Legal
Privacy Policy
Updated: 23 September 2026
1. Introduction
Krystyna Starodub, an individual developer based in Ukraine, operates the messenger under the Sayli trademark. In this document “Sayli”, “we”, “us” and “our” mean Krystyna Starodub, and “you” means you, the user of the service.
This Privacy Policy describes how Sayli uses and protects the personal information you provide to us, or that we receive or generate, in connection with your use of our services.
Sayli is designed never to collect or store sensitive information it does not need. Calls and secret chats are protected by end-to-end encryption and cannot be read by us or by any third party. Cloud chats travel between your devices and our servers only over encrypted connections.
1.1. Privacy principles
Sayli has two basic principles regarding the collection and processing of personal data:
- We do not use your data to show you ads.
- We store only the information vital for Sayli to work as a protected and full-fledged app.
1.2. Terms of Service
Our Terms of Service set out the conditions under which you use our services, including this Privacy Policy. The two documents should be read together.
1.3. What this policy covers
This Privacy Policy explains the legal basis on which we process your personal data, the types of personal data we may collect from you, how we safeguard that data, how we may use it, whom we may share it with, and your rights in relation to it.
2. Legal ground for processing your personal data
We process your personal data on the ground that the processing is necessary for our legitimate interests, which are: (1) offering our users useful and cutting-edge services; and (2) detecting, preventing or otherwise addressing fraud or security issues in connection with the provision of our services — unless those interests are overridden by your interests or by the fundamental rights and freedoms that require the protection of personal data.
3. What personal data we use
3.1. Basic account data
Sayli is a communication service. To create a Sayli account you give us your mobile number and some basic account information: your profile name, your profile picture and your about information.
The screen name you choose, your profile pictures and your username, if you set one, are always public — this makes it easier for your contacts and other users to reach you and to recognise you. We do not want to know your real name, gender, age or preferences.
Your screen name does not have to be your real name. Users who have you saved in their contacts see you under the name they saved, not under your screen name. In this way the same person can be “Terminator” in public, “John” to you and “Security Officer” to their colleagues.
Sayli can optionally discover which contacts in your address book already use Sayli, using a method designed to protect the privacy of your contacts: information from the contacts on your device may be cryptographically hashed before it is sent to the server, so that matches can be found without your address book ever reaching us in readable form.
3.2. Your email address
You may set up a password recovery email when you switch on two-step verification, or when you store documents in your Sayli profile. If you forget your password, the only thing we ever send to that address is a password recovery code.
We may also ask some users for an email address so that login codes can be delivered by email instead of SMS, with the option of “Sign in with Google” or “Sign in with Apple”. A login email address is used only to send you authentication codes when you log in, is stored separately from the recovery email, and is kept until you change it or delete your account.
3.3. Your messages
How your messages are handled depends on the kind of chat they are in.
3.3.1. Cloud chats
Sayli is a cloud service. We store the messages, pictures, videos and documents from your cloud chats on our servers, so that you can reach them from any of your devices at any time without depending on third-party backups. This data travels between your devices and our servers only over encrypted connections, and access to the servers is limited to the people who run the service.
3.3.2. Secret chats
Secret chats use end-to-end encryption. Everything in them is encrypted with a key known only to you and to your recipient. Without direct access to your device, neither we nor anyone else can tell what is being sent in those messages.
Secret chats are not stored on our servers. We keep no logs of messages sent in secret chats, so after a short while we can no longer tell who sent a message or when. For the same reason secret chats are not available in the cloud: you can reach those messages only from the device that sent or received them. Secret chats are not available in some regions.
3.3.3. Media in secret chats
Every file you send in a secret chat is encrypted before upload with a one-off key that the server does not know. That key and the location of the file are then encrypted again with the key of the secret chat and sent to your recipient, who can then download and open the file. Technically the file sits on a Sayli server, but to everyone except you and your recipient it looks like a random, meaningless block of data. We do not know what that data represents or which chat it belongs to. We periodically delete such data from our servers to free disk space.
3.3.4. Public chats
In addition to private messages, Sayli supports public channels and public groups. All public chats are cloud chats, as described in 3.3.1 above. What you post there is protected in transit like everything else on Sayli — but it is visible to everyone.
