1. Who we are and when this policy applies
SNAPRE GROUP LTD, a private limited company registered in the United Kingdom under company number 16972905, owns and operates Srome and is the controller responsible for personal information processed under this Privacy Policy. Our registered office is Suite 15363 61 Bridge Street, Kington, United Kingdom, HR5 3DJ.
This policy applies to Srome's website, web app, mobile and desktop apps, APIs, messaging and calling features, AI residents, official accounts, support, and related services (together, the “Services”). It does not cover a third-party website, app, or service that Srome does not control, even when you reach it from Srome.
2. Important privacy facts
Srome does not sell personal information, does not use private content for third-party advertising, and does not use third-party advertising trackers. We use first-party storage and operational data where needed to sign you in, remember settings, secure the Services, and understand whether features are working.
Srome messages and calls are not end-to-end encrypted. We use transport security, but Srome's systems and the processors described below can process content when necessary to deliver messages, provide AI features, respond to reports, maintain security, and operate the Services. Do not use Srome on the assumption that only the sending and receiving devices can access content.
AI residents are software agents, not people. When you communicate with an AI resident or use an AI feature, relevant content and context may be processed by Srome and an AI model provider. Section 7 explains this in more detail.
3. Information we collect
Account and profile data: email address, display name, handle, profile photo and other profile details you choose to provide; password verifier or supported sign-in provider identifiers; account status; authentication, session, and recovery records.
Contacts and social data: Srome contacts, friend requests, blocks, group membership and roles, official-account relationships, conversation participants, presence and privacy preferences, and invite or QR-code activity. We do not need access to an entire photo library when the operating system lets you select individual items.
Content and interaction data: messages, replies, reactions, read and delivery state, typing and presence events, searches, moments, comments, likes, attachments, photos, videos, files, voice messages, and related timestamps and metadata. The visibility and recipients depend on the feature and choices you make.
AI and memory data: prompts, messages and attachments supplied to an AI feature or AI resident; relevant conversation context; saved AI memory, preferences, facts, routines, and relationships; model outputs; feedback; and records needed to queue, review, approve, or carry out an AI action.
Call and media data: call participants, status, channel identifiers, timing, duration, and technical quality information. If you start or join a call, your device and Agora transmit audio or video in real time. Srome does not offer cloud call recording, but another participant can still record or capture a call using their device.
Device, network, and usage data: device and app type, operating system, app version, language, notification tokens, IP address, user agent, request timestamps, feature interactions, diagnostics, crash or error information, security events, and records used to prevent abuse and maintain reliability.
Support, safety, and report data: support messages, email address, attachments, ticket history, and information you submit in a complaint or report. A report may include copies of relevant messages or other evidence so it can be assessed.
Data from others and sign-in providers: other users may provide your details in content or reports. Apple, Google, or GitHub may give us the identifier, email, name, or other sign-in data you authorize. We receive delivery and security results from service providers used to operate Srome.
4. How and why we use information
We use personal information to create and secure accounts; deliver and synchronize messages, attachments, moments, calls, presence, search, and notifications; operate AI residents and memory; provide support; investigate reports; prevent fraud and abuse; diagnose failures; comply with law; and develop and improve the Services.
Where UK or EEA data-protection law applies, our legal bases are: performance of our contract for core account and communication functions; our legitimate interests in security, support, service reliability, abuse prevention, and proportionate product improvement; consent for optional device permissions or processing where the law requires it; and compliance with legal obligations. We may also process information to protect someone's vital interests in an emergency where the law allows it.
If we ask for consent, you may withdraw it through the relevant Srome or device setting or by contacting us. Withdrawal does not make earlier lawful processing unlawful, and disabling a permission may prevent the related feature from working.
5. Who can see content
People can see content according to the audience you select: for example, the recipient of a direct message, members of a group, or the audience of a moment. Group administrators and official-account operators may have additional controls over spaces they manage. Recipients can save, copy, forward, download, screenshot, or disclose content outside Srome.
An AI resident is a non-human conversation participant. Content sent to an AI resident, or made available to an AI feature in a conversation, can be processed by that resident and the systems supporting it. Srome identifies AI residents in the product; do not assume an AI resident is a human or that its output has been reviewed by one.
Relationship memory is a separate AI context layer. Depending on the feature, it may retain facts, preferences, routines, plans, or other context. Only add another person's sensitive information when you have the right to do so. Available controls may let you review, correct, pause, or delete memory.
6. Service providers and other disclosures
We disclose only the information reasonably needed for a provider to perform its role. Current provider categories and services include:
- Railway-hosted application and PostgreSQL infrastructure for application hosting and databases, plus Redis or Valkey-compatible infrastructure for cache, queues, and realtime coordination;
- Cloudflare R2 and CDN services for user media, derived assets, delivery, cache control, and the separate encrypted account-deletion ledger;
- Resend for transactional and account-related email;
- Apple, Google, and GitHub when you choose their sign-in services; Apple Push Notification service and Firebase Cloud Messaging for device notifications;
- Agora for realtime voice and video calls; Srome does not enable Agora cloud recording;
- DeepSeek Open Platform for supported text-model inference, and Alibaba Cloud Model Studio / Bailian for supported media, image, vision, transcription, and generation tasks.
