Skip to content
Talder
Terms Privacy

Talder legal

Privacy Policy

Last updated: August 5, 2026

1. Scope and Data Controller

This Privacy Policy explains how Talder Team (“we”, “us”, “our”), the operator of the Talder mobile application, collects and processes personal data. For the processing described here, the data controller is Talder Team, based in Italy. Privacy requests may be sent to talderapp@gmail.com.

Some processing is necessary to create an account and provide communications. Contacts, live/background location, music activity, optional profile information, and device permissions are processed only when you enable the related feature, provide the information, or grant permission.

2. Data We Collect and Its Sources

Account and profile data:

  • Email address, username, custom ID, optional phone number, avatar, profile image, profile styling, verified-badge state, language, settings, and privacy choices.
  • Passwords stored as bcrypt hashes, authentication provider identifiers, session tokens, account-recovery data, and device installation identifiers.
  • Apple subscription product, signed transaction and original-transaction identifiers, entitlement state, purchase and expiration dates, and verification history.

Contacts and discovery:

  • If you allow Contacts access, Talder reads contact names and phone numbers on your device. Contact phone numbers are normalized and SHA-256 hashed on device; only hashes are sent for matching. Contact names remain on the device and are used to label matches locally.
  • If you add your own phone number, the server stores a matching hash and an encrypted copy so it can be displayed back to your account. Discoverability controls whether another user’s contact hash can match your account. A hash remains pseudonymous personal data and is not treated as anonymous.

Communications and social data:

  • Direct and group messages, replies, images, view-once state, voice messages, location messages, call history, timestamps, read/listened/delivery state, friends, blocks, requests, groups, roles, invitations, and notification preferences.
  • Real-time one-to-one and group audio packets while a talk or call is active. Recorded voice messages and media may be stored for later delivery. Selected voice effects for supported one-to-one talks and calls are applied on the sender’s device before transmission; the selected preset is stored locally in app preferences.
  • E2EE public keys, key versions, encrypted key envelopes, ciphertext, capability data, and delivery metadata where encryption is supported.

Location, device and activity data:

  • Precise live location, update time, optional background-location events, street/address and weather display requests, battery level, charging status, online/last-seen status, foreground/background state, and active talk/call state when the corresponding features are enabled.
  • APNs, Push-to-Talk, VoIP, Location Push, Live Activity, and battery-refresh tokens and local authentication tokens required to address the device.
  • Now Playing title, artist, artwork URL, playback source, progress and duration, plus Spotify access and refresh tokens when Spotify is connected.

Technical and safety data:

  • Connection identifiers, IP and network-derived information, rate-limit events, server errors, security events, product interaction, performance information, and diagnostics such as app state, connection generation, failure category and delivery delay.
  • Runtime diagnostics are designed not to include message bodies, audio payloads, passwords, APNs tokens, or signed media URLs.

We receive data directly from you and your device, from people who communicate with or invite you, and from Apple, Google, TikTok, Spotify, and App Store purchase services when you choose those integrations.

3. Purposes of Processing

We process data to create and secure accounts; authenticate users; deliver messages, media, groups, calls and Push-to-Talk; show the profile, presence, battery, music and location information you choose to share; match contacts; deliver notifications and Live Activities; verify purchases; send verification, recovery and security email; provide support; prevent abuse, spam and fraud; enforce limits; investigate incidents; prepare and maintain E2EE-capable delivery infrastructure; troubleshoot reliability; and comply with legal obligations.

We do not use Contacts, precise location, microphone audio, photos, messages, or music activity for advertising or third-party marketing.

4. Legal Bases for EEA/UK Processing

Where GDPR or similar law applies, we rely on:

  • Contract: account authentication, requested communications, groups, message history, purchases, support, and core service delivery.
  • Consent: optional Contacts access and matching, live/background location, music integrations, optional sharing controls, and device permissions where consent is required. You may withdraw consent in Talder or iOS Settings without affecting earlier lawful processing.
  • Legitimate interests: service and network security, narrowly scoped diagnostics, fraud and abuse prevention, rate limiting, reliability, and protecting users and our legal rights. We balance these interests against your rights and expectations.
  • Legal obligation: records or disclosures required by tax, accounting, consumer, court, law-enforcement, or other applicable law.

Account credentials and core communications are necessary to provide the requested account-based service. If you do not provide them, Talder cannot provide those features. Optional data is not required for unrelated features.

5. Sharing with Other Users

Your username, custom ID, profile image, styling, badge and selected profile information may be visible to other users. Messages, media, modified or unmodified voice audio, group content, and related delivery metadata are shared with the recipients you select or the members of a group.

Presence, activity, friends-list visibility, talk/call history visibility, battery status, Now Playing data, contact discoverability, and precise location are shared according to the applicable setting and feature state. No privacy control can remove copies another person already captured, exported, recorded, or stored outside Talder.

6. Service Providers and Third Parties

We disclose only the data needed for the relevant service to:

  • Apple: iOS platform services, Sign in with Apple, APNs, Push-to-Talk, VoIP, Location Push, Live Activities, WeatherKit/geocoding, Apple Music, StoreKit and purchase verification.
  • Google: Google Sign-In and Gmail SMTP for transactional account email.
  • TikTok/ByteDance: optional TikTok Login.
  • Spotify: optional account authorization and Now Playing retrieval.
  • Render: cloud application and WebSocket hosting.
  • Turso: account, relationship, settings, message metadata/content and service database storage.
  • Cloudflare R2: profile images, chat images, recorded voice messages and other uploaded media.

