PENA

Privacy Policy – PENA

This Privacy Policy describes how PENA ("we", "us", or "services") collects, uses, and protects information related to the use of the PENA app and other supporting sites, features, and services (hereinafter referred to as the "Platform").

PENA is designed to provide a secure, private, and fully encrypted communication experience, so your conversations remain entirely yours.

By installing or using PENA, you are deemed to have read and agreed to this policy.

1. Our Commitment to Your Privacy

Privacy is not just a feature for PENA. Privacy is a fundamental right of every individual and is the fundamental foundation of the entire system we build.

PENA is built on the core principle of privacy. PENA also does not collect user data in any form. The entire system is designed with the highest level of security standards and next-generation encryption technology, including protection against threats that do not exist today

We cannot view, store, or access your messages, and do not have the ability to read or record any communications that occur within PENA. All data and activities are completely under the control of the user.

All messages, communications, and data can only be viewed and stored by you. PENA does not own, does not store, and does not control any information from user activities within this application.

From the beginning, PENA was designed to ensure that full control of communications was in the hands of users, not in the hands of any company, server, or third party.

Privacy From the First Moment

PENA can be used without:

We believe that secure communication should not depend on identity. Therefore, PENA never asks for data that is not needed.

We Do Not Collect Personal Data

We are committed to:

We don't know who you are, who you're talking to, or what you're talking about—and we don't want to know.

Communication Without a Central Server

PENA uses a peer-to-peer (P2P) architecture, which means:

With this approach, the risk of mass surveillance and data leakage can be significantly minimized.

Uncompromised Encryption

All communications at PENA are protected by:

Only the sender and receiver can read the content of the message. Even we as developers don't have access.

Zero-Knowledge by Design

The PENA system is built on the principle of zero-knowledge:

If we don't have your data, then it can't be misused.

Your Data Stays on Your Device

When you delete something, the data is permanently lost, without any copies.

Additional File Security & Protection

To protect your device:

Peace must not come at the expense of freedom.

Freedom Comes With Responsibility

We give you complete freedom of communication.
However, we also believe that true freedom always comes with personal responsibility.

PENA does not monitor conversations, but users remain responsible for their actions in accordance with applicable law.

Long-Term Commitment

Privacy is not a momentary trend. We are committed to:

Transparency & Trust

We strive to always be transparent about:

Trust is not required. Trust is built.

2. Information We Collect

PENA is designed with the principle of data minimization, which is to process only information that is really technically necessary, without compromising user privacy.

Basic Principles of Information Collection

PENA is designed with the principle of data minimization, which is to process only information that is really technically necessary, without compromising user privacy.

In general:

Information We Do NOT Collect

PENA does not collect, store or process the following information:

Content of Communication

All messages and files are end-to-end encrypted.

Content of communication:

Due to the peer-to-peer architecture, data moves directly between the user's devices.

Non-Identifying Technical Information

To ensure that the application can function properly, PENA may process limited technical information, which is non-identifiable, including:

This information:

Payment Information (Premium Service)

For Premium services, payments are processed by third-party providers.

PENA:

Payment information is fully subject to the privacy policy of the relevant payment provider.

Information Storage

All communication data is stored locally on the user's device.

PENA does not provide:

Deletion of Information

Users can delete data at any time.

Once removed:

PENA does not have a copy of the data to restore.

Legal Obligations

Because PENA does not collect or store the content of communications, PENA cannot provide user communication data to any party.

Legal compliance is carried out without compromising the principles of privacy and anonymity.

Changes to Information Collection Policy

In the event of a change in the type of technical information processed, PENA will:

Changes are effective from the date they are announced.

3. Messages and Calls

Key Principles

Messages and calls in PENA are built on one simple principle: only the sender and receiver can know the contents.

PENA does not act as an intermediary that can read, store, or control user communications.

Message Encryption

All text, voice, and file messages:

Each communication session:

PENA:

Voice Calls & Secure Calls

Voice calls at PENA are made by:

Whole calls:

PENA does not store:

Peer-to-Peer (P2P) Architecture

Messages and calls are sent directly from the sender's device to the receiving device.

