Legal
Privacy Policy
Effective: 23 July 2026 · Last updated: 23 July 2026
VOID is built to know as little about you as possible while keeping people safe. This policy says exactly what we hold, why, for how long, and who touches it. No ads, no data sales, no profiling for marketing — ever.
VOID is operated by Sorion Pty Ltd (ACN 700 168 038, ABN 52 700 168 038) (“VOID”, “we”, “us”). Questions: support@voidsocial.app.
The short version
We hold your phone number (so you can sign in — and for emergencies and legal duties, nothing else), a one-way code derived from it (so bans stick), a coarse area code (never your exact location), what you post (briefly — it disappears on the schedule shown in the app, unless safety or law requires keeping a copy), and very little else. Other users never see any of it — they see a made-up presence word.
Who can use VOID
VOID is 18+. We don’t knowingly collect data from anyone under 18. If we learn an account belongs to a minor, we remove the account and delete its data. Where app stores provide an age signal, we use it to keep minors out.
What we collect and why
| Data | Why |
|---|---|
| Phone number | To sign you in (one person, one account). It stays in our authentication system for that purpose. We only ever access it outside sign-in in two situations: a genuine emergency involving danger to life, or where the law requires it (like mandatory child-safety reporting) — through a controlled, logged process. Never shown to other users; never used for marketing. |
| Phone hash | A one-way cryptographic code derived from your number. It can’t be reversed. It keeps one-person-one-account honest, makes bans survive reinstalling, and powers the Avoid List. It’s pseudonymous, and we treat it as personal information. |
| Approximate location | Your device converts your position into a coarse area code covering roughly a suburb-scale cell. Our servers never receive your exact coordinates, and we can’t reconstruct them. Other users only learn that a Story is within their chosen range. |
| Content you post | Stories (text or voice), replies, and Private Lines. Ephemeral — they expire on the schedule shown in the app, with the safety and legal exceptions described below. |
| Voice & transcripts | Voice is transcribed on our servers and checked before anyone can hear it; transcripts follow the same lifetime as the voice they came from. Your voice can identify you — use it only if you’re comfortable being heard. |
| Linked accounts (optional) | If you link X or Telegram for identity reveals, we store the verified handle. We never post to, read, or scan those accounts. |
| Avoid List (optional) | Numbers you add are hashed on our servers immediately and the raw numbers are discarded — never stored. Contact names never leave your phone. The hashes exist solely so you and those people don’t surface for each other, and are deleted when you remove them or delete your account. |
| Safety & moderation data | Reports, blocks, moderation decisions, and — for flagged or reported content — a preserved evidence copy (see “Disappearing, honestly”). |
| Push token | To deliver notifications. Payloads never contain message text, identity, phone, or precise location. |
| Diagnostics | Crash reports and minimal usage events — never message content, identity, or precise location. |
| Subscription status | If you buy VOID+, your entitlement status. Apple or Google handle payment; we never see your card. |
What we never collect
- No name, email, photos, or contact list (beyond the hashed Avoid entries you choose).
- No exact GPS position, no movement history, no map pins.
- No advertising identifiers, no ads, no sale or sharing of personal data — there are no advertisers, brokers, or “partners.”
- No profiles, feeds, followers, likes, or popularity metrics.
Anonymity, honestly
Anonymous from other users — always. Not anonymous from VOID’s own safety systems, our processors, or the law.
Moderation and AI safety
Content is checked by automated moderation before it goes live, including AI classification services (OpenAI, Google Perspective) that assess text and transcripts for threats, harassment, illegal content, content involving minors, and self-harm. Serious incidents create a private record for human review — final decisions rest with people, not models. Allowed private content is not kept as moderation evidence unless it is reported, flagged for safety, or legally required.
Disappearing, honestly
Content vanishes from the app on the schedule shown in the app. These are the exceptions, and they exist for safety and legal reasons:
- Reported or safety-flagged content is preserved as evidence for a limited period (currently 30 days), then only a hashed record and metadata remain.
- Child-safety material is preserved for one year and reported, as the law requires.
- Serious-emergency cases (danger to life): the case record — what was preserved, disclosed, and why — is retained.
- Your own choices: Vault keeps and delivered reveals persist as shown in the app. Story authors can revisit an anonymized, read-only copy of their Story’s public conversation for a limited window.
“Gone from the app” is not “beyond the law.” We say this in the app, and we mean both halves.
When we would disclose anything
- Legal requirement: mandatory child-safety reports (including to NCMEC in the US), valid legal process, and enforceable regulatory notices (including Australia’s eSafety Commissioner).
- Emergency: if we believe in good faith that someone is in imminent danger of death or serious physical injury, we may voluntarily disclose the minimum necessary information — which can include a phone number and coarse area — to emergency services or law enforcement. Every emergency disclosure is authorised by a person, against written criteria, and logged.
- Never: advertisers, data brokers, “partners.” There are none.
Who processes data for us
Service providers acting under contract, strictly to run VOID: Supabase (hosting, database, authentication), Twilio (sign-in SMS delivery), OpenAI and Google Perspective (automated content-safety classification only), Expo / Apple / Google push services (notifications), Sentry (crash diagnostics), RevenueCat and the Apple/Google stores (subscriptions, billing, age signals). Some operate in other countries, including the United States; where personal information crosses borders we take the steps Australian privacy law requires.
How long we keep things
| Data | Kept |
|---|---|
| Content (Stories, Comments, Lines, transcripts) | Until it expires or you delete it, per the app |
| Reported/flagged evidence | 30 days, then hashed record + metadata |
| Child-safety preservation | 1 year (legal requirement) |
| Emergency case records | Retained per legal guidance |
| Phone number | While your account exists; deleted with it |
| Phone hash (enforcement record) | Survives account deletion, so bans can’t be reset by reinstalling |
| Avoid List hashes | Until you remove them or delete your account |
| Vault keeps & reveals | Per the schedule shown in the app |
| Crash/usage data | Short-term, minimal |
Your rights and controls
- Delete your account any time in the app — see Account Deletion. Your content, linked handles, presence, and account data are deleted; your number goes with the account. What remains: the hashed enforcement record (so bans stick) and anything under a legal hold above.
- Access and correction: contact support@voidsocial.app to ask what we hold or to correct it. Australian users can complain to us first and then to the OAIC (oaic.gov.au). US state residents may have rights to access, delete, and correct — the same email exercises them; we do not sell or share personal information as those laws define it.
- Permissions: location and notifications are controlled in your OS settings. Revoking location stops Radar and posting, as the app explains.
Security
Everything is encrypted in transit and at rest. Access to production systems is restricted and role-based; access to your phone number outside sign-in goes through a single controlled, logged path. No system makes misuse impossible — our controls are technical and procedural, and we notify affected users and regulators of eligible data breaches as Australian law requires.
Changes
We’ll post updates here and give in-app notice of material changes. Continued use after the effective date means the updated policy applies.
Contact
Sorion Pty Ltd (ACN 700 168 038 · ABN 52 700 168 038) · 117/530 Little Collins St, Melbourne VIC 3000, Australia · support@voidsocial.app
Australian complaints: OAIC — oaic.gov.au