Tuijo Tuijo
Features Security FAQ
IT EN ES CA
Download
Your privacy is our priority

Privacy policy.

Tuijo is built from the ground up so it can't read what you write to each other. Here is exactly which data we handle and which we don't.

Last updated: 11 September 2026 Version: 1.1

1. Introduction

Welcome to the privacy policy of Tuijo. Tuijo is a private messaging app designed specifically for couples, with advanced end-to-end encryption (RSA-2048 + AES-256).

Your privacy is fundamental to us. This policy explains which data we collect, how we use it and what rights you have over your personal data.

๐Ÿ” Core principle

Zero-knowledge architecture: thanks to end-to-end encryption, your messages, photos and documents are readable ONLY by you and your partner. Not even we, the developers, can access your content.

2. Data we collect

2.1 Encryption system

Tuijo uses an asymmetric key-pair encryption system (RSA-2048) to guarantee maximum security and privacy:

  • Personal private key: generated automatically on your device and never shared with the server. It always stays on your device only, protected by the operating system (Keychain on iOS, Keystore on Android). It is required to decrypt the messages you receive.
  • Public key (QR code): generated together with the private key and shared with your partner via QR code during pairing. It is used by your partner to encrypt messages meant for you. It can be shared safely because it only encrypts, it cannot decrypt.
Important: we do not store any personal authentication information (email, user ID, password). The system relies solely on the cryptographic keys generated locally on your device.

2.2 Location (only when you share it)

Tuijo uses the device location exclusively when you start the "Share location" feature from the chat. We never collect your location at any other time, nor in the background without an active share.

  • What is processed: GPS coordinates (latitude and longitude), accuracy and heading.
  • How: coordinates are encrypted on your device with AES-256 before being sent. The server only stores the encrypted data, together with the time and the expiry of the share. Not even we can see where you are.
  • For how long: you choose the duration (1 or 8 hours) and the mode (live location or a single location). When it expires, or when you stop sharing, updates stop and the location is marked as no longer active.
  • In the background: during a live share the app keeps updating your location even if you lock the screen or switch to another app, showing a persistent notification (Android) or the system indicator (iOS). If you close the app, sharing stops.
  • Who sees it: only your partner, on their device, to compute distance and direction.
Full control: you can stop sharing at any time from the app and revoke the location permission in the system settings. Everything else in the app keeps working.

2.3 Messages and content (encrypted)

  • Encrypted messages: message text encrypted with AES-256.
  • Encrypted attachments: photos, videos and documents encrypted end-to-end.
  • TODOs and reminders: shared reminders and notes (encrypted).
  • Metadata: send timestamp, message ID, message type (text/attachment/TODO).
Important note: all content (messages, attachments, TODOs) is end-to-end encrypted. We only store encrypted data that we cannot read without your private keys, which are stored ONLY on your device.

2.4 Technical data

  • FCM token: token for Firebase Cloud Messaging push notifications, required to send notifications when you receive new messages.
  • VoIP token (iOS only): Apple PushKit token used to ring your phone when you receive a call, even when the app is closed.
  • Platform: the device operating system (iOS or Android), to pick the right kind of notification.

2.5 Voice calls

Voice calls are peer-to-peer (WebRTC): audio travels directly between the two phones, encrypted (DTLS-SRTP), and never passes through or gets recorded on our servers. The server is only used to let the two devices find each other (signalling): that data is itself end-to-end encrypted and is deleted when the call ends. Because the connection is direct, the two devices exchange their IP addresses, visible only to your partner.

2.6 Device permissions

Tuijo asks for these permissions, always and only at the moment you use the corresponding feature:

  • Location: for location sharing (see 2.2).
  • Microphone: for voice calls. It is never activated outside a call.
  • Camera: to scan the QR code during pairing, take photos to send and take the couple selfie. No image is processed without an action from you.
  • Photos and files: to attach photos or documents you choose; they are encrypted before sending.
  • Notifications: to alert you about messages, reminders and incoming calls.
  • Contacts, address book, calendar, SMS: never requested.

3. How we use data

3.1 Main purposes

  • Provide the service: sync messages between your devices and your partner's.
  • Notifications: send push notifications when you receive new messages or reminders.
  • Calls: connect the two devices for a direct voice call.
  • Location: show your partner where you are, only for the duration of a share you started.
  • Security: maintain the integrity and security of the pairing system.
  • Improvements: fix bugs and improve the app's features.

3.2 What we do NOT do with your data

  • We don't read your messages (impossible thanks to E2E encryption).
  • We don't sell your data to third parties.
  • We do not track your location and never store it in clear text: it is used only during a share you started, encrypted.
  • We don't use your data for targeted advertising or profiling.
  • We don't share your content with anyone (except legal cases, see section 5).

4. Encryption and security

4.1 Encryption architecture

Tuijo uses a two-layer encryption system:

  • RSA-2048: for the secure exchange of public keys during pairing.
  • AES-256: for the encryption of messages and attachments.
  • Unique key per message: every message has a randomly generated, unique AES key.

๐Ÿ”‘ Your private keys

Your RSA private keys are stored EXCLUSIVELY on your device using flutter_secure_storage, an encrypted storage system protected by the operating system (Keychain on iOS, Keystore on Android). Not even we can access them.

4.2 Security measures

  • HTTPS/TLS: all communications between app and server use secure, encrypted connections.

5. Data retention and deletion

Data deletion can be carried out directly from the app by either of the two partners. Both partners have full control over the shared data and can delete it at any time.

Location data has an expiry you choose (1 or 8 hours): once expired it is no longer updated and remains only in encrypted form, unreadable without the keys on your devices, until you delete the data from the app. Call signalling data is deleted at the end of every call.

6. Contact

For privacy questions or requests, you can contact us:

  • Email: info@tuyjo.com

๐Ÿ’œ Our commitment

Privacy is at the heart of Tuijo. We designed the app from scratch with end-to-end encryption to ensure your conversations stay private between you and your partner. We will keep protecting your privacy as a core principle.

Back to home
Tuijo Tuijo

Tu y yo โ€” you and I. The private, encrypted messaging made only for couples.

App

Features Security How it works FAQ

Download

App Store Google Play

Legal

Privacy Policy Support
ยฉ 2026 Tuijo ยท All rights reserved Made with ๐Ÿ’ for those who are happy as two