No server that:

The risk of mass data leaks is minimized because:

Post-Quantum Encryption (PQE)

PENA is designed to deal with future computing threats.

Encryption systems consider:

Communication keys:

Metadata & Privacy

PENA does not:

Temporary technical information is only used for:

This information is temporary and not stored.

Message Deletion

Messages can be deleted manually or automatically.

Once removed:

The Auto-Delete feature ensures that messages do not leave a digital footprint.

Technical Limitations

The quality of messages and calls can be affected by:

PENA does not guarantee:

However, security remains a top priority.

User Responsibility

The user is responsible for the content of messages and calls made.

PENA does not moderate, record, or intervene in user communications.

4. How We Use Data

Principles of Data Use

PENA uses data with one main goal: to keep applications running safely, stably, and as they function — without compromising user privacy.

We do not use data to:

Data Used Technically

PENA only uses non-identifying technical data that is necessary to:

This data is of the nature:

Use of Communication Data

Fill messages, calls, and files:

End-to-end encryption ensures:

All communication takes place directly between the user's devices.

Service Enhancement

Anonymous technical data can be used to:

This use is carried out without:

Legal Compliance

Because PENA does not store the content of communications or user identities, our ability to hand over data is severely limited.

Legal compliance is carried out to the extent possible without violating the principles of privacy and anonymity of users.

Paid Services (Premium)

Data associated with the Premium subscription is used only for:

Payment information is managed by third parties and is not used for any other purpose by PENA.

No Ads & No Tracking

PENA:

We don't build a business from your data.

Control in the Hands of the User

The user has complete control over:

Once the data is deleted, it will:

5. Control of Data

Principles of Data Ownership

In PENA, the data belongs entirely to the user.

PENA does not claim ownership of:

We only provide technology, not control data.

Full Control on User Devices

All communication data is stored locally on the user's device.

There is no cloud storage, backup servers, or central archives.

Independent users:

Right to Delete Data

Users can remove:

Once removed:

Removal is instant and final.

No Remote Access

PENA does not have:

Even under certain conditions:

Control over Files & Media

Each file received:

Anti-malware features:

Control over Identity

PENA does not use:

No centralized account should be closed.

Deleting an app means:

Rights of Access & Portability

Because PENA does not store user data, requests:

Technically not available.

All control is in the hands of the user.

Technical Limitations of Data Control

Losing the device means:

Users are recommended:

Affirmative Statement

We do not hold your data.
We don't control your data.
You are in full power.

6. Children's Privacy

Child Protection Principles

PENA is committed to protecting the privacy and safety of children in the digital space. We expressly limit the use of the service so as not to violate applicable child protection laws.

User Age Restrictions

PENA is not intended for children under the age of 13, unless legally permitted by the applicable laws in the user's territory.

By using PENA, users represent and warrant that:

No Child Data Collection

PENA does not knowingly collect personal data from children, including but not limited to:

Because PENA:

therefore, technically PENA does not have a mechanism to identify the age of individual users.

Content & Communication

PENA does not moderate or monitor the content of user communications because:

Responsibility for the use of the app by the child lies solely with:

Actions in the event of a violation

If PENA becomes aware of any use of the services by a child in violation of applicable law:

Because the PENA architecture does not store data, the actions that can be taken are technical and limited.

The Role of Parents and Guardians

Parents or guardians are responsible for:

PENA recommends the use:

Compliance with Child Protection Laws

PENA strives to comply with the general principles of child protection as set forth in applicable laws and regulations, including but not limited to:

However, this compliance is still carried out without compromising the principles of anonymity and user encryption.

Affirmative Statement

PENA is not designed to collect child data.
We don't build anyone's profile — including kids.
Security and privacy start with restrictions, not oversight.

7. Prohibited Use

You are not allowed to use the PENA for unlawful activities, including but not limited to:

Accounts that are proven to have abused the service based on valid evidence may be restricted or disabled.

8. Requests from Law Enforcement

General Principles

PENA respects the applicable law. However, from the beginning, PENA was designed with the principle of privacy by design, so our ability to access or hand over user data is very limited technically.

