YUPZAP · LEGAL & PRIVACY

Privacy policy

Updated 7 October 2026 · Merdot Private Limited

Merdot Private Limited operates Yupzap. This policy explains information processing for our social, messaging and calling features, our website, account support and safety reporting. The information involved depends on the features you use and the permissions you choose.

A public post, a message to a chosen recipient and a safety report have different audiences. Review your audience and the information you submit before sharing. This policy does not grant permission to use personal information for purposes unrelated to those described here.

All policies ↗
01

Account and profile information

We process your registered phone number, account identifier, username, display name, profile picture and account settings to create and operate your account, identify you to the people you interact with, support sign-in and investigate account problems.

Optional information can include a recovery email, birthday, gender, biography, website and professional or business details you submit. Information you put in a public profile can be viewed and copied by other people. Avoid putting private contact details or sensitive information in a public field.

    02

    Content, contacts and communications

    The service processes the content and associated information needed for the features you use: messages, photos, videos, voice recordings, documents, posts, comments, reactions, follows, group activity, call metadata and reports. A location you deliberately share becomes part of that communication. Private message and attachment content is end-to-end encrypted; processing it for delivery does not give Yupzap access to its readable content. Account, routing and call metadata are distinct from encrypted conversation content.

    When you permit contact discovery, contact information is processed to find people you know and apply relevant privacy controls. You can decline or revoke contact access through device settings; discovery features may then be limited. A technical transformation such as hashing does not make contact information automatically anonymous.

    A report or support request can disclose selected content, account identifiers, attachments and context to our reviewers. Only include what is needed. Never send a password, one-time sign-in code, recovery secret or private encryption key.

      03

      Device, activity and payment information

      We process session identifiers, notification tokens, device and platform information, IP addresses, request and security records and engagement events needed to operate, maintain and protect the service. Website and app storage can retain settings and supported local content. Clearing local storage can remove information that has not been transferred elsewhere.

      When you make a purchase, the payment provider processes payment credentials under its own notice. Yupzap processes relevant transaction identifiers, purchase history, subscription status and support records to provide the purchased service, handle disputes and meet financial obligations. Do not send payment-card credentials to support.

        04

        Why information is used

        We use information for the following purposes, limited to what is relevant to the feature or request. Where consent is legally required, it must be obtained separately and may be withdrawn; a general acceptance of terms does not replace required consent.

        • Account operation: sign-in, recovery, profile settings, audience choices and delivery of requested features.
        • Communication and discovery: route messages and calls, display posts to their selected audience, find permitted connections and deliver notifications.
        • Safety and reliability: investigate reports, detect account abuse or fraud, troubleshoot failures, enforce policies and protect people and the service.
        • Purchases and support: validate transactions, manage access to paid features and respond to account or billing requests.
        • Legal obligations: respond to valid legal process, preserve required records and make legally required reports.
        05

        Who receives information

        Recipients and audiences receive the information you choose to share. Public profiles and posts may be accessible outside your immediate connections. Group members and other recipients can keep their own copies or share information outside Yupzap; changing an audience later cannot recall every independent copy.

        Service providers process information needed for infrastructure, storage, authentication, communications, notifications and payments. The providers identified for Yupzap include Amazon Web Services, Cloudflare, Merdot Connect, Expo and relevant Apple or Google notification services. Purchases through Apple or Razorpay are processed under the respective payment flow. A provider does not need every category of account information for every task.

        Information may be disclosed for a valid legal requirement, a necessary safety response, fraud investigation or the establishment or defence of legal claims. Requests must be assessed for their legal basis and scope; a request from an authority is not permission for unlimited access. Disclosures should be limited to information lawfully required or otherwise justified.

        Providers and recipients may operate in countries other than yours. Processing and transfers remain subject to applicable legal requirements. Contact us if you need information about the providers or processing locations relevant to your account.

          06

          Security, encryption and local copies

          Yupzap private chats, attachments, voice calls and video calls are end-to-end encrypted. The participants hold the keys needed to read or listen to their content, so Yupzap cannot read private messages or listen to calls. Encryption in transit and on a device provide different protections. Public social content and information deliberately submitted for review have a different audience.

          Check the security information for your installed version and conversation. Content you deliberately submit in a report may be made available for review. Endpoint compromise, screenshots and recipients sharing their own copies can expose information even when a communication uses encryption.

          No security measure eliminates every risk. Tell support promptly about suspected account compromise without including secrets. Do not uninstall or erase your old device until you have confirmed that any supported transfer or backup has succeeded.

            Security and encryption ↗
            07

            Retention and account deletion

            Information is kept for the purpose for which it is needed, including operating an active account, delivering requested content, resolving an outstanding issue and meeting a specific legal obligation. Different categories can have different retention needs; there is no single retention period for all Yupzap information.

            You can request account deletion in the app or through the Delete account page. The deletion process covers the active account, associated profile and settings, owned posts and uploads and the handling of sent-message content described in that flow. Ownership verification may be required to prevent someone else deleting your account. Uninstalling the app is not an account-deletion request.

            Records needed for billing, fraud prevention, safety investigations, legal preservation or dispute resolution may need to remain separately after an account closes. Backup copies may remain until the relevant backup lifecycle or preservation obligation ends. Contact support for the categories, reason and retention period applicable to your request. Deletion is not a promise of instant erasure from every backup or recipient device.

            Other users’ independent content and copies they already downloaded are not automatically deleted. A retained compliance record must not be treated as permission to reactivate a deleted profile. Cancel any recurring purchase with its billing provider as well; deleting an account does not itself cancel an external subscription.

