Dialog ("Dialog", "we", "us") is a messenger for chat, group voice & video calls, and screen sharing, available in the browser and as desktop and Android apps. This policy explains what data we collect, why, and your choices. By using Dialog you agree to this policy.
1. Information we collect
- Account data — your username (login), display name, and password. Passwords are stored only as a salted hash; we never store or see your plaintext password.
- Profile — optional avatar, description, and status (online / do not disturb / invisible).
- Messages & media — the content of messages you send (text, images, voice notes, GIFs, files, reactions, edits) and the chats/groups they belong to. These are stored so your conversations sync across devices.
- Contacts & groups — your friend relationships, blocks, and group memberships.
- Technical data — connection metadata needed to operate the service (e.g. delivery/read receipts, presence, and standard server logs such as IP address and timestamps).
- Push subscriptions — if you enable notifications, the push endpoint and keys your browser/device provides.
2. Encryption — what is and isn't end-to-end
Secret DMs are end-to-end encrypted. Turn on a secret chat in a one-to-one conversation and messages are encrypted on your device and only decryptable on the participants' devices — the server stores an opaque blob it cannot read. The private keys are generated on your device and never leave it, so no one, including us, can decrypt those messages. Because the keys are device-only, a new device or a cleared browser cannot read a secret chat's earlier messages, and losing all your devices loses that history — that is the trade-off for the server never holding a key.
Everything else is not end-to-end encrypted. Normal chats, group chats, channels and anything involving a bot travel over TLS and are stored on the server, which means whoever operates it can technically read them (us on the hosted instance; you if you self-host). Encryption at rest for that stored content is on the roadmap.
Encryption hides content, not metadata. Even for a secret DM, the server still sees who is talking to whom, when, and roughly how much — the same limitation every messenger has. And the crypto is our own implementation pending an independent audit; the code is public, so verify it rather than take our word.
3. Local storage on your device
We store a login token and some preferences in your browser's local storage to keep you signed in. The desktop and Android apps are thin wrappers around the same web app and store the same data locally on your device. We do not use third-party advertising or tracking cookies.
4. Calls & screen sharing
Voice/video calls and screen sharing are peer-to-peer: audio and video flow directly between participants over WebRTC. No media server sits in the middle, and no third party receives the stream. Dialog's server only relays the small signalling messages needed to set the connection up. If two participants cannot reach each other directly (strict NAT or firewall), the connection falls back to a TURN relay, which forwards encrypted packets without being able to read them.
5. Third-party services
To provide certain features, limited data is shared with:
- TURN/relay providers — used only as a fallback, to route call and screen-share media.
- Giphy — when you search for GIFs, your search query is sent to Giphy to return results.
- Link previews — when a link is shared, our server may fetch that URL to generate a preview (title/image).
- Web Push services — your browser/OS push provider (e.g. Mozilla, Apple, Google) delivers notifications you've enabled.
6. How we use your data
- To operate the messenger — deliver messages, sync chats, place calls, and show presence.
- To authenticate you and keep your account secure.
- To send notifications you've opted into.
- To maintain reliability and prevent abuse/spam.
We do not sell your data or use your messages for advertising.
7. Storage & security
Data is stored in a MySQL database with a Redis cache, on servers located in the EU (Frankfurt region). Traffic is encrypted in transit (HTTPS/WSS). Passwords are hashed. No method of storage or transmission is 100% secure, but we take reasonable measures to protect your data.
8. Data retention
We keep your account and messages until you delete them or your account. Deleting a message or leaving/clearing a chat removes it from our active database. Backups and logs are retained only as long as needed to operate the service.
9. Your rights
You can view and edit your profile, delete individual messages, clear chats, and request deletion of your account and associated data. Depending on your location (e.g. the EU/GDPR), you may have rights to access, correct, export, or erase your data. To exercise these, contact us below.
10. Children
Dialog is not directed to children under 13 (or the minimum age required in your country). We do not knowingly collect data from children below that age.
11. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
12. Contact
Questions or data requests: vanylix@proton.me.