Rings gaiiarings.com →

Privacy Policy

Rings · Last updated: September 29, 2026

The short version: Rings shows two people who meet the contacts they have in common — a feature we call Crosscon. Matching uses hashes of phone numbers. These remain personal data because phone numbers can be guessed. After you both accept a connection, each of you sees only the contacts you have in common, under the name the other person saved them. Messages, files, shared locations and calls are end-to-end encrypted with the Signal protocol, so we cannot read them. Call transcription runs entirely on your iPhone. No ads, no trackers, no selling of data.

Who we are

Rings (listed on the App Store as "Rings: Mutual Contacts") is operated by GAIIA PRODUCTIONS LLC-FZ ("we", "us"). "Crosscon" is the name of the Rings feature that matches two people's contacts; it is not a separate app or service. Contact: privacy@gaiiafoundation.com.

What we collect and why

Everything in this section leaves your phone, is stored on servers we operate, is linked to your account and is used only to make Rings work. None of it is used for advertising or tracking.

"About you" (optional)

You can tell your connections what you do: a professional field you pick from a fixed list and a short "About you" text. If you fill either of them in — during setup or later in Settings › About you — it is uploaded to our servers and shown only to people you have accepted as connections. It is never shown to anyone else and never used in any search. Interest tags picked in an earlier version of the app are kept with it. The job title you type to find your field stays on your iPhone. "About you" is not end-to-end encrypted, so that a reported profile can be moderated. You can change or clear it at any time in Settings › About you; our server keeps only the latest version, and all of it is deleted with your account.

Professional search and introductions through mutual connections are switched off in this version of Rings. If you published anything through them in an earlier test version, the app withdraws it from our servers when it starts. We will update this policy before switching them on.

End-to-end encrypted: we store or relay it, but cannot read it

Message text, photos, voice messages, files and their names, locations you share in a chat, group names, reactions and replies, and call summaries you choose to send are end-to-end encrypted with the Signal protocol (libsignal). Call audio and video are encrypted with WebRTC (DTLS-SRTP), and call signaling — the messages that set up a call — is encrypted and authenticated with libsignal, so a call can be set up only with the person you expect. You can compare an eight-emoji handshake with the other person to check that nobody is in the middle.

Our server holds encrypted messages only for delivery: for up to 7 days after delivery, or 30 days if undelivered. Encrypted files are kept for 30 days. When a direct connection is not possible, calls are relayed through our TURN server, which sees only encrypted media.

Stays on your iPhone

Processed briefly, not stored

Services we rely on

Our API, database, storage for encrypted files and TURN relay run on servers we operate. We also rely on Apple (Sign in with Apple, Apple Push Notification service, Apple Maps and on-device speech recognition) and on Google's public STUN server. Notifications about new messages carry no message content; notifications about connection requests may include the other person's display name. Rings contains no analytics, advertising or cloud AI services.

What we do NOT do

Sign in with Apple

Rings asks Apple only for your name, to pre-fill your display name; it does not request your email address. Your Sign in with Apple identifier stays in your iPhone's Keychain and is never sent to our server. Server access uses credentials belonging to your registered installation. A phone number or an Apple sign-in does not grant access to another installation or restore its history.

Data retention and deletion

You can also ask us to delete your data by writing to privacy@gaiiafoundation.com.

Your rights

Depending on your jurisdiction (including GDPR), you have the right to access, correct, export or erase your personal data. Write to us and we will respond within 30 days.

Changes

We will post any changes to this policy on this page and update the date above.