Skalara

Privacy Policy

Last updated: September 1, 2026 · Version 1.0

This policy explains what Skalara collects, why, who else can see it, and what you can ask us to do about it. It describes how the service actually works rather than what a template would say, so where the answer is uncomfortable it is written plainly.

The short version

  • We identify your account by your phone number. You cannot use Skalara without one.
  • Your messages are encrypted where they are stored. They are not end-to-end encrypted — see “How your messages are protected”, which explains exactly what that means.
  • We do not sell your data, and we do not use it for advertising or profiling.
  • We keep some records because Iranian law requires it, and we hand over data when a judicial authority lawfully orders it.
  • You can see your data, correct it, and delete your account from inside the app.

Who is responsible for your data

Skalara is run by Poriya Hamidi as an individual rather than a company. A small number of people help build and moderate it, so throughout this policy “we” means that group — a handful of people, not a staffed organisation. If Skalara ever becomes a company, this section will say so.

Under Iranian law Poriya Hamidi is the party answerable for the personal data described here; under the GDPR, the “controller”.

For anything in this policy, including requests about your own data, write to support@skalara.ir. We answer within 30 days.

The law this policy follows

Iran has no single data protection act. The Personal Data Protection Bill drafted in 2018 has still not been passed, so the rules that bind us are spread across several statutes. Skalara is built for people in Iran, so Iranian law is the floor:

  • Article 25 of the Constitution, which forbids inspecting correspondence, recording or disclosing telephone conversations, eavesdropping, and covert investigation, except where the law provides otherwise.
  • The Electronic Commerce Law (1382/2003). Article 58 forbids storing, processing or distributing sensitive personal data without explicit consent. Article 59 permits processing other personal data with consent, only for stated purposes, only to the extent needed — and gives you the right to see your data, correct it, and have it deleted. Article 71 makes a breach of Article 58 a criminal offence carrying one to three years’ imprisonment.
  • The Computer Crimes Act (1388/2009), which criminalises unauthorised access and interception, and in Article 32 requires service providers to retain traffic data and subscriber information for a defined minimum period.
  • The Citizens’ Rights Charter (1395/2016), which is a statement of government policy rather than binding law, and whose privacy provisions we follow as a floor rather than a ceiling.

Where a global standard is stricter than Iranian law, we apply the stricter one. In practice that means we follow the GDPR’s approach to purpose limitation, data minimisation, transparency and your rights, whether or not you live somewhere the GDPR applies. If you are in the European Economic Area or the United Kingdom, the GDPR or UK GDPR applies to you directly under its extraterritorial scope, and the section on your rights sets out what that adds.

What we collect, and why

Everything below is either something you gave us or something the service produces while you use it. Nothing here is bought from a third party, and nothing is inferred about you for advertising.

WhatWhy we have itHow long we keep it
Phone numberIt is your account identifier and how we send you a sign-in code. We also store a keyed hash of it so we can check whether a number is already registered without scanning the numbers themselves.Until you delete your account.
Username, display name, avatar, banner, bio, pronouns, profile coloursThey are what other people see. You choose all of them and can change them.Until you change or delete them.
PasswordTo sign you in. We store an argon2id hash, never the password itself, so we cannot read it or recover it for you.Until you change it or delete your account.
Passkeys and authenticator (TOTP) enrolmentStronger sign-in that does not depend on SMS. For a passkey we hold only the public key and a label you choose; the private key never leaves your device. A TOTP secret is stored encrypted.Until you remove the credential.
Backup codesA way back in when you lose your phone. Stored hashed, so a copy of our database does not yield working codes.Until you generate a new set, which invalidates the old one.
Messages, and the files you attach to themTo deliver them. Message text is encrypted before it is stored; attachment bytes are encrypted before they are written to object storage.Until you or the other participant deletes them, or you delete your account.
Who you talk toConversation membership, friendships, friend requests and blocks are what make the service work at all.Until the relationship ends or you delete your account.
Sessions and devicesTo keep you signed in and to let you sign out of a device you no longer have. We store a hash of each session token plus the browser and operating system it reported.Until the session expires or you sign it out.
IP addressTo apply rate limits and to keep a security record of account changes. It is stored as a keyed hash, not in the clear, so the audit trail can recognise a repeat address without holding a list of addresses.With the security record it belongs to.
Security eventsA record of sign-ins, password changes, passkey removals, suspensions and similar. It exists so you and we can tell whether something happened that should not have.See “How long we keep things”.
Online statusSo your friends can see whether you are around. Held in memory with a short expiry, never written to permanent storage. Setting yourself invisible reports you to everyone else as offline.Minutes. It disappears on its own.
Reports you file about a messageSo a moderator can act on it. A report contains an encrypted copy of the reported message, because the author can delete the original and a report that emptied itself would make deletion a way to escape moderation.See “How long we keep things”.
Payment recordsTo give you what you paid for and to keep the accounting records the law requires. We store the plan, amount, date and the gateway’s reference. Card details are entered on the gateway’s own page and never reach us.As long as tax and accounting rules require.