Providers process data under their own terms and, where they act for us, applicable data-processing commitments. We select providers whose contractual and security commitments are intended to protect personal data consistently with this policy and applicable law. We may also disclose narrowly necessary information to professional advisers, authorities, or affected parties when required by law or necessary to investigate abuse, fraud, security incidents, or threats to safety and rights.

We do not sell or rent personal data.

7. Security and Encryption

We use bcrypt password hashing, TLS for client-server transport, signed Apple transaction verification, session authentication, access controls, rate limits, encrypted storage fields for supported data, and operational security monitoring.

Talder includes E2EE-capable infrastructure, but its general rollout is currently disabled. Until E2EE is enabled for a supported flow, content is protected in transit using TLS but is not end-to-end encrypted, and the server may process content as necessary to provide the service.

When a supported E2EE rollout is enabled, E2EE-capable clients encrypt supported content before upload. Servers may still process sender, recipient, group, time, message type, delivery/read state, key version and other necessary metadata. Unsupported, legacy, compatibility, notification, and rollout-disabled flows are not end-to-end encrypted. E2EE private keys are intended to remain in device Keychain/app-group storage; the server stores public keys and encrypted key envelopes.

No system is completely secure. Protect your device and credentials, and contact us if you suspect unauthorized access.

8. Retention and Account Deletion

We keep identifiable data only while needed for the purposes above, using these criteria:

  • Active account, profile, settings, relationships, groups, message history and associated media are retained while the account or content remains active and the data is needed to provide the service.
  • Pending registration data is periodically removed when verification is not completed. Password-reset secrets are hashed, expire quickly, and stale reset requests are removed.
  • Device and push tokens are replaced or removed when invalid, disconnected, disabled, or no longer needed.
  • Security, rate-limit and operational logs are retained according to incident, reliability and provider-log lifecycle needs, then deleted or aggregated when no longer necessary.
  • Purchase and original-transaction claim records may remain after account deletion where needed to meet accounting or legal obligations, prevent a transaction from being claimed by multiple accounts, resolve refunds, or investigate fraud. Active entitlement links are disabled on deletion.

Account deletion from the App removes or deactivates primary account records, relationships, messages, group membership, tokens, Spotify credentials and other active service data. Content already delivered may remain on recipients’ devices. Residual media objects, caches and backup copies may persist until provider lifecycle, backup-expiration and technical cleanup processes complete; they are not used for a new purpose during that period. Some records may be retained when law, dispute preservation, fraud prevention, or safety obligations require it.

9. Your Choices and Rights

In Talder and iOS Settings you can edit profile data; control friend requests, activity, friends-list and talk-history visibility; disable contact discoverability, battery, music and location sharing; disconnect integrations; manage notifications and permissions; block users; delete supported content; and delete your account.

Depending on applicable law, you may request access, correction, deletion, restriction, objection, portability, information about safeguards, or withdrawal of consent. Email talderapp@gmail.com from or with enough information to verify the account. We may request limited additional verification and will respond within the period required by law, normally one month under GDPR.

You may complain to the supervisory authority where you live, work, or believe an infringement occurred. In Italy, the authority is the Garante per la protezione dei dati personali (garanteprivacy.it). Exercising a privacy right does not affect mandatory processing or the rights and safety of other people.

10. Device Permissions

Talder may request Microphone for calls, talks and voice recording; Camera and Photos for profile/chat images; Contacts for optional on-device hashing and discovery; When In Use or Always Location for chat/map sharing and background updates; Media/Apple Music for Now Playing; Notifications for alerts and background wake features; and Face ID/Touch ID to confirm sensitive local actions such as account deletion.

Background modes support audio, VoIP, Push-to-Talk, location, remote notifications and refresh tasks. You can revoke permissions in iOS Settings. Refusal disables only the dependent feature where technically possible.

11. International Transfers

Providers may process data in Italy, the European Economic Area, the United States, or other countries. Where a transfer from the EEA/UK requires safeguards, we rely as applicable on adequacy decisions, standard contractual clauses, provider participation in recognized transfer frameworks, and supplementary technical or organizational measures. You may request information about the safeguard applicable to your data.

12. Children

Talder is not directed to children under 13. A user must also meet the digital-consent age applicable in their country or have legally valid parental authorization where the service supports it. In Italy, consent-based information-society processing by a child under 14 requires authorization from the holder of parental responsibility.

If you believe a child is using Talder contrary to these requirements, contact talderapp@gmail.com so we can investigate and take appropriate action.

13. No Advertising Tracking or Significant Automated Decisions

Talder does not sell personal data, serve behaviorally targeted advertising, or combine activity across unrelated companies’ apps and websites for advertising. We do not make decisions based solely on automated processing that produce legal or similarly significant effects.

Automated technical controls may temporarily rate-limit requests, reject invalid credentials or payloads, detect duplicate transactions, and protect service security. You may contact support if you believe a technical control affected your account incorrectly.

14. Policy Changes

We may update this policy when the App, providers, or legal requirements change. We will update the date and provide prominent notice or request consent when required. A policy update does not itself authorize a new incompatible use of data; additional consent or another valid legal basis will be obtained where required.

15. Contact

Data controller: Talder Team
Country: Italy
Privacy and support email: talderapp@gmail.com
Legal home Terms of Service

Talder Team · Italy