Saltar al contenido
Zam Zam
Funciones Seguridad Descargar Ayuda
Español
  • English
  • Español
  • Русский
  • Українська
  • Deutsch
  • Français
  • Português
  • Türkçe
  • العربية
  • 简体中文

El inglés es el texto oficial

Este documento se publica en inglés. Las páginas para el público están traducidas desde el menú de idioma. Aún no hay una traducción revisada de este texto legal.

Privacy Policy

Effective October 2, 2026. English is the authoritative text.

This policy describes how Zam Zam Messenger handles information. It is written for people in the European Economic Area and elsewhere. It is not a certification, and it does not claim that every review or registration required by a particular store or regulator has already been completed.

Who we are

The controller is Bragin Group Inc., 539 W Commerce St # 717, Dallas, Texas 75208-1953, United States. Zam Zam Messenger is the product. Privacy questions: privacy@zamzam.chat. Phone: +1 302 506 2230.

The short version

Private conversations — direct chats, Saved Messages, groups, and private channels — are end-to-end encrypted. The keys that can read them are created on devices. We do not store a readable copy of those conversation keys. We do hold account and delivery information that a messaging service needs in order to operate. Public channels and stories are not end-to-end encrypted.

Account and phone number

An account is created with a phone number, a one-time verification code, a username, and a display name. We use the phone number to create the account, to sign you in, and to match contact discovery when someone uses that feature.

The phone number is stored in protected form. It is not shown on your public profile. A username and display name are visible as your identity in the product. There is no biography field.

Delivery of the verification code may be performed by a telecommunications provider. The current application code does not name one commercial verification vendor. When a provider sends the code, it receives the phone number for that delivery.

Profile, presence, and privacy settings

You can set a profile photo. Its visibility can be everybody, people you already have a direct chat with, or nobody. Last seen has the same three choices and defaults to everybody. Read receipts are on by default and are shown only when both people have them on.

You can block another account. A block stops that person from messaging you, and neither of you appears in the other’s contact-discovery results.

Devices and sessions

Each signed-in app is a device. We store the platform, a device name, app version, operating-system version, locale, time zone, and when the device was last seen. Signing in creates a short-lived access session and a refresh session. The refresh token is stored only as a digest. Access sessions are designed to last about 15 minutes. Refresh sessions are designed to last about 30 days unless you sign out or the device is removed.

You can sign out of one session or all sessions, and you can revoke a device from an account that is still signed in. Revoking a device turns off its sessions and push token and rotates encryption for conversations it belonged to.

There is no QR code flow for linking a device yet. Another device is added by signing in.

Push notifications

If you allow notifications, we store a push token for that device so Apple Push Notification service or Firebase Cloud Messaging can wake the app. The token is stored in protected form.

Notification text does not include the contents of an encrypted message. The default text is a generic label such as “New message” or “Photo”. You can choose to include the sender’s name. Apple or Google receives the token and the notification we ask them to deliver. They do not receive the readable text of an end-to-end encrypted message from us, because we do not have it.

Messages and files

Message contents for private conversations are end-to-end encrypted. Photos, video, voice messages, files, and stickers in those conversations are encrypted on the device before upload. Our servers store and forward ciphertext and the routing data needed to deliver it. They are not designed to hold the keys that would make that content readable.

A new device can decrypt messages sent after it joins. Older encrypted messages are not copied to it from a backup. Zam Zam does not currently offer encrypted cloud backup or a message-history export.

Public channels are different. They are meant to be read by subscribers, and they are not end-to-end encrypted. Content posted there can be seen by the service.

Stories

Stories can be a photo, a video, or text. They expire after 24 hours. Story text is stored so it can be delivered. Stories are not end-to-end encrypted. The usual audience is people you already have a direct chat with. The apps do not yet offer a close-friends list or story replies.

Calls

We keep call metadata such as participants and start and end times. We do not make a recording of the call in the product.

One-to-one call audio and video are encrypted between the participants. A relay may carry that encrypted media. The relay is not given the keys used to read it. This is standard call encryption, not the same end-to-end design used for private messages.

Group call media is end-to-end encrypted by default. Media servers route the call and do not hold the room key in readable form. A group call can require approval before someone joins. Call links exist. Screen sharing is available on desktop and Android. It is not available on iPhone.

Contact discovery

If you choose to find people, the app sends a batch of phone numbers. We match them in memory and do not store that upload as an address book. The response tells you which of those numbers already have an account.

There is no separate switch to hide your account from discovery. Someone who already has your number and uses discovery can learn that you use Zam Zam, unless one of you has blocked the other.

