Privacy Policy
Last updated 27 September 2026
ice9 is a messenger. This page describes what the service stores, why, for how long, and who else ever sees anything. It describes what the software does today — not what it is meant to do one day. Where the honest answer is uncomfortable, it is written down anyway.
1. Who is responsible
The ice9 service is operated by the team that publishes the ice9 apps (“we”, “us”). For anything in this policy, including any request about your data, write to [email protected]. We are the controller of the personal data described below.
2. Why we are allowed to process your data
- To provide the service you asked for. Delivering a message requires storing it until it arrives; running an account requires a phone number. This is the performance of our agreement with you, set out in the Terms of Service.
- Our legitimate interest in a service that works and is not abused: keeping the system up, finding faults, and stopping spam and attacks.
- Your consent, where the app asks for it explicitly — access to your address book, and permission to send notifications. Consent can be withdrawn at any time in your device settings, and withdrawing it stops that processing.
3. What we process
- Your phone number. Required: it is how an account is created and how other people find you. There is no way to use ice9 without one.
- Your profile: name, username, photo — whatever you choose to put there.
- Your messages and the files you send: text, photos, videos, voice and video messages. They are stored on our servers so they reach your other devices and the person you wrote to — end-to-end encrypted, with the exceptions listed in section 5.
- Your contacts, only with your permission. If you allow access to your address book, the phone numbers and names in it are sent to us so we can tell you who already uses ice9. We keep the numbers and names of the people who do; the others are not stored. Refuse the permission and nothing is sent. We do not use those numbers to contact anyone.
- People you invite: the number an invitation is for, and who invited whom. An invitation opens only the account it was made for, and this is how.
- Your calls: who called whom, when, and for how long — the list of calls in the app is built from it. The call itself goes between the phones, encrypted.
- How you connect: device model, app version, language, IP address, and when you were last active. This is what the list of active sessions in the app is built from, and it is how a stranger signing into your account becomes visible to you.
- A notification token issued by Apple or Google, so a message can reach your device while the app is closed.
- Server logs recording what happened — the kind of each request, errors, IP addresses and timestamps — without the content of requests. A failed request can appear in its error record, except one that carries a phone number or a name.
4. What we never do
- No advertising, and no profile of you assembled for anyone to target.
- No analytics and no crash telemetry. The app offers its usage log to the server; the server accepts it and discards it without reading it.
- No selling, renting or sharing your data with anyone for their own purposes.
- No scanning of your messages for any purpose of ours.
5. Encryption, stated plainly
Chats are end-to-end encrypted with MLS, the IETF standard (RFC 9420). Your phone encrypts each message and file before it leaves, and only the devices in that conversation hold the keys to open it. Our servers keep and forward what they cannot read. The encryption code is open: github.com/dsfox/ice9-mls.
What the servers still see, and where the encryption does not reach today:
- Who writes to whom, when, and how much. Delivering a message needs it.
- Your profile — name, username, photo — and the names and photos of groups.
- Saved Messages, your chat with yourself.
- A location you share and a contact card you send.
- A message sent when the other side cannot take part in the encryption in time — they have no device that can, or setting it up takes more than about ten seconds. It is sent readable rather than not at all, and a file forwarded from such a message stays readable too.
- The records of calls described in section 3.
6. Where your data is kept
The servers are operated by JSC Timeweb and located in Russia. Everything described in section 3 is stored there.
ice9 is not offered in the European Economic Area or the United Kingdom. We do not market it there and it is not available from the app stores of those countries — see section 2 of the Terms of Service. We would rather stay out of a market than pretend to protections we cannot give from where the servers stand.
Wherever you are, know what it means that the data sits in Russia: it is held under Russian law, and the safeguards and remedies of European data protection law are not available to you here.
7. Who else sees anything
- Apple and Google, which deliver notifications. They receive your device token, the number of unread messages, the numeric id of the account that wrote, and a sealed blob only your phone can open. No message text and no name — the notification says “New message”, and your phone fills in the rest from the sealed blob.
- Our notification relay, push.ice9.app, when the server you use is not ours: it receives your device token, a count and a sealed blob only your phone can open, forwards them to Apple or Google, and keeps nothing. It never sees a name or a word.
- Our hosting provider, which operates the machines and therefore has physical access to them.
- Authorities, where we are compelled by a valid legal demand under the law that applies to us. We have not received one to date. If that ever changes in a way we are permitted to describe, this page will say so.
Nobody else. There are no advertising partners, data brokers or analytics providers, because there is no advertising, no data trade and no analytics.
8. How long we keep things
- Messages and files: until you or the person you wrote to delete them, or until the account is deleted.
- Profile and account data: for as long as the account exists.
- Session records: until you end that session or it expires.
- Server logs: they are rotated by size, which today means a day or two.
- Backups: a full copy of the database and the files is made every night and replaces the one before; there is no other copy. What you delete is gone from it by the next night.
9. Your rights
Wherever you are, you can ask us to:
- tell you what we hold about you, and give you a copy;
- correct anything wrong;
- delete your data (see section 10);
- restrict or object to a particular use of it;
- hand it over in a portable form, or send it to someone else.
Write to [email protected]. We answer within 30 days and charge nothing. These are the rights European law gives people there; we give them to everyone, because they are the right rights to have and not because someone makes us. If you think we have handled your data badly, you may also complain to the data protection authority where you live.
10. Deleting your account
You can end your account yourself. The steps for each platform are at ice9.app/delete-account.
Deleting removes your profile and username, releases your phone number, and signs out every device: the account stops existing and nobody can reach you through it.
Your message history, the files you sent, the address book you uploaded, your settings and your device tokens are erased from our servers as part of the same request — in one transaction, so it either all goes or the account stays and you are told.
What stays: a record that the account existed and was deleted, without your number, and the invitations that name you. The nightly backup still holds the rest until the next night replaces it (section 8).
One more honest caveat. Messages you already sent are copies that now live with the people you sent them to, and deleting your account does not reach into their apps — that is true of every messenger.
11. If something goes wrong
If personal data is lost or exposed, we will notify the competent supervisory authority within 72 hours of becoming aware of it — the deadline European law sets, which we hold ourselves to — and we will tell the people affected directly — in the app and by whatever contact we have — where the breach is likely to put them at risk. We will say what happened, what it means for you, and what we are doing about it, rather than the minimum we can get away with.
12. California
If you live in California: we do not and will not sell or share your personal information, and there is nothing to opt out of. In the past twelve months we have collected the categories described in section 3 — identifiers, your content, and internet activity — for the purposes stated there, and we have disclosed none of them for any commercial purpose. Your rights to know, delete, correct, and not be discriminated against for exercising them are the same rights set out in section 9; write to [email protected] and we will answer within 45 days.
13. Children
ice9 is not for people under 13, and in countries where the law sets a higher age for consenting to the processing of personal data — 16 across much of the European Economic Area — not for anyone below that age. We do not knowingly keep an account for a child. If you believe one exists, write to us and it will be removed.
14. Changes to this policy
When this policy changes, the new version appears here with a new date at the top. If a change alters what we collect or who sees it, the app will say so before it takes effect.
15. Getting in touch
Anything at all: [email protected].