Skip to content
MARCO badgeMELEGAECOSYSTEMMARCO Chat

Privacy

MARCO Chat Privacy Policy

Effective 7 September 2026. This policy describes the current MARCO Chat service operated by AMAAR ONE LTD.

Who controls your data

AMAAR ONE LTD is the operator and data controller for MARCO Chat. Privacy and deletion questions can be sent to support@melega.app.

Account and profile

MARCO Chat uses a pseudonymous account and does not require a phone number or email address. We process the account identifier, username, display name, optional biography, optional profile image, session and device records, and the security state needed to operate the account. This data is required for account creation, authentication, contact discovery by exact username, security and delivery of the service.

Messages, calls and media

Private message content and shared media are end-to-end encrypted before they leave your device. MARCO servers store and transmit ciphertext but do not hold the conversation keys needed to read it. Your recipients can decrypt the content on their authorised devices. Encrypted content may include text, reactions, replies, voice notes, photos, videos, documents, location and contact cards that you deliberately share.

The self-hosted Matrix service necessarily processes operational metadata such as pseudonymous user and room identifiers, event identifiers, timestamps, membership, delivery state and encrypted object references. Read receipts and typing indicators are processed only when those features are enabled. We do not place message plaintext or conversation metadata in push notifications.

Notifications

On Android, when notifications are enabled and platform permission is granted, the app registers a Firebase Cloud Messaging token with the MARCO service. The push payload is an opaque wake signal only. Turning notifications off removes the Matrix registration and requests deletion of the Firebase token. Device revocation and account deletion remove server-side push registrations. Apple Push Notification delivery is not currently enabled in the production service.

Contacts, biometrics and device permissions

MARCO Chat does not upload or synchronise your address book. On Android, the system contact picker lets you deliberately choose one contact and grants the app access only to that selection. A contact card leaves the device only if you choose to send it in an encrypted conversation. Biometric templates remain with the operating system; MARCO receives only the success or failure of an authentication request.

Optional services

GIF search is optional. When you perform a GIF search, MARCO forwards the search terms to GIPHY without intentionally including your MARCO account identifier or contact graph. GIPHY receives ordinary network information and applies its own privacy terms. Wallet verification is optional and processes a public wallet address, a challenge and a signature. The MARCO Passport integration is currently disabled in production.

Service providers and locations

The production Matrix and account services run on infrastructure hosted by Hostinger. Encrypted media objects are stored in Cloudflare R2. Google Firebase Cloud Messaging provides Android push delivery, and GIPHY answers searches initiated by the user. These providers process data on our behalf or at your explicit request. We do not sell personal data and do not use chat activity for advertising profiles.

Retention

  • Account and profile records remain while the account is active and are removed on deletion.
  • Sessions, devices and push registrations remain until they are revoked, signed out or deleted.
  • Encrypted message history and media remain while required by the participating rooms and are subject to user deletion and redaction actions.
  • MARCO does not retain GIPHY search terms as a search-history profile.
  • Network IP history is disabled in the Matrix application configuration.
  • Production service logs are size-bounded and rotated; they are not message-content logs.

Account deletion cannot remove copies already delivered to another person, exports or screenshots, or data another person must retain under law. Encrypted historical events may remain on recipient devices or in shared rooms without becoming readable by MARCO. No separate application-data backup system is currently configured.

Your choices and account deletion

You can edit profile data, disable notification and interaction settings, revoke devices, or permanently delete your account in the app. You can also submit an external deletion request on the Delete MARCO account page. We may need to verify control of the account before acting on an external request.

Security and changes

Data is encrypted in transit and private conversation content is additionally protected by end-to-end encryption. No security measure eliminates every risk. Material changes to this policy will be posted on this page with a new effective date.

© 2026 AMAAR ONE LTD. All rights reserved.

support@melega.app