Grom
Legal

Privacy Policy

This Privacy Policy explains how the administrator of this Grom network ("we", "our") processes the personal data you provide, or that is generated while you use the Grom app and server (the "Services").

1. Introduction

Grom is a self-hosted messenger: the app and server work together, but the server is run by the administrator of a particular Grom network, not by a single global company. This Policy explains what data is processed while you use the Services.

1.1. Privacy principles

We follow two core principles around collecting and processing personal data:

  • We do not use your correspondence to serve ads.
  • We only store the data required for Grom to work as a reliable, full-featured messaging service.

1.2. Terms of Service

This Privacy Policy is part of our Terms of Service, so please read it alongside them.

1.3. Scope

This Policy explains: the legal basis on which we process personal data; what data we may collect; how we keep it secure; the purposes we use it for; who it may be shared with; and what rights you have over your own personal data.

2. Legal basis for processing personal data

Your personal data is processed on the basis that it's necessary for our legitimate interests — in particular, providing an effective Service and detecting, preventing, or resolving fraud or security issues — except where those interests are overridden by your own interests or fundamental rights and freedoms that require protection of personal data.

3. Types of personal data we use

3.1. Basic account information

When you create a Grom account, you provide a mobile phone number and basic profile information (name, profile photo, a short bio). Your chosen profile name, photo, and username (if you decide to set one) are always visible to other users, so that contacts and other people can recognize you or reach out. We don't require your real name, gender, age, or interests.

Your display name doesn't have to match your real name. People who've added you as a contact will see you under whatever name they saved for your number in their own address book, not necessarily the one you set yourself.

3.2. Your email address

If you enable two-step verification, you can add an email address for password recovery. This address is used only to send a code as part of the forgotten-password recovery flow — never for marketing.

3.3. Your messages

Cloud chats. Grom is a cloud service: we store the messages, photos, videos, and documents from your cloud chats on the server, so you can access them from any device at any time without needing a separate backup service. This data is stored encrypted.

Secret chats. Secret chats use end-to-end encryption — the data is encrypted with a key that only you and the other person hold. We don't store secret chats on the server and don't keep logs of messages sent within them, so we have no record of who you talked to, or when, in those chats. Secret chats aren't part of the Grom cloud — they only exist on the device they were sent from or to.

Media in secret chats. Every file in a secret chat is encrypted with its own key before upload, and that key is then re-encrypted with the secret chat's own key and sent to the recipient. The file technically passes through the server, but to anyone other than the sender and recipient it looks like an unreadable sequence of bytes.

Public chats. Public channels and groups are cloud chats; anything you post there is encrypted at rest and in transit, but will be visible to every user of the network.

3.4. Phone number and contacts list

Grom uses phone numbers as unique identifiers. We ask permission before syncing your contacts, and only store the phone number, first name, and last name from your address book — so we can notify you when a contact joins Grom and show the right names in notifications. You can stop syncing or delete contacts from the server at any time in Settings > Privacy and Security.

3.5. Location data

If you share a location in a chat, it's handled the same way as any other message in a cloud or secret chat. If you broadcast a live location or turn on visibility in a "people nearby" feature, Grom uses that data to show your location to whoever you're sharing it with, for as long as the feature stays active.

3.6. Cookies

We only use the cookies necessary for Grom Web to function. We don't use cookies for profiling or interest-based advertising.

4. Security of personal data

4.1. Data storage

All data is stored on a server run by the administrator of this particular Grom network, and isn't shared with third-party companies or data centers outside that administrator's control. Data is stored encrypted.

4.2. End-to-end encrypted data

Messages, media, and other files from secret chats, as well as call content, are only ever processed on your device and the other person's device. Before this data ever reaches the server, it's encrypted with a key known only to the two of you — so we have no technical way to decrypt it.

4.3. Data retention period

Unless stated otherwise in this Policy, personal data is retained only for as long as necessary to provide the Services.

5. Processing of personal data

5.1. Our Services

We process your data to provide a cloud history of your correspondence — messages, media, and files — across all your devices, without needing any third-party backup service.

5.2. Security and protection

To improve account security and prevent spam and other violations of the Terms of Service, we may collect metadata: IP address, device information and app version, username change history, and similar. This kind of metadata is kept for no longer than 12 months.

5.3. Spam and abuse

To fight fraud, spam, and abuse, network moderators may review messages that recipients have reported. Confirmed spam can lead to a temporary or permanent restriction on messaging non-contacts; this can be appealed through the Grom SpamBot. More serious violations can lead to an account being banned. Automated systems may also scan messages in public chats to fight spam.

5.4. Working across multiple devices at once

We may store aggregated metadata so that Grom's features stay available at the same time across every one of your devices.

5.5. Enhanced features

We may use aggregated usage data about how Grom is used for helpful features — for example, showing your most frequent contacts in the search menu. You can turn this off in Settings > Privacy and Security > Data Settings.

