WAYA
Home Privacy Terms Delete account

ON THIS PAGE

Who we are Data we process Service providers Retention Your rights Security Contact
PRIVACY AT WAYA

Privacy Policy

A clear account of what WAYA processes, why it is needed, and the choices you have.

Last updated: 30 July 2026 • Effective: 30 July 2026

Important. This is the current public WAYA Privacy Policy. We are reviewing it with qualified privacy counsel and will update it when needed. Questions or corrections: privacy@wayahq.com.

1. Who we are

WAYA ("we", "us") is operated by Charles Mensah (sole proprietor) based in Ghana. You can reach us at privacy@wayahq.com.

2. What WAYA is

WAYA is a mobile communication app — voice calls, messaging, and voice notes — built for African networks. Current messages and uploaded media are not application-layer end-to-end encrypted. WAYA's service can process and read this content when needed to operate, secure, or support the service. Application-layer E2EE is planned but is not currently available.

3. Data we process

You give us:

  • If you join the launch waitlist, your name, email address, and the page or campaign source associated with the submission.
  • Your verified email address, which is the primary sign-in identifier, and the password you choose. Passwords are stored only as one-way Argon2id hashes; we cannot view your password.
  • Your phone number, if it is attached to a legacy account or you provide it for an optional phone-based feature. A phone number is not required for current email/password registration.
  • Your display name and (optional) profile photo.
  • Contact-discovery digests. The app normalizes and SHA-256 hashes selected phone numbers on your device, then sends only those first-stage digests to our API over authenticated TLS. The API applies a second keyed hash with a server-only salt before lookup and persistent storage.
  • The text of messages you send. It is protected in transit with TLS and stored in a server-readable representation.
  • Voice notes, images, videos, PDFs, profile photos, and other files you upload. WAYA authorizes access and stores the objects privately. When B2 media storage is active, encrypted objects are held by Backblaze B2 and are readable by the service.
  • Call audio is routed through WAYA's self-hosted LiveKit service to provide WebRTC calls. Calls use WebRTC transport encryption, but WAYA does not currently provide application-layer call E2EE.

We collect automatically:

  • For launch-waitlist abuse prevention, keyed hashes derived from the request IP address and browser/user-agent. We do not store the raw IP address or raw user-agent with the waitlist entry.
  • A device installation identifier and, when notifications are enabled, an APNs or FCM push token used only to deliver WAYA notifications.
  • A platform/session label supplied by the app, plus request information such as IP address and browser/user-agent, for session security, compatibility, and troubleshooting.
  • Connection metadata (when you came online, which conversation a message belongs to, message timestamps) needed for delivery.
  • Operational and diagnostic events needed to secure, troubleshoot, and improve the service.

We do not collect:

  • Your raw address-book phone numbers or contact names; contact discovery sends only on-device SHA-256 digests.
  • Your precise location.
  • Advertising identifiers (IDFA / GAID).

4. Why we process it

  • Launch updates — maintain the waitlist and contact people who asked to hear when WAYA launches. Legal basis: consent.
  • Service operation — deliver messages, route calls, send notifications. Legal basis: contract.
  • Account security — email verification, password authentication, session management, and abuse detection. Legal basis: contract and legitimate interest.
  • Product improvement — aggregate service reports, operational diagnostics, and feedback used to understand reliability and improve the product. Legal basis: legitimate interest.
  • Legal compliance — respond to lawful requests, prevent fraud.

5. Who we share with

We share only the minimum necessary, with:

ProcessorPurposeRegion
Hetzner Online GmbHApplication, database, calling, and temporary migration-copy hostingGermany
Backblaze, Inc.Private encrypted storage of customer images, profile photos, voice notes, videos, PDFs, and attachments when B2 media storage is activeBackblaze data region __WAYA_B2_DATA_REGION__
LiveKit open-source software on WAYA infrastructureVoice-call WebRTC processing and routingGermany
Cloudflare, Inc.DNS, proxy, CDN, TLS edge, and WAFGlobal
Selected email delivery providerAccount verification, password reset, and service email, when transactional email is enabledProvider-dependent
Apple Inc.Push notifications (APNs)Global
Google LLCPush notifications (FCM)Global
Paystack Payments Ltd.Legacy payment records and refunds only; WAYA no longer accepts new client paymentsNigeria/Ghana

We do not sell personal data. We do not share data for advertising.

6. Where data is stored

The primary PostgreSQL database and LiveKit calling service are on WAYA's self-hosted Hetzner server in Germany. When B2 media storage is active, customer media is stored in a private Backblaze B2 bucket in data region __WAYA_B2_DATA_REGION__, encrypted in transit and at rest. During migration, checksum-verified local copies may remain on Hetzner for up to 14 days before deletion. Cloudflare processes proxied traffic at its global edge. Encrypted PostgreSQL backups are separate from the media bucket and retained under a rotating operational schedule, normally for up to 14 days. Cross-border transfers are governed by appropriate safeguards where required.

7. How long we keep it

  • Launch waitlist: up to 24 months after the most recent submission, or until you ask us to remove it. Keyed abuse-prevention request hashes expire after 90 days.
  • Account data: while your account is active. Account deletion removes the live account immediately; residual database copies may remain in encrypted backups until they rotate out, normally within 14 days.
  • Message content: retained while needed to provide conversation history and removed when you delete your account, unless applicable law requires longer retention.
  • Voice notes and media: retained while needed to provide conversation history and removed when you delete your account, unless applicable law requires longer retention.
  • Email-delivery log metadata: 90 days. Other operational logs are kept only for the applicable security and troubleshooting period.
  • Account-detached or pseudonymised financial, fraud-prevention, safety, deletion-receipt, or audit records: retained as required for legal compliance, abuse prevention, and service integrity. Financial records may be retained for up to 7 years where tax law requires it.

8. Your rights

You can:

  • Access the data we hold about you — contact privacy@wayahq.com.
  • Correct your profile information in the app.
  • Delete your account — Profile/Settings → Delete account. This removes the live account, user messages, social data, sessions, and customer media from each active storage provider. External object deletion remains pending until the exact stored version is permanently deleted; failures are durably queued for retry. Encrypted database backups rotate out normally within 14 days, and account-detached or pseudonymised financial, fraud-prevention, safety, deletion-receipt, or audit records may be retained where required.
  • Object to processing — email privacy@wayahq.com.
  • Lodge a complaint with your data protection regulator (Ghana DPC, Nigeria NDPC, EU DPAs).

9. Children

WAYA is not for users under 13. If you are between 13 and 16 you may need parental consent depending on your country.

10. Security

WAYA uses TLS for app and web traffic. Self-hosted LiveKit calls use WebRTC transport encryption. Backblaze media objects use SSE-B2 encryption at rest when B2 storage is active. Current message content and uploaded media remain readable by the WAYA service; application-layer E2EE for messages, media, and calls is a roadmap feature and will not be advertised as available until it is implemented and independently reviewed.

No system is perfectly secure. Use a strong device PIN/biometric and keep your OS up to date.

11. Changes

We'll notify you in-app at least 14 days before any material change.

12. Contact

If you cannot use the in-app deletion control, see Delete your WAYA account and contact support from the verified email address on the account so we can verify and process the request.

  • Privacy: privacy@wayahq.com
  • Security: security@wayahq.com
Home Privacy Terms Delete account Support

© 2026 WAYA. Made by DGC (MCC).