Privacy Policy
Last updated: June 9, 2026 · One and Three
Introduction
One and Three("we," "us," or "our") operates https://www.oneandthree.in and develops mobile applications including Retro Messenger. This Privacy Policy explains how we collect, use, store, share, and protect information when you visit our website or use our apps.
This policy is organized in two parts: practices that apply to our website, followed by practices that apply specifically to Retro Messenger. Where sections differ, the app-specific sections govern your use of the app.
Scope
This policy applies to https://www.oneandthree.in and to Retro Messenger for iOS (bundle identifier com.retromessenger.app). It does not apply to third-party websites or services that we do not control, including services you access through links inside the app (such as Google Sign-In).
Website: Information We Collect
When you use our website, we collect only the information you choose to provide or that is generated automatically by standard web technologies.
Contact inquiries:When you contact us via email or our contact form, we receive the information you provide, which may include your name, email address, the reason for your inquiry, and the content of your message. Our contact form opens your device's email client; we do not operate a server-side form backend that stores submissions on our own infrastructure.
Technical data: If you visit our website, our hosting provider may automatically process standard server logs (such as IP address, browser type, referring page, and request timestamps) to deliver the site securely and reliably. We do not use advertising trackers or sell website visitor data.
Website: How We Use Information
We use website-related information to:
- Respond to inquiries and support requests
- Operate, maintain, and improve our website
- Protect against abuse, fraud, and security incidents
- Comply with legal obligations
Website: Data Sharing
We do not sell your personal information. We may share website-related information only when required by law, to protect our rights and users, or with service providers who assist us in operating our website (such as hosting providers) under confidentiality and data-protection obligations comparable to those described in this policy.
Website: Data Retention
We retain contact correspondence only as long as necessary to fulfill the purpose for which it was collected, resolve support matters, or comply with legal obligations, unless a longer retention period is required by law.
Website: Cookies and Similar Technologies
Our marketing website does not use cookies for advertising or cross-site tracking. Your browser may store standard session or preference data locally. If we introduce analytics or similar technologies on the website in the future, we will update this policy before doing so.
Retro Messenger: Overview
Retro Messenger is a privacy-focused messaging app for iOS. Message bodies in conversations are protected with end-to-end encryption, meaning only conversation participants with the correct cryptographic keys can decrypt message content on their devices.
To deliver messaging, account management, notifications, and related features, certain information is stored on our cloud infrastructure and processed by third-party service providers. Some data, such as short message previews, message-request introduction notes, and conversation metadata, is stored in plaintext on our servers and is not end-to-end encrypted. We explain these practices in detail below.
Retro Messenger does not sell personal information, does not display advertisements, and does not use third-party analytics or crash-reporting SDKs for behavioral tracking.
Retro Messenger: Information We Collect
The following describes the categories of information processed when you use Retro Messenger.
Account and profile information: Email address and password (for email-based accounts), display name, username, Firebase user identifier, and a public encryption key used for end-to-end messaging. If you sign in with Google, Google provides authentication tokens to Firebase on your behalf; we receive your account identifier and profile information needed to create and maintain your account.
Messages and user-generated content: Text messages you send and receive, which are stored on our servers as encrypted ciphertext for delivery and sync. We also store a short plaintext preview (up to approximately 80 characters) of each message for inbox display and push notifications, a plaintext preview of the most recent message on each conversation, plaintext introduction notes you submit with message requests (between 10 and 200 characters), and plaintext group names. System-generated events (such as a member leaving a group) may be stored in plaintext.
Social and conversation metadata: Your friends list, blocked-user list, message-request status, read-receipt timestamps, typing-indicator timestamps, per-conversation unread counts, and which conversation you are actively viewing (presence) when the app is open.
Cryptographic and recovery data: Your public encryption key is stored in your cloud profile. An encrypted backup of your private encryption key may be stored in your account if you create a recovery passphrase. Your recovery passphrase is never transmitted to or stored on our servers.