            Messages you send to the official Yupzap account are kept so we can help you and post for you. It posts for you only after you tap Post or Confirm, and scheduled posts and their media are kept until they are published or cancelled. Caption suggestions are optional: only when you tap Suggest caption are smaller copies of those photos (never videos) sent to Merdot AI.

              Delete your account ↗
              08

              Choices, requests and complaints

              You can use available profile, audience, block, notification and permission controls. Revoking a device permission stops the related future access but does not automatically delete information already submitted. Contact us to request deletion of previously collected information.

              Contact support to request access to information about your account, correction, deletion, withdrawal of consent where relevant, or review of a privacy concern. Explain the request and provide enough account information to locate it. We may request proportionate proof of ownership; do not email sign-in codes or unnecessary identity documents.

              We will handle requests under the law that applies, explain any lawful limitation on an outcome and provide a route to raise a concern. Your applicable rights to approach a regulator, grievance mechanism, consumer forum or court are not replaced by contacting support. Rights and procedures under legislation apply when the relevant provisions are in force.

                Contact support ↗
                09

                Young people and changes to this policy

                Yupzap is intended for people aged at least 13 and any higher minimum age applicable to them. Where law requires parental or guardian consent or additional safeguards for a person under 18, those requirements must be met; a 13+ statement does not remove them. Contact support about an account believed to be below the permitted age or a child-safety concern.

                This page displays its revision date. Material changes to processing should be explained through an appropriate notice, with consent obtained where required. A revised policy does not by itself authorise incompatible use of information already collected.

                  Child safety standards ↗
                  10

                  Where your content is kept and how deletion works

                  The app keeps your chats, and the photos, videos and files in them, on your phone so they open quickly. Those copies stay on your phone until you delete them, delete the chat or remove the app. Copies that other people received stay on their own devices, under their control.

                  Our servers keep message content and attachments as needed to deliver them, to show your history and to run the features you use. If we change how long chat content is kept on our servers, we will update this policy.

                  When you delete a post, Zap, Loop, Moment or comment, it is removed from view on Yupzap straight away and later removed from our systems. A copy may be kept longer only where it is needed for a report, a safety review or a legal hold. Moments are shown for 24 hours.

                  Account deletion starts as soon as you confirm it. There is no waiting period, so it cannot be undone. Your profile, posts, uploads, follows, settings and any backups you stored with us are removed, and the text and media of messages you sent are cleared. Records described under Retention and account deletion, such as billing, safety and legal records, may be kept separately for the reasons given there.

                    11

                    Device permissions and notification privacy

                    Camera, microphone, photo-library, contact and location permissions should be used only for the features for which access is requested. The permission prompt and device settings determine the scope granted. You can change those settings; a feature requiring a denied permission may not work.

                    A lock-screen notification, shared screen or unlocked device can reveal content to people nearby. Review notification previews and device access settings. A local draft or downloaded copy can remain on a device independently of whether a social post is public. Encryption does not protect information shown on an unlocked screen.

                      12

                      Cookies, local storage and external links

                      Website cookies, browser storage and app storage can serve different purposes, including retaining settings and session state. A browser’s controls can limit or clear its storage but do not automatically delete server records or content on another device. Some sign-in or preference functions may stop working after storage is cleared.

                      Optional tracking that requires consent must not be treated as necessary merely because these terms mention it. This notice is not a consent mechanism. Follow the choices provided by the actual feature and contact support for information about a particular storage item or service.

                      Following an external link or opening a store page sends you to a separate service governed by its own notice. The external service can receive connection information when you visit. Avoid supplying sensitive information unless you recognise the destination and understand why it is requested.

                        13

                        Reports and information about other people

                        When you report content, the material you deliberately submit and relevant context can be reviewed to investigate it. A recipient’s decision to submit their copy for review is distinct from routine delivery of an encrypted conversation. Read the report confirmation to understand which messages or attachments are included.

                        Provide relevant identifiers and a description rather than unrelated conversation history. A complaint may need to be summarised to the affected person so they can respond, or disclosed under valid legal process. Reporter confidentiality is not an absolute guarantee; tell the grievance contact if disclosure could create a safety risk.

                          14

                          Suspected security incidents

                          Report suspicious sign-ins, lost access or exposed information promptly to support. Include the approximate time, affected feature and a short description; redact unrelated personal information and secrets. Do not send private keys, one-time codes or a full private conversation as proof.

                          A suspected incident requires assessment of the affected systems, information and people. Any notification, preservation and reporting duties are governed by applicable law. This notice does not promise that all incidents are detectable immediately or that a particular response has already been completed.

                            15

                            Requests made through representatives

                            An authorised representative should identify the account concerned, the request and the basis of authority. We may seek proportionate verification of that authority and the account holder’s identity to prevent unauthorised disclosure or deletion. A family relationship alone does not necessarily authorise access to private messages.

                            Requests concerning a deceased or incapacitated person require consideration of legal authority and other participants’ privacy. Contact the grievance officer for the applicable process. Account access or recovery of encrypted content cannot be promised where the necessary credentials or keys are unavailable.

                              16

                              Operator and grievance contact

                              Yupzap is operated by Merdot Private Limited (Merdot Pvt Ltd). Correspondence address: 4-D, Vardan Tower, Near Sardar Patel Stadium, Navrangpura, Ahmedabad, Gujarat, India 380009.

                              Grievance Officer: Mr. Amit Sharma. Email: [email protected]. Contact this address for a grievance or to seek review of an unresolved concern. Keep passwords, sign-in codes and unnecessary sensitive information out of your message.

                                Email the Grievance Officer ↗ Grievance process and appeals ↗

                                Need help with this policy?

                                Use a verified account email where possible. Include the relevant policy section and a brief description. Do not send login codes or private encryption keys.

                                Contact support ↗