3.4. Phone number and contacts
Sayli uses phone numbers as unique identifiers, which makes it easy to move over from SMS and from other messaging apps while keeping your social network.
We ask for your consent before syncing your contacts. We keep a record of your contacts so that we can show names correctly in notifications and let you know when one of your contacts joins Sayli. We store nothing else about your contacts — only the phone number and the name.
Our automated algorithms may also use anonymised sets of phone numbers to estimate roughly how many potential contacts an unregistered number would have on Sayli. We show the resulting figure next to your contacts in the “Invite friends” screen, so that you can see who would benefit most from using Sayli.
You can switch contact syncing off, or remove your contacts from our servers, at any time in Settings → Privacy & Security → Data Settings.
On Android, Sayli may ask for permission to read your call log (READ_CALL_LOG). If you grant it, Sayli can verify your account with a call instead of asking you to type a code: the app uses the permission only to confirm that the verification call was received, by checking the number in the call log.
3.5. Location data
When you share your location in a chat, it is handled like any other message in that chat.
If you share your Live Location in a chat, or switch on “Make Myself Visible” in People Nearby, Sayli uses your location data to show it to the users you are sharing it with, including while the app is closed — for as long as you keep those optional features switched on.
3.6. Cookies
We use only the cookies necessary to run and deliver our web services. We do not use cookies for advertising or for profiling.
Cookies are small text files that let us provide and personalise our services. Your browser lets you control them, including whether to accept them and how to delete them. You can disable cookies, but then you will not be able to log in to the web version of Sayli.
4. Keeping your personal data safe
4.1. Storing data
Personal data is stored on servers operated by Sayli. Access to them is limited to the people who run the service, and data travels between your devices and our servers only over encrypted connections.
4.2. End-to-end encrypted data
Messages, media and files in secret chats (see 3.3.2 above), the contents of your calls, and the documents you store in your Sayli profile are processed only on your device and on the device of your recipient. This information is encrypted with a key known only to you and to your recipient before it ever reaches our servers.
Sayli servers still handle this end-to-end encrypted data in order to deliver it, or to store it in the case of Sayli profile data, but we have no way of deciphering it. In that case we do not store or process your personal information at all: we store and process sequences of random symbols that are meaningless without keys we do not have.
4.3. Retention
Unless this Privacy Policy says otherwise, we keep the personal data you give us only for as long as it is needed in order to provide the services.
5. Processing your personal data
5.1. Our services
Sayli is a cloud service. We process your data in order to deliver your cloud chat history — messages, media and files — to any of your devices, without requiring you to use external backup services or cloud storage.
5.2. Safety and security
Sayli hosts large communities, which we have to monitor for abuse and for breaches of the Terms of Service. In order to improve the security of your account and to prevent spam, abuse and other breaches of our terms, we may collect information such as your IP address, the devices and Sayli apps you have used, and the history of your username changes. When such metadata is collected, it is stored for no longer than 12 months.
5.3. Spam and abuse
Our moderators may examine messages that have been reported to them, in order to stop phishing, spam and other forms of abuse and breaches of the Sayli Terms of Service. If a spam report about a message you sent is confirmed by our moderators, your account may be temporarily or permanently restricted from contacting strangers. More serious breaches may lead to your account being banned. We may also use automated algorithms to analyse messages in cloud chats in order to prevent spam and phishing.
5.4. Cross-device functionality
We may store some aggregated metadata in order to build Sayli features that work across all of your devices (see 5.5 below).
5.5. Advanced features
We may use some aggregated information about the way you use Sayli in order to build practical features. For example, when you open the search menu, Sayli shows a row of the contacts you are most likely to message; to do that we compute a rating that identifies the contacts you message most often. A similar rating decides which inline bots to suggest in the attachment menu or when you start a message with “@”. You can switch this off and delete the underlying data in Settings → Privacy & Security → Data Settings by unchecking “Suggest Frequent Contacts”.
5.6. No ads based on user data
Unlike other services, we do not use your data for ad targeting or for other commercial purposes. We keep only the data Sayli needs in order to work as a safe and full-featured cloud service.
