Privacy Policy
Last updated: August 21, 2026
Buko (“the App”) is operated by NIXLIGHT TECHNOLOGY LIMITED (“we”, “us”). This policy explains what we collect, how we use it, and your choices. Buko is a lightweight messenger; we do not show ads and we do not sell your personal data.
1. Information we collect
- Account & profile. Your email address (used to send a one-time login code), initial sign-in method and provider identifiers if you use Apple or Google sign-in, and profile details you provide: display name, optional username/handle, avatar, cover image, and bio.
- Invites. If invite access is enabled, invite codes you create or redeem, to manage registration access and abuse prevention.
- Messages & media. The content of messages and photos you send. Message history is stored primarily on your device; our servers keep a transient delivery buffer for up to 60 days. Media files are stored in object storage (chat media and Moments images for up to 60 days; profile/cover/group images are retained while in use).
- Moments. Posts (text and photos) you publish to your contacts; retained for up to 60 days.
- Device, sign-in & notifications. A per-install device identifier, app/device/OS information, sign-in time, IP address and approximate region, and a push notification token. We use these details to secure accounts, prevent abuse, diagnose compatibility issues, and deliver notifications.
- Calls. For voice/video calls we relay signaling and media through a third-party real-time network. We do not record calls.
- Diagnostics. Crash and error reports (which may include device model, OS version, and stack traces) to keep the App stable. These do not include your message content.
- Product usage. Bounded events about app launches and interactions with conversations, messages, calls, Moments, Plaza, Kits, official Bots, and support tickets. These events contain closed categories rather than message content, media, names, handles, search terms, amounts, prompts, or precise event times. A keyed pseudonymous daily identifier is used briefly to count daily active accounts; it is not stored with an action or event.
2. How we use information
- To provide messaging, calls, Moments, and notifications.
- To authenticate you and keep your account and the service secure (including anti-abuse and moderation).
- To diagnose crashes and improve reliability.
- To understand aggregate feature usage and decide how to improve and maintain the product.
- To respond to support requests and reports.
3. Service providers
We share the minimum necessary with infrastructure providers that process data on our behalf:
- Cloudflare — hosting, database, object storage, and real-time/calling infrastructure.
- Apple — push notification delivery (APNs).
- Resend — sending login verification emails.
- Sentry — crash/error diagnostics.
We do not sell your data and do not share it for advertising.
4. Retention
Locally stored history remains on your device until you delete it or uninstall. On our servers, the message delivery buffer, Moments, and chat media are automatically removed within 60 days. Product-usage events are immediately reduced to identity-free daily aggregates retained for up to 180 days. Short-lived keyed or opaque pseudonymous records support counting, batching, abuse limits, and retry safety: daily uniqueness and account/device session-window keys remain for up to 48 hours, account rate-limit keys for up to one hour, and retry or operation deduplication keys for up to 31 days. These records contain no event content or raw account or device identifier. Account sign-in and device information is retained while your account exists. When you delete your account, we remove your profile, sign-in metadata, login bindings, sessions, push tokens, avatar, and your Moments. Existing contact references, group membership, and group ownership may remain under a generic “Deleted User” identity so shared records are not corrupted. Ownership is not transferred automatically. The group or channel remains visible to surviving members and continues under its existing role and posting rules; capabilities that require an owner or admin may no longer be available. A space is dissolved only after no live human members remain. Ordinary human accounts with no authenticated activity for one year may be deleted. Before scheduling that deletion, we must successfully send a warning email at least 30 days before the earliest deletion date. Any authenticated activity during that period cancels the scheduled deletion. If the warning email cannot be delivered, the deletion countdown does not begin. Copies already delivered to participants’ devices are outside Buko’s control and may remain there, including screenshots or exported copies. Non-reversible keyed digests of deleted sign-in identities are retained for 24 hours to prevent repeated delete-and-register abuse, then removed. Registering again after that cooldown creates a separate new account and does not restore prior data or relationships.
5. Your choices and rights
- Access & correction. View and edit your profile in the App.
- Deletion. Delete your account from in-app Settings. Your profile and personal account data are removed; shared records may remain visible as “Deleted User” as described above.
- Blocking & reporting. Block users and report content; reported content enters a moderation queue.
- Notifications. Control push permissions in your device settings.
6. Security
All network traffic uses HTTPS/TLS. Sensitive data on your device is stored using the platform keychain/keystore. Access to backend systems is restricted.
7. Children
Buko is not directed to anyone under 18 (or the minimum age required in your region, if higher). If you are under that age, please do not use the App.
8. International processing
Our infrastructure is global; your information may be processed in countries other than your own, with appropriate safeguards.
9. Changes
We may update this policy. Material changes will be reflected on this page with a new “Last updated” date.
10. Contact
Questions? Email support@buko.app.