What we do not collect

  • Your location. Skalara never asks for it, and the browser is told it may not provide it.
  • Your contacts or address book.
  • Card numbers, bank details or any other payment credential.
  • Advertising identifiers, cross-site trackers, or any third-party analytics. There are none on this site or in the app.
  • Anything about your ethnicity, religion, political views, health or sexual life. Article 58 of the Electronic Commerce Law makes handling such data without explicit consent a criminal offence, and we have no reason to ask for it. If you put such information in your profile or your messages, you are choosing to, and this policy treats it like any other content you wrote.

The only cookies Skalara sets are the ones that keep you signed in and protect the sign-in forms. Nothing optional is set, so there is nothing to consent to.

How your messages are protected

Message text and attachments are encrypted with AES-256-GCM before they are written to disk, under a key derived separately for each conversation. Our database holds ciphertext; the object storage that keeps your files holds nothing readable. Connections between your device and our servers are encrypted in transit.

Skalara is not end-to-end encrypted. The keys are derived from a secret held on our servers, which means our servers can decrypt your messages — and so features like search across your own history work. It also means a court order compelling us to produce message content is something we could technically comply with, and that an attacker who obtained both our database and our key material could read messages. We would rather say this plainly than let the word “encrypted” imply a protection you do not have.

Access to that key material is restricted to the running service. We do not read your messages, and no routine process at Skalara exposes message content to a person. The exceptions are narrow and are set out in the next two sections: a message you report, and a lawful order.

Who else sees your data

We do not sell your data and we do not share it for anyone’s marketing. These are the only parties that handle it, each for one job:

WhoWhat they receiveWhy
LiaraEverything the service stores, because they host it.Hosting and database infrastructure, inside Iran.
ArvanCloudYour connection metadata, including your IP address, as traffic passes through.Content delivery and protection against denial-of-service and application attacks. Your browser reaches ArvanCloud, never our origin servers directly.
SMS.irYour phone number and the verification code being sent to it.Delivering sign-in and verification codes.
ZarinPalThe payment amount and a reference, plus whatever you enter on their page.Taking payment. Card details are entered on ZarinPal’s own page and never pass through Skalara.

Each of these acts on our instructions for the purpose named, and none of them is permitted to use your data for their own ends. All of them are Iranian providers, which is deliberate.

When we have to hand data to the authorities

The Computer Crimes Act requires service providers in Iran to retain certain traffic data and subscriber information, and empowers a judicial authority to order that data be produced. Where we receive an order that is lawful on its face and issued by an authority with jurisdiction, we comply with it.

What we will not do is volunteer your data, hand over more than an order actually demands, or give anyone standing access. We disclose the narrowest set of records that answers the order. Where we are legally permitted to tell you that your data was requested, we will.

You should read this section together with the one above about encryption. Together they describe the real limit of what Skalara can protect you from, and we would rather you decided what to say on the service knowing that.

Why we are allowed to process your data

Under Article 59 of the Electronic Commerce Law we process your personal data on your consent, for purposes stated to you at the point of collection, and only to the extent those purposes need. Creating an account is that consent; this page is that statement of purpose.