6. Bot messages
6.1. Ecosystem
Sayli has an API that lets third parties develop bots. Bots are applications that look like “special” Sayli users: you can chat with them from your chat list, add them to groups, or use their features through a special “inline” interface. Any of these actions results in some of your data being transmitted to the corresponding third-party bot developer.
6.2. How bots can receive data
You can send data to a bot developer by interacting with their bot in any of the following ways:
- by sending messages to a bot;
- by using an inline bot;
- by taking part in a group that contains a bot;
- by pressing buttons in messages sent by a bot.
6.3. What data bots receive
In any of the situations above, the developers of a bot may obtain your screen name, your username and your profile pictures (see 3.1 above). When you communicate with bots, they may also receive the following:
- a message you send to a bot;
- your IP address, if you click a link or a button the bot provides and the bot owns the website the link points to;
- the fact that you are a member of a particular group, if the bot belongs to the same group;
- your query to an inline bot: when you start a message with an inline bot’s username, such as @gif, every character you type is treated as a command to that bot and is sent to it so that it can do its job. We warn you about this the first time you use an inline bot.
Bots added to groups can work in two modes: with access to group messages, or without it. A bot with access to messages can see everything that happens in the group. The interface makes it clear which mode a bot is in.
6.4. Bots are not maintained by Sayli
Apart from our own bots, no bots and no independent bot developers are associated with Sayli. They are entirely separate from us. They should obtain your consent before they access your data or before you make it available to them.
8. Your rights regarding the personal data you provide to us
8.1. Your rights
In certain situations, applicable data protection legislation gives you rights regarding your personal data. You have the right to:
- request a copy of all the personal information we hold about you, and have that copy transmitted to another data controller;
- delete (see section 9 below) or modify your personal information;
- restrict, or object to, the processing of your personal information;
- have any inaccurate or incomplete personal information we hold about you corrected;
- file a complaint with the national data protection authority about the way we process your personal information.
8.2. Exercising your rights
If you would like to exercise any of these rights, write to us at [email protected].
8.3. Data settings
In our mobile apps you can manage the way your data is used — for example delete synced contacts — in Settings → Privacy & Security → Data Settings. Unfortunately we cannot offer you our services if you cannot accept Sayli’s modest minimum requirements. You can delete your Sayli account as described on the account deletion page.
9. Deleting data
9.1. Accounts
You can delete your account as described on the account deletion page. Deleting your account deletes all the messages, media, contacts and other data you store in the Sayli cloud. This cannot be undone.
9.2. Messages
When a message is deleted in a secret chat, the app on the recipient’s device is instructed to delete it as well.
In cloud chats you have at least 48 hours after sending a message to decide whether to delete it for everyone. In any other case, deleting a message removes it from your own message history only, and a copy remains on the server as part of your partner’s history until they delete it too; once they do, it is gone for good.
In one-to-one chats, either party can delete both sent and received messages at any time, with no time limit. Either participant can also delete the whole chat history for both sides, in which case the apps are instructed to do so no matter how many messages the other party would have kept.
In channels and supergroups a message can be deleted for all users. Note that supergroups keep deleted messages, and the original versions of edited messages, for 48 hours, so that they can be shown in the admin log.
9.3. Self-destructing messages
Messages in secret chats can be set to disappear. The countdown starts as soon as such a message is read and two check marks appear. When the timer expires, both devices in the secret chat are instructed to delete the message, photo or video. Previews of media with short timers, under a minute, are blurred; the timer starts when they are viewed.
9.4. Account self-destruction
By default, if you stop using Sayli and stay offline for at least six months, your account and all the messages, media, contacts and other data you store in the Sayli cloud are deleted. You can change the exact period after which an inactive account self-destructs in Settings.
10. Changes to this Privacy Policy
We may update this Privacy Policy from time to time — for example when we add new features, when we change the way we process data, or when new legal requirements apply to us.
We announce material changes in the app and on sayli.chat at least 14 days before they take effect, and we update the date at the top of this page. Continuing to use the service after a change has taken effect means that you accept the updated version. If you do not accept it, you can delete your account at any time.
11. Company details
Sayli is published and operated by Krystyna Starodub, an individual developer based in Ukraine.
Contact: [email protected].
Privacy questions: [email protected]. See also the Terms of Service and how to delete your account.