Privacy Policy
How Velisona handles your information.
Effective October 3, 2026
Who is responsible
Velisona is an invitation-only alpha messaging and one-to-one calling application created and operated by Ihor Maiorov. This policy covers the Velisona applications and this website. For privacy questions or requests, contact igor.v.maiorov@gmail.com.
Information we process
Account information includes your email address, first and last name, optional avatar, authentication provider identifiers, password hash when you use a password, and account preferences. We process device identifiers and public encryption keys, trusted-device approvals, notification tokens, contacts and contact requests, block lists, and your latest activity time. Other people can see your name and avatar during a contact lookup; accepted contacts can see your online status. You can hide your last-seen time in Privacy settings.
Messages, calls and files
Message bodies, reactions, replies and attachment contents are encrypted on your devices. Private decryption keys remain on your devices; the server does not receive them. Call audio and video are encrypted between the participants. Velisona does not record calls on its servers. Direct calls connect devices where possible; a relay forwards encrypted traffic when a direct connection is unavailable. Network addresses are necessarily visible to network and relay providers, and may be visible to the other participant in a direct call. End-to-end encryption does not conceal all metadata.
Delivery and retention
Undelivered encrypted messages wait in the live server queue for up to 7 days and are removed from that queue after acknowledgement or expiry. Encrypted uploaded photos, videos and files are available for at most 7 days from the associated message; retrying an upload does not extend that period. File contents are excluded from server backups, become unavailable at expiry and are automatically purged. Devices may keep downloaded copies and local history until their users remove them. Velisona cannot erase copies another participant has saved.
Metadata, diagnostics and backups
To deliver and protect the service, the server processes sender and recipient identifiers, delivery/read/unsend states, file size and expiry, call participants, timestamps, status and duration, authentication and invitation records, and administrative audit events. We use these records for delivery, call history, access control, troubleshooting, security and aggregate alpha statistics; administrators cannot read encrypted message or file contents. Account, relationship, message-state and call metadata currently remain for the life of the account or until a deletion request is fulfilled. Operational logs are size-limited and rotated. Database backups may contain account metadata and encrypted message envelopes, but not attachment file contents, and are rotated after approximately 8 days. Deleted database records may therefore remain in restricted backups until rotation. A backup restore must reapply fulfilled deletions and expiry rules.
Providers and sharing
DigitalOcean hosts the service. Resend delivers account emails. Apple Push Notification service and Google Firebase Cloud Messaging deliver notification signals; Apple or Google may also authenticate you if you choose their sign-in option. These providers receive the information needed for their role, such as email addresses, notification tokens, network addresses and technical delivery data. Push notifications do not include decrypted message or attachment contents. We do not sell personal information, show advertising, or include advertising or behavioral analytics SDKs. Information may be disclosed where required by law or to address fraud, abuse or a security incident. Service providers may process information outside your country.
Your controls and deletion
You can update your profile, manage trusted devices, change last-seen visibility, block contacts, revoke device permissions and sign out. To request deletion of your account and associated server data, email igor.v.maiorov@gmail.com from your registered email address with the subject “Delete Velisona account”. We verify account ownership before acting. You may also request access to or correction of your information at that address. Deletion removes or de-identifies your account, contact relationships and associated server records; limited records may be retained where necessary for a legal obligation or a specific security investigation. Any such exception will be explained in our response. Recipient-held copies are unaffected; remove local history and backups from your own devices separately. See the account deletion page for the request process.
Website storage, security and age
The public website stores your chosen language locally. The admin panel uses an essential authenticated session. We do not use advertising cookies. Encryption and access controls reduce risk, but no system is guaranteed to prevent every loss or unauthorized access. This private alpha is intended for people aged 18 or older and is not directed at children.
Changes and contact
We may update this policy as the alpha evolves. The effective date appears on this page. Material changes to how personal information is used will be communicated through the service or email when appropriate. Privacy and support contact: igor.v.maiorov@gmail.com.