Under the GDPR, for readers to whom it applies, the bases are:

  • Performance of a contract (Article 6(1)(b)) for your account, your profile, your messages and anything you paid for — without this data there is no service to give you.
  • Legitimate interests (Article 6(1)(f)) for security records, rate limiting and abuse handling. Our interest is keeping accounts from being taken over and the service from being used to harass people; we use hashed rather than plain identifiers so that interest is served with as little data as possible.
  • Legal obligation (Article 6(1)(c)) for the records Iranian law requires us to retain and for lawful disclosure orders.
  • Consent (Article 6(1)(a)) for anything optional, which you can withdraw at any time without losing access to the rest of the service.

How long we keep things

The table above gives the period for each kind of data. Three cases are worth stating separately:

  • Deleting a message removes its content, including the encrypted bytes of any file attached to it. This is not a hidden flag: the content is gone and we cannot restore it for you.
  • Deleting your account removes your profile, your settings and your credentials, and detaches your name from what you sent. A minimal record that the account existed is retained where the law requires it — for example so that a payment record remains reconcilable — and that record does not carry your profile.
  • Security and traffic records are retained for the minimum the Computer Crimes Act requires and are then removed. We do not keep them longer in case they turn out to be useful.

Your rights, and how to use them

Article 59 of the Electronic Commerce Law gives you the right to see the personal data we hold about you, to correct what is wrong or incomplete, and to have it deleted. Most of this is in the app rather than behind a form, because a right you have to ask for is a right most people never use:

  • See and correct it — Settings → My Account holds your profile, and Settings → Security lists your sessions, passkeys and recent security events.
  • Delete it — Settings → My Account → Delete account. This is immediate and cannot be undone.
  • Take it with you — write to us and we will send you your data in a machine-readable format.
  • Object or restrict — write to us and tell us what you object to; we will stop unless we have grounds that override yours, and we will tell you which.
  • Withdraw consent — for anything optional, in Settings; withdrawal applies from that point and does not undo what was lawful before it.

Requests by email go to support@skalara.ir and are answered within 30 days. We will ask you to prove you control the account, because handing someone else’s data to whoever asks would be the worse failure.

If you are in the EEA or the UK you additionally have the rights of GDPR Articles 15 to 22, including portability and the right not to be subject to solely automated decisions with legal effect. Skalara makes no such decisions: account suspension follows a human moderator reviewing a report.

How we protect it

  • Passwords are hashed with argon2id. We cannot read them, and neither can anyone who steals the database.
  • Message content and attachments are encrypted at rest, as described above.
  • Session tokens are stored as hashes and rotate on every refresh. Reusing a retired token revokes the whole session family, so a stolen token is detected rather than quietly enjoyed.
  • Sign-in offers passkeys and an authenticator app in addition to SMS, because SMS is the weakest of the three and a SIM swap defeats it.
  • Sensitive account changes require your password, and some require a code as well.
  • Traffic reaches us through ArvanCloud’s protection layer; our origin servers are not directly addressable.
  • Rate limits apply per account and per address, so neither one can be used to hide behind the other.

No service can promise this is enough. If a breach occurs that is likely to put you at risk, we will tell affected users and the relevant authorities without undue delay — and within 72 hours where the GDPR requires it.

Age

Skalara is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has an account, write to us and we will remove it. Where local law sets a higher age for consenting to online services on your own, that age applies to you instead.

If you are outside Iran

Skalara is hosted in Iran and your data is processed there. Iran has not been found by the European Commission to provide an adequate level of data protection, so if you are in the EEA or the UK, using Skalara means your personal data is transferred to a country without an adequacy decision. We are telling you this so the choice is yours to make. The protections in this policy apply to you wherever you are.

Changes to this policy

When we change something that matters — a new purpose, a new recipient, a longer retention period — we will tell you in the app before it takes effect, not by quietly editing this page. The version and date at the top always describe what you are reading.

Complaints

If you think we have handled your data wrongly, tell us first at support@skalara.ir — it is the fastest way to get it fixed. You may also raise it with a competent authority. In Iran, breaches of Article 58 of the Electronic Commerce Law are criminal matters and can be raised with the judicial authorities. If you are in the EEA or the UK, you may complain to your national supervisory authority.