Privacy Policy
Last updated: 11 August 2026
This policy describes what TeamTalk collects, what it does with it, and what it does not do. It is written to match what the software actually does, and it is updated when the software changes.
1. Who we are
TeamTalk (“TeamTalk”, “we”, “us”) provides a private chat service for teams, available as a mobile app and a web app. We are the controller of the personal information described below. You can reach us at master.kimthunbunly@gmail.com.
2. How accounts are created
There is no public sign-up. Accounts exist only because the owner of a team created one, using a phone number and a display name. Your phone number is your login identity; you confirm it with a code from an authenticator app on your device.
This means the team owner who invited you decides that you have an account, and can also remove it. If you did not expect to have a TeamTalk account, ask whoever gave you the invitation.
3. What we collect
Account information
- Your phone number and display name.
- Your role in the team (owner or member) and which channels you belong to.
- Whether your account is currently active.
Content you send
- The text of your messages.
- Voice messages you record, together with the waveform used to draw them.
- Photos, videos and files you attach, including their original filenames.
- Emoji reactions, pinned messages, and which messages you have read.
- Links you share, so a preview can be shown (see section 6).
Sign-in credentials
- The secret used by your authenticator app, and your backup codes. Both are stored encrypted (AES-256-GCM).
- Sign-in tokens. The long-lived one is stored only as an irreversible hash and expires after 30 days.
Device information
- A push notification token for each device you sign in on, plus whether it is Android, iOS or web. This is what lets us deliver a notification to that specific device, and nothing else.
4. What we do not collect
This is worth being specific about, because a lot of chat apps do collect these things:
- No analytics, tracking, crash-reporting, advertising or attribution services. The app contains no such component at all.
- No cookies, and no tracking pixels.
- No location data. The app never requests location permission.
- No access to your contacts.
- No camera access. The app cannot take a photo; it can only attach a photo or video you pick yourself from your library.
- No advertising, and no sale or sharing of your information for advertising.
- Our application code does not log your IP address or browser user-agent string. Standard network infrastructure may keep short-lived operational logs.
5. Who your information is shared with
We do not sell your information and we do not share it for marketing. Two service providers are involved in running TeamTalk:
Google Firebase Cloud Messaging — push notifications
When someone sends you a message and your app is not connected, we ask Google’s Firebase Cloud Messaging service to deliver a notification to your device.
That notification contains message content. It includes the sender’s display name, the channel name, and up to the first 120 characters of the message text (or a label such as “Photo”, “Voice message”, or the filename for an attachment). To deliver the notification, Google processes that content.
If your app is connected at the time, no push notification is sent and Google receives nothing about that message.
Amazon Web Services — storage and hosting
Photos, videos, voice messages and files you send are stored in Amazon S3. The database holding messages and accounts runs on an Amazon EC2 server. Both are in the Asia Pacific (Singapore) region.
6. Link previews
When a message contains a web link, our server fetches that page so a preview card can be
shown. Your device does not fetch it, so the site you linked to sees our server, not you or your
IP address. Common tracking parameters (such as fbclid and gclid) are
removed from the link before we fetch it. We store the page’s title, description and image
for 7 days so the same link is only fetched once.
7. Access to files you upload
Files you attach are stored at long, randomly generated web addresses. Those addresses are not individually access-controlled: anyone who has the link can open the file without signing in. The addresses are not published or guessable, and are only shown inside your team’s conversation — but if someone copies one out of the app and passes it on, the recipient can open it.
8. Security
- All traffic between the app and our servers is encrypted with TLS.
- Signing in requires a code from an authenticator app in addition to your phone number.
- Authenticator secrets and backup codes are encrypted at rest; long-lived sign-in tokens are stored only as hashes.
Messages are not end-to-end encrypted. Message text and attachments are stored unencrypted on our servers, which means we are technically able to read them. We access message content only where necessary to operate the service or where the law requires it. If you need end-to-end encryption, TeamTalk is not the right tool.
9. Where your information is stored
On servers in the Asia Pacific (Singapore) region. Push notifications are delivered through Google’s global infrastructure, so notification content may be processed outside that region.
10. How long we keep it
Messages and attachments are kept until they are deleted. There is no automatic expiry.
- A channel administrator can delete a message within 5 minutes of it being sent, or clear a channel’s entire history at any time.
- Deleting a message removes it from the conversation, but the underlying uploaded file remains in storage at its original address.
- When a team owner removes a member, that person can no longer sign in and their devices stop receiving notifications, but their account record (phone number and display name) is retained and the messages they sent stay visible to the team.
On request we will delete your account record and, where we can identify it, the content you sent — see the next section.
11. Your choices and your rights
Depending on where you live you may have rights to access, correct, delete or export your personal information, or to object to how it is used.
TeamTalk has no self-service delete-my-account button. To exercise any of these rights, or to have your account and content deleted, email master.kimthunbunly@gmail.com from a message that identifies the phone number on the account. We will confirm receipt and act within 30 days. You can also ask your team owner to remove your account, which immediately revokes your access.
Note that a request from you cannot remove the copies of your messages that other members of your team already have in their conversation history — those are your team’s records. We will tell you plainly what we could and could not delete.
12. Information stored on your device
The app keeps some data locally so it works offline and starts quickly:
- Your sign-in tokens and profile.
- A local copy of the most recent 500 messages per channel. This local cache is not encrypted; it relies on your device’s own lock screen and storage protection.
- Files you have downloaded, up to 500 MB, removed automatically after 30 days or when that limit is reached.
Signing out clears all of it. Uninstalling the app removes it too.
13. Permissions the app asks for
- Microphone — only to record a voice message, and only while you hold the record button.
- Photo library — only to attach photos and videos you select yourself. The app never reads your library on its own.
- Notifications — to tell you about new messages, replies and reactions in your team.
You can withdraw any of these in your device settings; the rest of the app keeps working.
14. Children
TeamTalk is a workplace tool. It is not directed at children and is not intended for anyone under 16. We do not knowingly collect information from children. If you believe a child has an account, contact us and we will remove it.
15. Changes to this policy
If we change this policy we will update the date at the top of this page. Significant changes will also be announced in the app.
16. Contact
Questions, requests or complaints: master.kimthunbunly@gmail.com.