smallTalk
Privacy Policy
For the smallTalk application (com.smalltalk.social) and the smallTalk backend services.
Last updated 25 September 2026
Who we are
smallTalk is operated by Makers Infotech Services, India. See www.makersinfotechservices.com.
For any privacy question, contact contact@makersinfotechservices.com.
What smallTalk actually does
smallTalk works out which physical room you are in — a café, a co-working space, a waiting room — and shows you who else is in that room right now. Leave, and you disappear from it. There is no directory and no feed. smallTalk also has Talk, a separate space for one-on-one conversations with people nearby under a generated name and avatar — never your real name or photo. This policy explains what that requires us to collect, and nothing more.
What we collect
Information you give us when you sign in
| Data | Why we need it |
|---|---|
| Phone number | The only sign-in method — a one-time code, no password to store or leak |
Information you give us during onboarding
| Data | Why we need it |
|---|---|
| First and last name | Account identity. Not shown to other users — see “What other users see” below |
| Date of birth | smallTalk is 18+ only; this is the age check. We keep the date, not just a checkbox, so we can re-verify against a raised minimum age later |
| Gender | Optional to publish to people sharing your room, off by default |
| Occupation | Optional to publish to people sharing your room, off by default |
Location while using the app
smallTalk uses your device’s location to work out which room you are in. This is the core of the product, and the promise around it is deliberate:
To be precise about what is kept: a room keeps a record that you visited it, with the time you arrived and left, but no coordinates. In Talk, while you are available, your last position is kept on our servers so that people within your chosen distance can find you; it is hidden once it goes stale, and removed when you stop being available.
If your phone reports which Wi-Fi network it can see, we use that only as a secondary signal to help confirm you are still in the room. The network name itself is never stored — a one-way, salted hash of it is, and only for as long as it is useful for that confirmation.
Android and iOS ask for location permission separately from the rest of the app, and you can revoke it at any time in system settings. Without it, smallTalk cannot place you in a room.
Information you create in the app
- Profile details you choose to add: a display name, bio, interests and photos.
- Messages you exchange with people who currently share, or recently shared, a room with you, including photos and GIFs you send.
- Talk: a name and avatar we generate for you, and — while you are available — your chosen topic, distance and last position.
Information collected automatically
When you sign in on a device we record: platform (iOS/Android), app version, OS version, and device model. This is used to keep the app working correctly on your device and to deliver push notifications, and is tied to your account.
What we do with photos
Phone cameras embed hidden information in photos, including the exact GPS coordinates where the picture was taken. For an app built around not revealing your location, publishing that by accident would defeat the point. Every uploaded image is decoded and re-encoded on our servers, which discards all embedded metadata — GPS coordinates, camera make and model, and timestamps — before it is stored.
What other users see
Someone sharing a room with you sees your display name, profile photo, bio and interests, and — only if you have turned each one on individually — your age, gender, and occupation. Off unless you turn it on. Your phone number, exact date of birth, first and last name, and precise location are never shown to another user, under any setting. In Talk, people see only your generated name and avatar and whatever optional Talk details you add.
If you message someone, that conversation exists only as long as you both remain relevant to it — see “How long we keep it” below for exactly how long it survives after it ends.
Blocking and reporting
You can block or report anyone you share a room with. A block is silent: the other person is never told, and it cannot be undone — that is intentional, not an oversight. A report is recorded and reviewed; enough reports against the same account can lead to an automatic warning or suspension. We do not tell a reporter whether a report crossed that threshold.
Invite codes
Every account has its own invite code. If a new account is created using someone else’s code, we record which account referred it. This is used only to credit the person who invited someone — it is never shown to any user in the app, and it does not change what either account can see or do.
How we use your information
We use it only to:
- create and secure your account, and sign you in;
- work out which room you are in, moment to moment;
- show you who else is in that room, and let you message them;
- confirm you are old enough to use smallTalk;
- deliver push notifications about messages and replies you are waiting on;
- keep the service working, diagnose faults, and prevent abuse of it.
We do not sell your personal information. We do not use it for advertising, and we do not build advertising profiles. smallTalk shows no ads and contains no advertising SDKs.
Who we share it with
We do not sell or rent your data. We share it only with the infrastructure providers that run the service on our behalf, under contract, and only to the extent needed to operate it:
| Provider | Role | What it handles |
|---|---|---|
| MSG91 | SMS delivery | Your phone number, solely to deliver the sign-in code |
| Google (Cloud Run, Places API, Firebase Cloud Messaging) | Application hosting, place lookup, push delivery | All requests to the service; approximate coordinates, resolved to a place name and then discarded; push tokens |
| Google Cloud (Cloud SQL, Cloud Storage) | Database and photo storage | Your account record, messages, and photos |
| Upstash | Short-lived presence data | Which room you are currently in, held only while you are there |
| Apple Push Notification service | iOS push delivery | A push token, and the notification content |
We do not use any advertising or analytics SDK — Firebase Analytics and Firebase's advertising features are explicitly disabled in this app.
We may also disclose information where the law requires it, or to protect the rights and safety of our users.
Where your data is stored
Our application servers, database (Google Cloud SQL) and photo storage (Google Cloud Storage) are all in asia-south1 (Mumbai, India). If you use the app from outside India, your information is transferred to and processed there.
How we protect it
- All traffic between the app and our servers is encrypted with TLS (HTTPS).
- Sign-in codes are never stored in a readable form, only as a salted HMAC.
- Every request is authenticated, and checked to confirm you may access that specific record.
- Private conversations are readable only by their participants.
- Uploaded images are sanitised as described above.
- Every route is rate-limited to slow down abuse of the API itself.
No system is perfectly secure, but we take these measures seriously and review them as the service changes.
How long we keep it
| Data | Retention |
|---|---|
| Your live position | Used to place you in a room and held only briefly for that purpose; no trail of coordinates is kept |
| Room visits | A record that you were in a room, with arrival and departure times, but no coordinates. Kept while your account is active |
| Talk position | Your last position, kept only while you are available in Talk and hidden once stale |
| Wi-Fi network name | Never stored — only a salted hash, only while confirming you're still in a room |
| Messages in a conversation | Deleted within 24 hours of the conversation closing (either person leaving the room, or an etiquette rule closing it). There is no archive |
| Profile, photos, account details | Kept while your account is active |
| Device and push token records | Kept while your account is active |
Your choices and rights
- Control what others see — toggle age, gender and occupation visibility individually, from Settings.
- Delete your account and its data — from the Settings screen, or by writing to contact@makersinfotechservices.com. See the account deletion page.
- Withdraw location permission — in your device's system settings at any time.
- Ask us for a copy of your data, or ask us to restrict how we use it, by writing to contact@makersinfotechservices.com.
We respond to requests within 30 days.
Children
smallTalk is not intended for children. You must be at least 18 years old to create an account, which is why we ask for your date of birth and refuse accounts that resolve to under 18. If you believe a child has given us personal information, write to contact@makersinfotechservices.com and we will delete it.
Changes to this policy
If we change this policy we will update the date at the top and, for significant changes, notify you in the app. Continuing to use smallTalk after a change means you accept the updated policy.
Contact
Makers Infotech Services
India
www.makersinfotechservices.com
contact@makersinfotechservices.com