Voysd LogoVoysd

Privacy Policy

Effective Date: July 30, 2026 | Last Updated: July 30, 2026

Parent Organization: XelDust ("Company", "we", "us", or "our") | Official Web Portal: https://voysd.xeldust.com/

1. Introduction & Sovereign Architectural Overview

XelDust respects your privacy and is committed to protecting it through our compliance with this Privacy Policy ("Policy"). This Policy describes the types of information we may collect from you or that you may provide when you access or use the Voysd application, website (https://voysd.xeldust.com/), services, and associated peer-to-peer (P2P) communication architecture, and our practices for collecting, using, maintaining, protecting, and disclosing that information.

Voysd is engineered on a zero-knowledge, decentralized messaging philosophy. Unlike traditional messaging platforms that maintain centralized database archives of user messages and media, Voysd utilizes client-side WebCrypto encryption (ECDH P-256 key exchange and AES-GCM-256 symmetric stream ciphers) paired with direct WebRTC peer-to-peer data channels. This means that private message payloads, voice streams, video calls, and direct file transfers pass directly between user devices and are encrypted and decrypted locally in client memory. XelDust does not possess, store, read, or possess the technical capability to decrypt your end-to-end encrypted peer-to-peer communications.

Please read this Policy carefully to understand our policies and practices regarding your information and how we will treat it. If you do not agree with our policies and practices, your choice is not to use our Service. By accessing or using Voysd, you agree to this Privacy Policy.

2. Scope and Applicability

This Policy applies strictly to information collected by or through:

  • The Voysd web application hosted at https://voysd.xeldust.com/, desktop, and mobile user interfaces.
  • Email, text, and other electronic messages between you and XelDust.
  • The ephemeral signaling queues maintained temporarily on our hosted infrastructure (via Firebase Realtime Database) solely to negotiate direct peer-to-peer connections.

This Policy does not apply to information collected by any third party, including through any application or content (including advertising) that may link to or be accessible from or through the Service, or direct communications occurring out-of-band between users over decrypted peer-to-peer data channels once an active WebRTC session is established.

3. Information We Collect and How We Collect It

A. Authentication & Profile Metadata (Provided Directly by You): Google OAuth Credentials: To prevent automated bot creation, spam account proliferation, and directory abuse without requiring passwords or paid SMS verification, Voysd mandates authentication via Google Sign-In. When you register, we receive your Google unique account identifier (UID), your primary email address, your Google public profile display name, and your Google account profile picture URL. Voysd Profile Handle: You are required to select a unique lowercase username handle (e.g., @username). Profile Visibility Preferences: Your selection of Public (searchable) or Private (unlisted) visibility. Age Declarations: Explicit certification that you meet our minimum age threshold of 16+.

B. Ephemeral Signaling Data & Short-Lived Messages: WebRTC Connection Tokens: SDP tokens containing public ECDH cryptographic keys and network routing parameters are posted temporarily to our database signaling queues (/requests/). Quick Msg Fallback Payloads: Transmitted text messages to offline peers are encrypted locally and written to a short-lived inbox queue (/requests/$target_uid) which is deleted immediately upon delivery.

C. Public Contact Stories Content: 24-Hour Ephemeral Posts: If you operate a Public account and choose to post a Contact Story, we store the 280-character text payload, any associated oEmbed video links (e.g., YouTube URL parameters), author metadata, and a creation timestamp on our database.

D. Device and Usage Information: Local Browser Metadata (dark mode, system language), and Firebase Cloud Messaging (FCM) tokens to receive incoming connection requests.

4. End-to-End Encryption and Zero-Knowledge Architecture

Voysd enforces an End-to-End Encrypted (E2EE) architecture for all live peer-to-peer sessions:

  • Client-Side Key Generation: Your browser generates a unique Elliptic Curve Diffie-Hellman (ECDH P-256) key pair locally using native WebCrypto browser APIs. Private keys never leave your client device's volatile memory.
  • Symmetric Encryption: Upon exchanging public key parameters with your target peer, both client devices derive a matching 256-bit symmetric AES-GCM key.
  • Payload Isolation: Message strings, file attachments, and media packets are encrypted before leaving your device and decrypted only upon arrival.

Because encryption occurs at the application edge, XelDust operates with Zero Knowledge of your live message contents. We cannot read, analyze, inspect, sell, or disclose your decrypted peer-to-peer communications.

