Privacy Policy
The short version: Rings shows two people who meet the contacts they have in common — a feature we call Crosscon. Matching uses hashes of phone numbers. These remain personal data because phone numbers can be guessed. After you both accept a connection, each of you sees only the contacts you have in common, under the name the other person saved them. Messages, files, shared locations and calls are end-to-end encrypted with the Signal protocol, so we cannot read them. Call transcription runs entirely on your iPhone. No ads, no trackers, no selling of data.
Who we are
Rings (listed on the App Store as "Rings: Mutual Contacts") is operated by GAIIA PRODUCTIONS LLC-FZ ("we", "us"). "Crosscon" is the name of the Rings feature that matches two people's contacts; it is not a separate app or service. Contact: privacy@gaiiafoundation.com.
What we collect and why
Everything in this section leaves your phone, is stored on servers we operate, is linked to your account and is used only to make Rings work. None of it is used for advertising or tracking.
- Display name — the name you enter in your profile (pre-filled from your Apple ID name if Apple shares it). It is shown to people you connect with and in the notifications they receive about your requests.
- Own phone number (optional) — if you enter your number, only its SHA-256 hash is sent. It is not verified and cannot be used to sign in or recover an account. People who already have your number in their address book can see that you are on Rings, may get a notification when you add it, and can send you a Crosscon request. Kept until you change it or delete your account.
- Contacts (hashed) — while "Share contacts for matching" is on (it is on by default once you allow Contacts access, and you can turn it off in Settings), Rings uploads SHA-256 hashes of the phone numbers in your address book, except contacts you hide from Crosscon. Hashes are pseudonymous, not anonymous. Our server reveals only the overlap between two people, and only after both accept the connection; a block stops further access. For each contact you have in common, the name you saved them under is uploaded and shown to that one person. When you start a Crosscon with, or invite, a specific contact, the hash of that contact's number is stored with the request. Hashes and names are kept until you turn sharing off or delete your account.
- Connections and groups — who is connected with whom, and which group chats you belong to. Kept until you delete your account.
- Account and device identifiers — a random account identifier issued by our server when you register (it is not your advertising ID), and the Apple push tokens (APNs and VoIP) used to deliver messages and to ring your phone for calls. Kept until you delete your account.
- "About you" and professional field (optional) — described in the next section.
- Call log — for each call: the two account identifiers, start and end time, audio or video, and the outcome (for example answered or missed). Never the audio, video or anything said. Kept until you delete your account.
- Message delivery metadata — sender and recipient account identifiers, times, and whether a message was delivered and read. Kept together with the encrypted message: up to 7 days after delivery, or 30 days if it is never delivered.
- Abuse reports — when you report someone: both account identifiers, the reason you choose and the text you write, and — if you report from a group chat or a specific message — the group and an identifier of that message (not its content, which stays end-to-end encrypted). Our team reviews reports and may suspend or permanently ban an account; the decision, its reason and which team member made it are kept as a moderation record. For a permanent ban we keep the hash of the account's phone number, if one was entered, so the same number cannot register again. Kept for safety and moderation.
- Support messages — when you write to Rings Support from the app, your messages and our replies are stored on our server with your account identifier. They are not end-to-end encrypted: our support team reads them to help you, so please do not send passwords or codes. Kept until you delete your account.
"About you" (optional)
You can tell your connections what you do: a professional field you pick from a fixed list and a short "About you" text. If you fill either of them in — during setup or later in Settings › About you — it is uploaded to our servers and shown only to people you have accepted as connections. It is never shown to anyone else and never used in any search. Interest tags picked in an earlier version of the app are kept with it. The job title you type to find your field stays on your iPhone. "About you" is not end-to-end encrypted, so that a reported profile can be moderated. You can change or clear it at any time in Settings › About you; our server keeps only the latest version, and all of it is deleted with your account.
Professional search and introductions through mutual connections are switched off in this version of Rings. If you published anything through them in an earlier test version, the app withdraws it from our servers when it starts. We will update this policy before switching them on.
End-to-end encrypted: we store or relay it, but cannot read it
Message text, photos, voice messages, files and their names, locations you share in a chat, group names, reactions and replies, and call summaries you choose to send are end-to-end encrypted with the Signal protocol (libsignal). Call audio and video are encrypted with WebRTC (DTLS-SRTP), and call signaling — the messages that set up a call — is encrypted and authenticated with libsignal, so a call can be set up only with the person you expect. You can compare an eight-emoji handshake with the other person to check that nobody is in the middle.
