Kalkan — Maxfiylik siyosati
Oxirgi yangilanish: 2026-yil 2-sentyabr
Kalkan — maksimal xavfsizlikka qaratilgan xabar almashish ilovasi. Bu hujjat ilovaning haqiqiy texnik arxitekturasini aks ettiradi va vaqti-vaqti bilan yangilanadi.
1. Kim biz
Kalkan — shaxsiy, oxiridan-oxirigacha shifrlangan (end-to-end encrypted, E2EE) xabar almashish ilovasi. Ushbu hujjat Kalkan Android ilovasi orqali qanday ma'lumot yig'ilishi, saqlanishi va ishlatilishini tushuntiradi.
2. Asosiy tamoyil: server sizning xabarlaringizni O'QIY OLMAYDI
Kalkan Signal Protocol (X3DH + Double Ratchet) orqali oxiridan-oxirigacha shifrlaydi. Xabarlar, ovozli xabarlar, fayllar va rasmlar faqat sizning qurilmangiz va suhbatdoshingiz qurilmasida ochiq matnda mavjud bo'ladi. Bizning serverimiz faqat shifrlangan ma'lumotni "pochtachi" sifatida uzatadi — uni deshifrlash kaliti bizda yo'q.
3. Biz yig'adigan ma'lumotlar
- Telefon raqami — hisobingizni yaratish va tasdiqlash uchun (Firebase Phone Authentication orqali).
- Qurilma ma'lumoti — model, OS versiyasi — xavfsizlik maqsadida (yangi qurilma tasdiqlash tizimi, hisobingizni himoya qilish uchun).
- Push-bildirishnoma tokeni (FCM) — sizga xabar/qo'ng'iroq haqida bildirishnoma yuborish uchun.
- Kontaktlar (ixtiyoriy, ruxsat berilsa) — telefon kitobingizdagi raqamlarni Kalkan foydalanuvchilari bilan solishtirish uchun FAQAT qurilmangizda ishlatiladi.
- Taxminiy joylashuv (ixtiyoriy, ruxsat berilsa, faqat "Kalkan Local" bo'limida) — yaqin atrofdagi bizneslarni ko'rsatish uchun, aniq GPS EMAS.
- Shifrlangan xabarlar/fayllar — serverimiz orqali o'tadi, lekin biz ularni O'QIY OLMAYMIZ (2-bandga qarang).
4. Biz yig'MAYDIGAN narsalar
- Xabarlaringiz matnini yoki fayllaringiz mazmunini — texnik jihatdan imkonsiz (E2EE).
- Reklama maqsadida foydalanuvchi profilini kuzatuvchi tahliliy tizim (Analytics) — o'chirilgan.
- Aniq GPS joylashuv tarixini doimiy saqlash.
5. Uchinchi tomon xizmatlari
Ilova quyidagi xizmatlardan foydalanadi: Firebase (Google) — autentifikatsiya, ma'lumotlar bazasi, bildirishnomalar; LiveKit — audio/video qo'ng'iroqlar infratuzilmasi; VirusTotal (ixtiyoriy) — yuborilgan faylning faqat SHA-256 xeshi (fayl mazmuni EMAS) tekshiriladi.
6. Zaxira nusxa (Backup)
Agar zaxira nusxa yoqilsa, ma'lumotlaringiz SIZ o'rnatgan parol bilan (Argon2id) shifrlanadi va shu holda serverga yuklanadi. Parolingizni faqat siz bilasiz — biz uni serverga hech qachon yubormaymiz va tiklay olmaymiz. Parolni unutsangiz, zaxira tiklanmaydi.
7. Ma'lumotlarni o'chirish
Sozlamalar → Hisobni o'chirish orqali istalgan vaqtda hisobingizni va unga bog'liq barcha ma'lumotlarni butunlay o'chirishingiz mumkin.
8. Xavfsizlik chegaralari — halol so'z
Hech qanday ilova (Kalkan ham) davlat darajasidagi maxsus josuslik dasturlaridan (masalan, qurilmangiz allaqachon buzilgan bo'lsa) 100% himoya qila olmaydi — bu texnik jihatdan imkonsiz. Biz mavjud bo'lgan eng kuchli, ko'p qatlamli himoyani taqdim etamiz.
9. Bog'lanish
Savollar uchun: safegram3@gmail.com
Eslatma: bu hujjat ilovaning haqiqiy texnik ishlashiga asoslangan dastlabki loyiha — to'liq yuridik ko'rib chiqish keyinroq amalga oshiriladi.
Kalkan — Privacy Policy
Last updated: September 2, 2026
Kalkan is a security-focused messaging app. This document reflects the app's actual technical architecture and will be updated over time.
1. Who we are
Kalkan is a private, end-to-end encrypted (E2EE) messaging app. This document explains what data the Kalkan Android app collects, stores, and uses.
2. Core principle: the server cannot read your messages
Kalkan uses the Signal Protocol (X3DH + Double Ratchet) for end-to-end encryption. Messages, voice notes, files, and photos exist in plaintext only on your device and your contact's device. Our server only relays encrypted data — we do not hold the keys to decrypt it.
3. Data we collect
- Phone number — to create and verify your account (via Firebase Phone Authentication).
- Device information — model, OS version — for security purposes (new-device approval, to protect your account).
- Push notification token (FCM) — to notify you of messages/calls.
- Contacts (optional, permission-gated) — used ON-DEVICE ONLY to match your phone book against Kalkan users.
- Approximate location (optional, permission-gated, only in the "Kalkan Local" section) — to show nearby businesses; not precise GPS.
- Encrypted messages/files — pass through our server but are unreadable to us (see section 2).
4. What we do NOT collect
- The content of your messages or files — technically impossible due to E2EE.
- Advertising-driven individual user tracking (Analytics) — disabled.
- Continuous precise GPS location history.
5. Third-party services
The app uses: Firebase (Google) for authentication, database, and notifications; LiveKit for audio/video call infrastructure; VirusTotal (optional) — only the SHA-256 hash of a sent file is checked, never the file content.
6. Backup
If backup is enabled, your data is encrypted with a password YOU set (Argon2id) before being uploaded. Only you know this password — we never receive it and cannot recover it. If you forget it, your backup cannot be restored.
7. Data deletion
You can permanently delete your account and all associated data at any time via Settings → Delete Account.
8. Security limits — an honest note
No app, including Kalkan, can guarantee 100% protection against state-level spyware targeting an already-compromised device — this is technically impossible. We provide the strongest, multi-layered protection available.
9. Contact
Questions: safegram3@gmail.com
Note: this is an initial draft based on the app's actual technical behavior — full legal review will follow.