5. Ephemeral Data Processing & Purging Mechanisms

To comply with our data minimization principles, XelDust enforces automated data purging:

  • Instant Request Cleansing: The exact millisecond a receiving client downloads a WebRTC signaling token or a "Quick Msg", the client application issues an immediate database deletion command (.remove()), permanently erasing the payload.
  • Inbox Queue Hard Limits: User inbox paths are enforced with a strict hard capacity ceiling of twenty (20) pending requests. Any additional incoming requests are automatically rejected.
  • 24-Hour Story Self-Destruction: All Contact Story payloads carry an absolute server-side TTL of 24 hours. Upon expiration, stories are automatically purged from database records.
  • Community Report Masking: If a Contact Story receives three (3) community reports from distinct accounts, its visibility is automatically masked globally across all client applications.

6. Client-Side Processing and Local Storage (IndexedDB)

Voysd prioritizes client-side storage over centralized cloud databases. Custom user profile pictures, local conversation histories, blocked user lists, and cryptographic session variables are stored locally within your browser's IndexedDB or localStorage sandboxes. To maintain community safety without compromising server-side privacy, Voysd integrates a client-side moderation library (TxtFilter). Text strings are processed locally inside your browser memory prior to transmission to filter profanity. No text is transmitted to external servers for moderation.

7. Use of Your Information

XelDust uses the limited information collected or provided about you for the following essential operational purposes: to authenticate your identity via Google OAuth, maintain the public handle directory, route transient signaling tokens, enforce our age compliance rules (16+ baseline, restriction of media links for users under 18), and investigate severe security violations or systemic platform abuse.

8. Disclosure and Sharing of Your Information

We do not sell, rent, trade, or monetize your personal information or metadata under any circumstances. We disclose information solely under the following limited conditions:

A. Infrastructure & Service Providers: We utilize Google Firebase / Cloud Infrastructure for Google Authentication, hosting static web assets, routing database signaling nodes, and delivering Firebase Cloud Messaging (FCM) push alerts. All service providers are bound by strict contractual obligations to handle data confidentially.

B. Legal Compliance and Protection of Rights: We may disclose profile metadata or transient logs if required to do so by United States federal or state law, subpoena, warrant, or court order. Because message payloads pass E2EE over WebRTC or are purged immediately upon delivery, we cannot produce decrypted historical message logs in response to legal requests.

9. Age Restrictions & Child Privacy Protection (16+ Mandate)

Voysd is intended strictly for users who are sixteen (16) years of age or older. We do not knowingly collect, solicit, or maintain personal information from individuals under sixteen (16) years of age. During onboarding, every user must explicitly certify that they meet the 16+ age threshold. If we learn that personal information has been collected from an individual under 16 years of age without verified parental consent, we will take immediate steps to delete that account and erase all associated handle directory nodes.

For registered users between 16 and 17 years of age, our client application and database rules automatically enforce a hard restriction: the "Allow Links & Previews" setting is permanently disabled (disabled="true"), preventing the rendering or embedding of external media players (such as YouTube or Vimeo iframes) within stories or chat contexts.

10. International Data Transfers & United States Jurisdiction

Voysd is owned and operated by XelDust, organized under the laws of the United States, and hosted on cloud server infrastructure located within the United States. If you access or use the Service from the European Union, United Kingdom, Asia-Pacific, or any other region, please be advised that through your continued use of the Service, you are transferring your information to the United States and you explicitly consent to the transfer of your information to and processing within the United States and the application of United States federal and state laws regarding privacy and data protection.

11. Your Privacy Rights (US State & Global Privacy Laws)

Depending on your jurisdiction (specifically CCPA/CPRA, GDPR), you possess specific rights regarding your personal information: the Right to Know / Access a summary of the personal metadata held about your account, and the Right to Deletion of your account metadata and removal of your username handle from our public directory. To exercise any applicable data privacy rights, please submit a verified request to our legal team at support@xeldust.com.

12. Data Security and Technical Safeguards

XelDust implements industry-standard safeguards designed to secure your personal information: Transport Layer Security (TLS 1.3), WebCrypto ECDH P-256 and AES-GCM-256 ciphers, and DTLS-SRTP encryption protocols for WebRTC media streams. However, no method of transmission is 100% secure. You acknowledge that you transmit personal information at your own risk.

13. Third-Party Links and Embedded Content

The Service may contain links to third-party websites or embed third-party media content (such as YouTube or Vimeo video players embedded within Contact Stories). XelDust does not control, monitor, or endorse the privacy practices, content, or cookie policies of any third-party websites or embedded players. Viewing embedded content or clicking external links subjects you to the privacy policies and terms of those respective third-party providers.

14. Changes to Our Privacy Policy

XelDust reserves the right to modify or update this Privacy Policy at any time in its sole discretion. Any changes will be effective immediately upon posting the revised Policy within the Voysd application or on our website. Your continued use of the Service constitutes agreement to the changes.

15. Contact Information

XelDust — Legal & Privacy Department
Email: support@xeldust.com
Application Web Portal: https://voysd.xeldust.com/