Device and notification data: Push notification tokens (Firebase Cloud Messaging and Apple Push Notification service), notification preferences (such as muted conversations), and authentication session tokens managed by Firebase.
Information stored only on your device: Your private encryption keys (in the iOS Keychain), unsent message drafts, decrypted message caches during an active session, locally stored copies of your own group-message plaintext (because group ciphertext is addressed to recipients), and certain app UI preferences. This device-local data is not uploaded to our servers except where you explicitly trigger an action that sends data (such as sending a message).
Information we do not collect: Retro Messenger does not access your device contacts, photo library, camera, microphone, or precise location. We do not collect advertising identifiers (IDFA) or use App Tracking Transparency. We do not currently support profile photo uploads.
Retro Messenger: How We Collect Information
We collect app information through the following means:
- Information you provide: When you create an account, set up your profile, send messages, submit message requests, name group conversations, create a recovery passphrase, or contact support.
- Automatic collection during use: When you use messaging features, the app generates encryption keys, syncs encrypted messages, updates read and typing status, registers for push notifications (if you grant permission), and stores conversation metadata needed to operate the service.
- Device APIs: The iOS Keychain (for cryptographic keys and authentication tokens), UserNotifications (for push alerts), and the system clipboard when you choose to copy your username or share a profile link.
- Server-side processing: Cloud functions process certain events (such as delivering push notifications when a new message or message request arrives, validating password-reset requests, accepting message requests, and processing account deletion) using data stored in our database.
Retro Messenger: How We Use Information
We use Retro Messenger information to:
- Create, authenticate, and maintain your account
- Deliver, sync, and display messages and conversations
- Operate message requests, friend connections, group chats, and blocking
- Provide read receipts, typing indicators, and unread counts
- Send push notifications you have authorized
- Enable end-to-end encryption and optional key recovery
- Prevent abuse, enforce blocks, and maintain service security
- Respond to support requests and comply with legal obligations
We do not use your messages or personal information for advertising, and we do not sell personal information to third parties.
Retro Messenger: End-to-End Encryption and Plaintext Data
Message bodies in Retro Messenger are encrypted on your device before being uploaded. We use Curve25519 key agreement, HKDF, and ChaCha20-Poly1305 for message encryption. Your private encryption key is stored in the iOS Keychain and is not transmitted to our servers in unencrypted form.
Despite end-to-end encryption of message bodies, the following categories of data are stored or transmitted in plaintext on our infrastructure and may appear in push notifications: short message previews, conversation last-message previews, message-request introduction notes, group names, and certain system event messages. Our service providers that host this infrastructure can technically access this plaintext data, although we do not use it for advertising.
If you lose your device and recovery passphrase, encrypted message history may be permanently inaccessible. See our Terms of Service for user responsibilities regarding key recovery.
Retro Messenger: Third-Party Service Providers
We use third-party service providers to operate Retro Messenger. These providers process data on our behalf and are contractually required to protect it with safeguards comparable to those described in this policy. We require that any party with access to user data provide equal or greater protection of that data as stated here.
Google Firebase (Google LLC): We use Firebase Authentication (account sign-in), Cloud Firestore (database storage and sync), Cloud Functions (server-side event processing), and Firebase Cloud Messaging (push notification delivery). Firebase processes account credentials, profile data, encrypted and plaintext message data described in this policy, conversation metadata, push tokens, and related operational data. Firebase Analytics is disabled in our project configuration, and we do not integrate Firebase Analytics in the app.
Google Sign-In (Google LLC):If you choose to sign in with Google, Google processes your authentication and provides tokens to Firebase. Google's use of information is governed by Google's privacy policy.
Apple Push Notification service (Apple Inc.): Apple delivers push notifications to your device. Notification payloads may include sender display names and short message or request previews.
