Last updated 5 September 2026
Privacy at Carillio
What we hold, what we cannot hold, and who else touches it. This describes the system as it is built, not an aspiration.
Carillio is operated by Ravinaro. This policy covers the Carillio iOS app, this website and the administration console at carillio.ravinaro.com. Write to privacy@ravinaro.com with any question about it.
What we cannot read
Messages and calls are end-to-end encrypted with Messaging Layer Security (RFC 9420). Encryption and decryption happen on your devices. Our servers queue and forward ciphertext only; they never hold a key that opens it.
- Message bodies — sealed on the sending device. We store the sealed envelope and the delivery metadata needed to route it.
- Photos, video and voice notes — encrypted on your device before upload. Object storage holds bytes we cannot open; the key travels inside the encrypted message.
- Group calls — media keys are derived from the MLS group, so the media server forwards encrypted streams without being able to decode them.
- Push notifications — delivered as encrypted payloads and decrypted by a notification extension on your phone.
This applies to organizations too. An organization administrator manages membership, seats and policy. No administrator, and nothing in our console, can read a conversation.
What we do hold
- Your phone number, in the form you verified it, linked to your account. It is how people reach you and how we recover an account.
- Salted hashes of phone numbers for contact discovery. When you look for people you know, your device sends hashes, not numbers. We never receive or store your address book in the clear, and we do not keep a record of who you looked up.
- Account and device records — account id, display name, avatar reference, the public keys and key packages your devices publish, push tokens, and the app build and iOS version of each device.
- Delivery and call metadata — which account sent an envelope to which account and when, and per-call timing and quality measurements (bitrate, packet loss, round trip time). This is what makes delivery and troubleshooting possible.
- Organization records — the organization, its members and roles, its verified domains, its policy, and the evidence submitted for a verified badge.
- Abuse reports — a report contains only what the reporting person chooses to attach. If they attach a decrypted excerpt, that excerpt was decrypted on their device.
- Waitlist addresses from this website — the address and the date, nothing else.
We run no advertising, we sell nothing to anyone, and there are no third-party analytics or advertising SDKs in the app or on this site.
How long we keep it
| Data | Kept for |
|---|---|
| Undelivered message envelopes | 30 days, then deleted whether delivered or not |
| Encrypted media | 90 days by default; an organization may set a shorter window |
| Account, device and organization records | While the account exists |
| Call and delivery metadata | Rolling operational window for troubleshooting and abuse handling |
| Administrative audit log | Retained — it exists to record who did what in the console |
Deleting your account
Delete your account from inside the app, under Settings. Deletion clears your phone number and its hash, your display name, your avatar and your Apple sign-in link, removes your devices and their keys so you stop receiving anything, and queues your stored media for erasure. Copies of messages already delivered to other people live on their devices and are theirs, not ours — we cannot reach into another person's phone.
Who else processes data
| Subprocessor | What for |
|---|---|
| Cloudflare | Hosting, database, object storage, call media forwarding and relay, logs |
| Twilio | Sending the SMS code that verifies your phone number |
| Apple | Push notification delivery, Sign in with Apple, App Store distribution |
| Stripe | Payment for organization seats. Card details go to Stripe, never to us |
| Resend | Transactional email — console sign-in links and organization invitations |
None of them receives message or call content, because none of them can: they only ever see ciphertext or the narrow item listed above.
Where data lives
Carillio runs on Cloudflare's global network, so records and encrypted media may be stored and processed outside your country. Transfers rely on the standard contractual clauses in our agreements with the subprocessors above.
Your rights
You can ask for a copy of the data associated with your account, ask us to correct it, or ask us to delete it. In-app deletion is the fastest route; otherwise write to privacy@ravinaro.com and we will answer within 30 days. If you are in the EEA or the UK you also have the right to complain to your data protection authority.
Children
Carillio is not directed at children under 13, and we do not knowingly create accounts for them. Tell us at privacy@ravinaro.com if you believe one exists and we will remove it.
Changes
If this policy changes materially we will say so in the app before the change takes effect. The date at the top of this page always reflects the current version.