7. End-to-End Encryption Notice
Effective date: April 03, 2025 Company: RAB CORP Pvt Ltd Service: SYNC
7.1 What end-to-end encryption means
End-to-end encryption helps protect your private conversations. When supported end-to-end encryption is active, your message is encrypted on your device before it leaves your phone. It is designed to be decrypted only on the device or devices of the person or group you send it to.
In simple terms: the message travels through our systems in encrypted form. For supported private chats, we are not able to read the plaintext content of your message while it is being delivered.
7.2 Where SYNC uses end-to-end encryption
SYNC uses end-to-end encryption for supported private one-to-one chats and supported group chats. Media and files shared in supported encrypted conversations may also be encrypted before upload or delivery, depending on the feature and app version.
SYNC uses security codes to help users verify contact identity keys. If a contact's secure identity key changes, supported app versions warn the user and block silent trust until the user verifies or explicitly accepts the new key.
Some features may not be protected in the same way, including public or semi-public channels, broadcasts, profile information, group names, user handles, support messages, reported messages, legal notices, and other information you choose to make visible or send to us. We will design the app to indicate feature behaviour where needed.
7.3 What we cannot see in ordinary operation
For supported end-to-end encrypted private messages, we do not see the plaintext content of your messages in ordinary operation. This means we generally cannot read the words, images, videos, audio, or files inside those encrypted private messages unless you or another participant voluntarily provides them to us, such as by reporting the message or sending it to support.
We do not provide a backdoor to your supported encrypted private messages. We do not give law enforcement, governments, advertisers, or third parties direct access to the plaintext of supported encrypted private messages that we do not possess.
7.4 What we can still see or process
End-to-end encryption protects message content, but it does not hide all information connected with the Services. We may still process information needed to run, secure, and protect SYNC, such as:
your phone number, email address, display name, user handle, profile information, and Account settings;
device information, authentication information, app version, push notification tokens, and security logs;
message metadata such as sender and recipient identifiers, message identifiers, timestamps, delivery status, group identifiers, file type, and encrypted payload information;
group, channel, broadcast, and profile information that is visible by design;
Reports, grievances, support messages, screenshots, and attachments you send to us;
decrypted copies of messages or media that a User voluntarily reports through the app;
information required for legal compliance, security, fraud prevention, abuse prevention, and service operation; and
records preserved in response to grievances, lawful requests, or cyber security incidents.
7.5 How abuse reporting works with encryption
Encryption should not protect abuse. If you receive harmful, illegal, abusive, impersonating, child safety, nude, morphed, threatening, spam, malware, or other prohibited Content, you can report it.
When you report a message or media item, the app may send us the selected reported Content and related details, such as message ID, sender information, group information, timestamp, media hash, and your complaint category. This allows us to review the Report and take action where appropriate.
Only the selected reported Content and relevant details are sent for review. Reporting a message does not give us automatic access to all of your conversations.
7.6 Lawful requests and encryption
We may receive lawful requests from courts, competent authorities, law enforcement agencies, government bodies, or CERT-In. We review such requests under our Law Enforcement Guidelines and Applicable Law.
Where we have information under our control or possession, such as account details, metadata, security logs, Reports, or voluntarily reported Content, we may provide it when lawfully required. For supported end-to-end encrypted private messages, we cannot provide plaintext message content that we do not have.
If we are legally required as a Significant Social Media Intermediary to enable identification of the first originator of information, we will handle such requests only in the manner permitted by Applicable Law. Such requests do not require us to disclose message content or information about unrelated Users beyond what law requires.
7.7 Your responsibilities
End-to-end encryption protects message delivery, but it cannot protect against everything. You are responsible for keeping your device, app, Account, OTPs, passwords, and screen access secure.
People who receive your messages can still screenshot, copy, photograph, save, forward, report, or disclose them. If you back up files, export chats, store media outside the app, or use third-party services, those copies may not be protected by SYNC’s end-to-end encryption.
Do not share OTPs, passwords, private keys, intimate images, confidential documents, or sensitive information with untrusted people.
7.8 Safety and privacy together
SYNC is designed to protect privacy while also allowing lawful safety actions. We aim to minimise access to private message content, provide strong encryption, support user reporting, preserve evidence where required, act against harmful Content, and respond to valid legal obligations.
If you see abuse, report it. If you believe your Account or device is compromised, contact support@rabcorp.co.in. If you have a privacy question, contact privacy@rabcorp.co.in. If you have a legal grievance, contact Ashish Bhawkar, Ashish.bhawkar@rabcorp.co.in.
03 April 2026