Abuse reports

If you report someone, we store the report: who sent it, who it is about, a category, any comment you write, and message identifiers you attach. We do not receive the readable text of an end-to-end encrypted message with that report.

Connection and security data

Like other internet services, our servers see connection information in order to answer requests and to limit abuse. The product does not keep a separate long-term ledger of IP addresses as a user-facing feature. Ordinary server logs may exist for operations and security. A fixed public retention period for those logs is not defined in the product, so we do not invent one here.

This website

zamzam.chat does not create an account and does not use advertising or analytics cookies. Your browser can store one local preference so the cookie notice stays dismissed. Language is chosen by the page address, not by a tracking cookie. The site may appear in ordinary server logs.

Why we use information

  • To create and protect your account, deliver messages, calls, stories, and notifications, and sync the devices you sign in.
  • To apply the privacy settings, blocks, and abuse reports you use.
  • To keep the service reliable and to investigate abuse and security problems.
  • To answer support, privacy, and security requests.

Legal bases

Where the GDPR or a similar law applies, we use these bases:

  • Contract: providing the account and the messaging, calling, and story features you use.
  • Legitimate interests: securing the service, preventing abuse, and understanding whether the service is working. Those interests are not used as a reason to read end-to-end encrypted conversations.
  • Legal obligation: where a law requires us to keep or disclose something.
  • Your action: contact discovery runs when you use it. We do not treat that as a separate stored consent flag, because the product does not have one.

Processors

We operate the messaging, media, and call infrastructure ourselves. External processors we actually use for the product are:

  • Apple Push Notification service, for notifications to Apple devices.
  • Google Firebase Cloud Messaging, for notifications to Android devices. This is push delivery, not a statement that every Firebase product is in use.

A telecommunications provider may process a phone number when a verification code is sent. No named commercial verification vendor is wired in the current server software, so we do not list one.

This website does not send data to an advertising or analytics company.

International transfers

Bragin Group Inc. is in the United States. Apple and Google may process push data in the United States and in other countries where they operate. Where a transfer tool is required, we use one that the law allows. This policy does not claim an adequacy decision or a completed certification.

How long we keep it

  • Verification challenges are short-lived, on the order of minutes, and registration grants are short-lived, on the order of minutes.
  • Access sessions last about 15 minutes. Refresh sessions last about 30 days unless revoked sooner.
  • Stories expire after 24 hours.
  • Account, profile, device, conversation membership, public channel content, and call metadata stay while the account exists, unless a shorter behavior above applies. The product does not define a separate automatic deletion date for that material.
  • Encrypted message material is kept for delivery. We cannot read it. There is no encrypted backup product that keeps a restorable history for you.

Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict, or object to certain processing, and to complain to a supervisory authority. You may also ask for a copy of the account information we can actually access.

The apps do not yet include a data export. Email privacy@zamzam.chat and we can provide account information we hold, such as username, display name, and phone number. We cannot produce a readable export of end-to-end encrypted messages, because we do not have the keys.

There is no automated in-app or website control that deletes an account. The steps we can do today are on the account deletion page. The same page is the deletion resource for store listings.

We do not sell personal information. This website does not use advertising trackers. Zam Zam does not currently send marketing email, so there is no marketing-preference list to join or leave.

Children

Zam Zam is not directed at children under 16. The apps do not currently ask for a date of birth. If you believe a child under 16 has an account, contact privacy@zamzam.chat.

Changes

If this policy changes, we will update the date on this page. Where a change is material, we will provide a notice that is reasonable for the product at that time.

Contact

Privacy: privacy@zamzam.chat
Support: support@zamzam.chat
Security: security@zamzam.chat

Bragin Group Inc.
539 W Commerce St # 717
Dallas, Texas 75208-1953
United States
Phone: +1 302 506 2230

Producto

  • Funciones
  • Seguridad
  • Descargar

Ayuda

  • Ayuda
  • Eliminar cuenta
  • Opciones de privacidad

Legal

  • Privacidad
  • Términos
  • Empresa

Contacto

  • support@zamzam.chat
  • privacy@zamzam.chat
  • security@zamzam.chat

Descargar

  • iPhone
  • iPad
  • Android
  • macOS
  • Windows
  • Linux

Zam Zam © 2026 Bragin Group Inc.

Idioma

Español
  • English
  • Español
  • Русский
  • Українська
  • Deutsch
  • Français
  • Português
  • Türkçe
  • العربية
  • 简体中文

Este sitio guarda una preferencia en tu dispositivo para que este aviso no vuelva a mostrarse. No usa cookies de publicidad ni de analítica. Política de privacidad.