasonable, and explain our decision. We ordinarily provide an initial response within seven (7) business days and complete the request within the period required by applicable law.

10. Minors

  1. The Service is available only to users who are at least fourteen (14) and is not directed to children.
  2. Users under eighteen (18), or under the independent age of consent where they live, may use the Service only after a parent or legal guardian has reviewed and agreed to this Policy and the Terms of Service.
  3. A child under fourteen (14) must not register or use the Service. If we discover that we may have processed data of a child under fourteen contrary to this Policy, we will suspend the account, investigate and delete the data or take other legally required action.
  4. A guardian may contact admin@ideasphereapac.com to request access to or deletion of a minor’s data or to submit a complaint.

11. Security and Encryption Limitations

  1. Measures include password hashing, session rotation, trusted-device approval, end-to-end encryption, transport protection, access control, administrator separation, audit records, rate limiting and retention cleanup.
  2. The design uses X25519, HKDF-SHA256 and AES-256-GCM. Device private keys are not uploaded.
  3. The design has not completed an independent audit and does not fully implement Double Ratchet, MLS, key transparency or independently audited safety-number verification. It does not therefore provide forward-secrecy and post-compromise recovery assurances equivalent to mature audited protocols.
  4. Encryption cannot prevent endpoint compromise, screenshots, recording, recipient saving or forwarding, weak passwords, malware, social engineering, metadata exposure or implementation defects.
  5. If personal data is leaked, altered or lost, we assess the impact, take remedial measures and notify affected users and regulators where applicable law requires.

12. Changes to This Policy

We may update this Policy when law, features, purposes, data categories, recipients, deployment locations or security architecture change. We will give prominent notice of material changes affecting user rights through in-app announcements, pop-ups, release notices or other appropriate means. Where renewed or separate consent is required, we will obtain it.

Previous versions and effective dates should remain available through the website or the in-app legal-documents page.

13. Contact and Complaints

For questions concerning this Policy, personal data, account deletion, security incidents or minors, contact:

  • Company: IDEASPHERE PTE. LTD.
  • UEN: 202609984N
  • Address: 421 CHOA CHU KANG AVENUE 4, #02-230, KEAT HONG LAUREL, SINGAPORE 680421
  • Website: https://website.52dly.com/
  • Customer support, complaints and DPO: admin@ideasphereapac.com

Do not submit passwords, security-question answers, device private keys or unrelated communication plaintext. We ordinarily provide an initial response within seven (7) business days after receiving a complete request.

If you remain concerned about our processing, you may lodge a complaint with the Personal Data Protection Commission of Singapore (“PDPC”) or another competent regulator where you live.

14. Language

This Policy is available in Chinese and English. If they differ, the English version prevails unless mandatory law provides otherwise.

© 2026 QuietLink Back to home