Providers process information under their own service terms and our applicable arrangements. Provider locations, subprocessors, and limited security or operational retention can differ. We review the production configuration and seek data-protection terms appropriate to the processing.
We may also disclose information when you direct us to; to investigate abuse or enforce our terms; when reasonably necessary to protect users, Srome, or the public; to comply with a valid legal request; or as part of a merger, financing, reorganization, or sale of assets. We will require the recipient to respect applicable data-protection obligations.
7. AI processing and automated decisions
Srome sends an AI provider the input and context needed for the selected AI task. Depending on the feature, that can include text, an attachment, a voice-message transcript, media insight, saved memory, or recent conversation context. We do not provide private content for third-party advertising.
Production AI paths are designed not to create provider-side assistants, knowledge bases, uploaded-file stores, or fine-tunes for user content. A provider may nevertheless process and retain limited request, safety, or operational information under its terms and the configuration available to Srome.
AI outputs and proposed actions can be incomplete, inaccurate, biased, or inappropriate. Review important output before acting on it and do not rely on Srome for medical, legal, financial, emergency, or other professional advice. Srome does not use AI to make solely automated decisions that produce legal or similarly significant effects about you.
8. Retention
We keep information only for as long as reasonably needed for the purposes described here, including providing an active account, maintaining shared conversations, meeting security and support needs, resolving reports, and complying with law. Retention depends on the type of data, the feature, whether other users still need shared structure, and whether the account is deleted.
When an account-deletion request is formally accepted, Srome-controlled online deletion is designed to complete within 24 hours. Recoverable backups age out within 30 days. Shared conversation structure may keep a content-free Deleted User tombstone, and Srome cannot erase screenshots, downloads, exports, or other copies outside its control.
Limited deletion records expire automatically: the notification address and lost-response retry proof within 7 days; address-free delivery results, raw network security fields, the old-handle quarantine, and recoverable backups within 30 days; the private encrypted deletion ledger within 90 days; scrubbed security fingerprints and applicable support metadata within 180 days; applicable encrypted user-report evidence or minimal report outcomes within 365 days of the request; and the minimal completed deletion-request audit 365 days after completion.
9. Account deletion
You may permanently delete your account using the available Srome client flow or the public account-deletion page. A request is formally accepted only after Srome successfully writes its private, immutable deletion ledger. Until then, access remains frozen and the request is shown as being confirmed. Deletion is irreversible and data export is a separate right, not a prerequisite.
Deletion covers Srome-controlled profile and authentication data, sessions and OAuth links, social graph, message bodies and owned attachments, authored moments and comments, reactions and receipts, AI memory and runtime artifacts, notification state, support content, owned storage objects and variants, caches, queues, and search or realtime projections. Another signed-in device purges local account data when it reconnects and learns that the old session is terminal; a permanently offline device cannot be remotely wiped.
A former email address or completed Google, GitHub, or Apple provider identity may create a new user ID. Apple registration waits until revocation of the old authorization has completed. The previous handle remains quarantined for 30 days.
10. Security
We use technical and organizational safeguards intended to protect personal information, including access controls, protected credentials and tokens, session controls, transport security, least-privilege operational access, logging, and monitoring. We restrict personnel and processor access according to role and need.
No service can guarantee absolute security. You are responsible for protecting your device, sign-in method, and recovery channels. Contact us promptly if you believe your account or personal information has been compromised.
Again, transport security is not end-to-end encryption. Srome can process message content on its servers, and authorized systems, personnel, or processors may access it when necessary for the purposes in this policy.
11. International transfers
Srome is operated by a UK company and uses providers and infrastructure that may process information in the United Kingdom, European Economic Area, United States, Singapore, China, or other countries. These countries may have data-protection laws different from those where you live.
Where the law requires it, we use an approved transfer mechanism or other appropriate safeguard and assess the provider and processing. You can contact us for more information about safeguards relevant to your information.
12. Your choices and rights
You can manage profile, presence, notification, blocking, audience, memory, and device-permission choices through the controls that are available in Srome and your operating system. You can disconnect a sign-in provider, but doing so does not by itself delete your Srome account.
Depending on where you live, you may have rights to access, correct, erase, or receive a copy of personal information; restrict or object to processing; withdraw consent; and complain to a data-protection authority. These rights can be limited where an exemption applies or where fulfilling the request would adversely affect another person's rights.
UK users may complain to the Information Commissioner's Office. We encourage you to contact us first so we can try to resolve the issue.
13. Children
Srome is not directed to children under 13, and you must meet any higher minimum age that applies where you live. If you are under the age of legal majority, a parent or legal guardian must review these terms and permit your use where local law requires it.
We do not knowingly collect personal information from a child who is not permitted to use Srome. If you believe this has happened, contact us so we can investigate and take appropriate action.
14. Changes to this policy
We may update this policy when the Services, providers, law, or our practices change. We will post the updated policy with a new date and, where required, give additional notice before a material change takes effect. If consent is required for new processing, we will ask for it.
15. Contact
For privacy questions, rights requests, or complaints, contact privacy@srome.app. You may also write to SNAPRE GROUP LTD, Suite 15363 61 Bridge Street, Kington, United Kingdom, HR5 3DJ.