Spojiti Privacy Policy

Effective 2026-08-08 · CognitionX Logic India Private Limited

The short version: we know nothing about you, by design.

Spojiti has no accounts, no phone numbers, no email addresses, and no profiles. Your identity is a cryptographic keypair derived from a recovery phrase that only you hold. Every message and call is end-to-end encrypted — our servers only ever see ciphertext, and messages are deleted from the server the moment they are delivered.

What we never collect

Names, phone numbers, email addresses, contact books, locations, advertising identifiers, analytics profiles, message content, call content, or metadata about who you talk to beyond what is technically required to route ciphertext between two opaque identifiers. We run no ads, no trackers, and no third-party analytics.

What the service technically holds

To move encrypted data between your devices and your contacts, the relay stores: (1) an opaque account identifier derived from your public key — random letters and numbers linked to no real-world identity; (2) public cryptographic key material used to establish end-to-end encryption; (3) undelivered encrypted messages, held only until delivery and then deleted; (4) if you enable notifications, a push token issued by Apple or Google — an opaque routing handle that carries no content (our notifications themselves contain no sender and no message text); (5) if you enable the optional encrypted backup, a single backup blob encrypted with a key derived from your recovery phrase — we cannot open it.

The website keeps one aggregate counter per page per day — how many times each page was viewed. That is the entire record: no cookies, no IP addresses, no device details, no visitor identifiers of any kind, and nothing that could connect a view to a person or to an app account.

Your content lives on your devices

Chat history is stored only on your own devices, encrypted at rest. Deleting the app, or your identity inside it, destroys that copy. We keep no message archive anywhere.

Payments

Spojiti payment cards hand you to your own UPI or payment app. We are never part of the money flow, hold no financial data, and see no transaction details — the payment happens entirely inside the app you choose.

Safety features

Optional safety tools (such as warnings about potentially abusive messages) run entirely on your device. Content is never scanned on our servers — structurally, it cannot be, because we only ever hold ciphertext.

Legal requests

We comply with valid legal process — and hold almost nothing to produce: no identity, no content, no history. What exists is listed under "What the service technically holds" above.

Children

Spojiti is not directed at children under 13 (or the applicable minimum age in your region), and we cannot knowingly collect data about them — we do not know who anyone is.

Changes & contact

We will post any changes to this page. Questions, access requests and erasure requests: spojiti@spojiti.world — put DATA in the subject line. Full detail of what a support email costs you in privacy terms, and how to avoid it, is on our support page.

Grievance Officer

Published as required by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the Digital Personal Data Protection Act, 2023.

Hemanth, Director — CognitionX Logic India Private Limited, Bengaluru, Karnataka, India
spojiti@spojiti.world — subject line GRIEVANCE. Acknowledged within 24 hours; resolved within 15 days.

If a grievance is not resolved to your satisfaction, you may escalate to the Grievance Appellate Committee established under the same Rules.