5.6. No advertising based on your correspondence

We don't use your correspondence data for targeted ads or any other commercial purpose. If a network runs an ad platform for public channels, the ad content is based solely on the channel's own topic — no correspondence data is ever analyzed to serve ads.

6. Interacting with bots

6.1. The ecosystem

Grom provides access to a Bot API, which lets third-party developers build bots. Talking to a bot, adding it to a group, or using an inline bot means you're sending some of your data to that bot's developer.

6.2. How bots can receive your data

A bot's developer can receive your data when you: send the bot a message; use an inline bot; are a member of a group that includes the bot; press a button in one of the bot's messages; pay for goods or services through the bot; or submit a join request that the bot processes.

6.3. What data bots may collect

In all these cases, the bot receives the public parts of your account: display name, username, profile photo. Beyond that, bots receive whatever messages you send them directly; may learn your IP address if you follow a link in one of their messages; can see that you're a member of a shared group; and a bot with privacy mode disabled sees every message in the group it's been added to.

6.4. Bots are independent of Grom

Most bots are independent products built by third-party developers and aren't connected to the network's administration. They're required to ask permission before accessing your data.

7. Third-party payment services

7.1. Payment data

Grom doesn't process payments directly — that's handled by third-party payment providers. Neither the network's administration nor the sellers of goods and services (bot developers) ever get access to your card details.

7.2. Bank card data

Card details entered in the payment provider's own interface go straight to that provider's server and never reach Grom's servers. If you choose to save your card, it's kept by the payment provider as a token that can't be converted back into a card number.

7.3. Shipping information

Shipping details you enter when placing an order are sent directly to the developer of the selling bot. This data can be saved in the app for convenience, or deleted at any time.

7.4. Deleting payment data

In Settings > Privacy and Security you can delete all saved payment data and shipping details you've sent, and request that payment providers delete any saved card tokens.

7.5. Payment disputes

Because Grom never stores card or transaction data, we can't handle disputes or refund requests directly — responsibility for a disputed payment lies with the bot's developer, the payment provider, and the banks involved in the transaction.

8. Parties your personal data may be shared with

8.1. Other Grom users

By communicating with other users and sharing information with them, you give permission for your personal data to be shared with those users under this Policy. We can't prevent a recipient from sharing that data with someone else without your consent.

8.2. The network's administrator

Unlike large messengers with their own group of companies across multiple jurisdictions, this Grom network's data is processed exclusively on infrastructure controlled by that network's own administrator — it isn't shared with any other legal entity.

8.3. Law enforcement

If the network's administrator receives a valid order from the relevant authorities confirming involvement in a criminal case and a violation of the Terms of Service, they may review the request and disclose relevant information (such as an IP address or phone number) in accordance with the law that applies to this network.

8.4. Message translation, at your request

If the app offers to translate individual messages or entire chats, this feature may involve a third-party translation provider — in that case, the original message text is shared with them solely to get back a translated version.

9. Your rights over the personal data you've provided

9.1. Your rights

Under applicable data-protection law, you have the right to: (1) request a copy of all your personal data stored in Grom; (2) delete or amend your personal data; (3) restrict or object to the processing of your data; (4) correct any inaccurate data; (5) file a complaint about data processing with the network's administrator or the relevant data-protection authority.

9.2. Exercising your rights

To exercise these rights, contact the network's administrator — see section 12 below for how to reach them.

9.3. Managing your data

You can manage how your data is used in Settings > Privacy and Security. If you'd rather not provide the minimum data the app needs to function, unfortunately we won't be able to provide you the Services — in that case, you can delete your account in the app's settings.

10. Data deletion

10.1. Accounts

You can delete your account in the app's settings. Deletion removes every message, media file, contact, and other piece of data from the server, and is confirmed through the account itself — it can't be reversed afterward.

10.2. Messages

  • Deleting a message in a secret chat also removes it from the other person's device.
  • In cloud chats, a message can be deleted for every participant for at least 48 hours after it was sent; after that, deleting it only removes it from your own history.
  • Either side of a one-on-one chat can delete personal messages — sent or received — with no time limit, including fully clearing the chat history for both sides.
  • In supergroups and channels, deleting a message removes it for every member; deleted and edited messages may be kept in the admin action log for 48 hours.

10.3. Timed message deletion

Messages in secret chats can be set to delete on a self-destruct timer — the countdown starts as soon as the message is read, and once it runs out, the message is removed from both devices.

10.4. Automatic account deletion

If an account stays inactive for a long period (18 months by default), it's automatically deleted along with all the data stored for it on the server. This period can be changed in the app's settings.

11. Changes to this Privacy Policy

We reserve the right to review and change this Policy over time. Any changes take effect as soon as the new version is published on this page. Check back periodically to stay up to date.

12. Additional information

Answers to common questions are available on the FAQ page. To request a copy of the data stored for you in Grom, contact the network's administrator through the Grom SpamBot in the app.

For any questions about privacy, contact the administrator of the network your account is registered on.