Our server holds encrypted messages only for delivery: for up to 7 days after delivery, or 30 days if undelivered. Encrypted files are kept for 30 days. When a direct connection is not possible, calls are relayed through our TURN server, which sees only encrypted media.
Stays on your iPhone
- Call transcription (beta, off by default) — if you turn it on in Settings and tap Record during a one-to-one call, both phones show "Recording on" and the other phone plays a chime. Speech is transcribed on your iPhone by Apple's on-device speech recognition; on iOS 26 with Apple Intelligence, the summary of what was agreed is drafted by Apple's on-device model. Call audio and transcripts never leave your iPhone: they are not sent to us, to Apple's servers or to any AI service. A summary leaves your phone only if you tap Send, and then end-to-end encrypted to that chat.
- Task reminders — scheduled as local notifications on your iPhone.
- Your address book — the numbers themselves are never uploaded; only the hashes and common-contact names described above.
- Your own organisation of contacts — categories (including ones you create), ratings and notes, the job title you type, and your profile photo.
Processed briefly, not stored
- Location (Shake to Connect only) — when you shake to connect, your coordinates are sent once. Our server matches them in memory against a shake made within 3 seconds and 150 m, and discards them within 10 seconds; they are never stored. Locations you share in a chat are end-to-end encrypted (see above).
- IP address — your IP address necessarily reaches our API and our TURN relay, Google's public STUN server (stun.l.google.com, used during calls to find a network path) and Apple Maps (map previews). Our servers record it in routine technical logs for security and troubleshooting; we do not use it to track or profile you.
Services we rely on
Our API, database, storage for encrypted files and TURN relay run on servers we operate. We also rely on Apple (Sign in with Apple, Apple Push Notification service, Apple Maps and on-device speech recognition) and on Google's public STUN server. Notifications about new messages carry no message content; notifications about connection requests may include the other person's display name. Rings contains no analytics, advertising or cloud AI services.
What we do NOT do
- No advertising, no trackers, no analytics SDKs, no data brokers.
- No selling of your data and no sharing of it with third parties for their own purposes. What you share inside Rings (your display name, common-contact names, "About you") is shown only to the people described above — never to anyone outside the app.
- No reading of your messages or calls: they are end-to-end encrypted, and transcription happens on your iPhone.
- No ranking people for money, no promoted placement, no use of any of this data for advertising or profiling.
Sign in with Apple
Rings asks Apple only for your name, to pre-fill your display name; it does not request your email address. Your Sign in with Apple identifier stays in your iPhone's Keychain and is never sent to our server. Server access uses credentials belonging to your registered installation. A phone number or an Apple sign-in does not grant access to another installation or restore its history.
Data retention and deletion
- Delete your account — Settings › Delete Account. Our server deletes your account and its data: display name, phone-number hash, contact hashes and common-contact names, connections, group memberships, queued messages and files, encryption keys, "About you", call log, support messages, blocks and the reports you filed. The app then erases its local data. Messages already delivered remain on the other person's device, as with any messenger. Stored files are removed through a deletion queue with retries; download links issued earlier can remain valid until they expire. Reports other people filed about an account are kept for safety.
- Stop contact matching — turn off Settings › Share contacts for matching. Our server deletes your uploaded contact hashes and the common-contact names exchanged in your connections, and the app stops uploading them until you turn sharing back on. If you are offline, the deletion happens when your iPhone reconnects.
- "About you" — change or clear it in Settings › About you.
- Retention periods — encrypted messages and their delivery metadata: up to 7 days after delivery, 30 days if undelivered; encrypted files: 30 days; contact hashes and common-contact names: until you turn sharing off or delete your account; account data, connections, call log and support messages: until you delete your account; abuse reports, moderation records and banned phone-number hashes: kept for moderation.
You can also ask us to delete your data by writing to privacy@gaiiafoundation.com.
Your rights
Depending on your jurisdiction (including GDPR), you have the right to access, correct, export or erase your personal data. Write to us and we will respond within 30 days.
Changes
We will post any changes to this policy on this page and update the date above.