We may disclose information if required by law, legal process, or governmental request, or when we believe disclosure is necessary to protect the rights, safety, and security of our users, the public, or One and Three.
Retro Messenger: Data Retention
We retain app data for as long as your account is active and as needed to provide the service, unless you delete specific content or request account deletion.
- Messages and conversations: Retained until you delete individual messages, delete a conversation, or delete your account. Deleting a chat removes message documents from our database for that conversation.
- Account and profile data: Retained until you delete your account in the app or request deletion by email.
- Push tokens: Retained while your account is active and notifications are enabled. Tokens are removed from our database when you sign out of the app on a device.
- Device-local data: Remains on your device until you delete the app or clear app data. Signing out removes push tokens from our servers but does not delete private keys from your device Keychain.
We may retain limited information longer when required by law, to resolve disputes, enforce our agreements, or maintain security records.
Retro Messenger: Your Rights, Choices, and Controls
Depending on your location, you may have rights to access, correct, delete, or export personal information, restrict certain processing, or object to processing. You can exercise many choices directly in the app or by contacting us.
In-app controls:
- Update your display name and username in Settings
- Change your password (email accounts) in Settings
- Delete individual messages or entire conversations
- Export a conversation as a plaintext file from within a chat
- Block users to prevent further messaging and push notifications from them
- Report users from a chat or group member list (opens a pre-filled email to support)
- Mute notifications for specific conversations
- Permanently delete your account under Settings → Security → Delete account (requires re-authentication)
- Sign out of your account on a device
Revoking consent and permissions: You can withdraw consent for push notifications at any time in the iOS Settings app under Notifications for Retro Messenger. Disabling notifications stops delivery of push alerts but does not delete your account or message history. You may stop using the app or delete your account as described below.
Account and data deletion: You can delete your account in the app at Settings → Security → Delete account. You must confirm the action and re-authenticate with your password (email accounts) or Google Sign-In before deletion proceeds. Deleting your account is irreversible and removes your profile, friends, message requests, encryption backup, and related cloud data. One-to-one conversations and their message history are deleted from our servers; you are removed from group conversations. Device-local data (such as Keychain keys and drafts) should be cleared by deleting the app from your device after account deletion.
If you cannot access the app, you may also email support@oneandthree.in from the address linked to your account with the subject line "Account Deletion Request." We will verify your identity and process eligible requests within 30 days, subject to legal retention requirements.
Access and correction requests: Email support@oneandthree.in to request access to or correction of personal information we hold about you.
If you are in the European Economic Area, United Kingdom, or other regions with data-protection laws, you may also have the right to lodge a complaint with your local supervisory authority.
Retro Messenger: Push Notifications
With your permission, Retro Messengersends push notifications for events such as new messages and incoming message requests. Notification content may include the sender's display name and a short preview of the message or introduction note. You can disable notifications in iOS system settings at any time. We do not send promotional or advertising push notifications.
Children's Privacy
Our website and Retro Messenger are not directed to children under 13 years of age (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us at support@oneandthree.in and we will take steps to delete it.
Retro Messengeris a messaging service. Parents and guardians are responsible for supervising minors' use of messaging apps.
Security
We implement technical and organizational measures designed to protect information, including encryption in transit (TLS), end-to-end encryption of message bodies, Keychain storage for private keys, and access controls on our cloud database. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
International Data Transfers
One and Three is based in India. Information collected through our website and Retro Messenger may be processed and stored in India and in other countries where our service providers operate (including the United States, where Google Firebase infrastructure is located). Data-protection laws in these countries may differ from those in your jurisdiction. Where required, we rely on appropriate safeguards for international transfers.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page. For significant changes to Retro Messenger practices, we may also notify you in the app or by email where appropriate. Continued use of our services after changes take effect constitutes acceptance of the updated policy.
Contact
For privacy questions, data requests, or Retro Messenger support, contact us at support@oneandthree.in.
One and Three · https://www.oneandthree.in