We don't store data we don't own.

Limited Data Access

PENA does not store:

All communications:

Technically, PENA cannot read, access, or decrypt user communications, even at the request of any party.

Acceptable Types of Requests

PENA can only respond to law enforcement requests that:

However, our responses are still limited by:

Information That Might Be Conveyed

Under certain conditions and to the extent technically available, PENA can only provide:

General information about:

Non-identifying technical information that:

Information We Can't Provide

PENA cannot and will not provide:

No Backdoor Access

PENA does not provide a backdoor, monitoring mechanism, or hidden access.

Providing such access would be contrary to:

Transparency

Where legally possible, PENA reserves the right:

PENA cannot change the technical design of the application to meet data access requests.

Jurisdiction & Compliance

Each request is judged based on:

Legal compliance is carried out without:

Affirmative Statement

We respect the law.
But we don't keep what we shouldn't keep.
We cannot give up user privacy, because we do not have it.

9. Disclaimer

Nature of Service

PENA is provided as is and as available (as available).

We make no warranty that the service will:

No guarantee of communication success

PENA does not warrant that:

Service performance may be affected by:

User Safety & Risk

PENA uses high-level security technologies, including:

However, no system is completely risk-free.

Users understand and accept that:

Data Loss

Because PENA does not store data on the server:

may result in permanent data loss.

PENA is not responsible for:

Responsibility for Content

All communication content is the responsibility of the user.

PENA:

PENA is not responsible for:

Third-Party Services

PENA can rely on:

PENA is not responsible for:

Limitation of Liability

To the extent permitted by law, PENA is not responsible for:

No Legal or Professional Advice

PENA does not provide:

The use of the service is entirely the responsibility of the user.

Closing Statement

We build secure technology.
But the way that technology is used is entirely in your hands.
Use wisely.

10. Intellectual Property Rights

Ownership of Rights

All intellectual property rights contained in and related to the PENA application, including but not limited to:

Is owned by PENA or legally licensed to PENA, and is protected by applicable copyright, trademark, and applicable laws and regulations.

License to Users

PENA grants users a limited, non-exclusive, non-transferable, and revocable license, to:

This license is granted for personal and legitimate use only, in accordance with the terms of this service.

Restrictions on Use

Users are prohibited to:

User Content

All user-generated communication content (messages, files, media) remains the user's property.

PENA:

Any license to user content is not granted to PENA, as PENA does not technically store such content.

Feedback & Suggestions

If a user provides feedback, suggestions, or ideas to PENA:

Feedback is not considered confidential information, unless otherwise stated in writing.

Intellectual Property Rights Infringement

PENA reserves the right to take action against:

Actions can be:

Rights Not Granted

All rights that are not expressly granted to the user remain the property of PENA.

Affirmative Statement

We are building this technology seriously.
Use with respect.
Copyright is not to hinder, but to protect.

11. Jurisdiction

Applicable Law

The terms of use, privacy policy, and all legal relationships between users and PENA are governed by and construed based on the applicable laws of the Republic of Indonesia, without regard to the principle of conflicts of laws.

Scope of Jurisdiction Application

This jurisdiction applies to:

These terms apply regardless of the physical location of the user when accessing the service.

Dispute Resolution

Any disputes, disputes, or claims arising from the use of PENA will be resolved first through deliberation or peaceful settlement efforts.

If a peaceful settlement is not reached, the dispute will be resolved through the authorized legal forum in the territory of the Republic of Indonesia, in accordance with the provisions of the applicable laws and regulations.

Foreign Jurisdiction Restrictions

Users understand and agree that:

Technical Limitations Related to Jurisdiction

Because PENA:

then the exercise of certain jurisdictions may be technically restricted.

Users understand that these limitations are a consequence of PENA's privacy and security design.

No Waiver of Rights

The exercise of this jurisdiction does not eliminate or limit the rights of users protected by applicable law to the extent that it does not conflict with these terms of service.

Affirmative Statement

The law is still respected.
But privacy is not sacrificed.
Jurisdiction goes hand in hand with the principle of user protection.

12. Official Contact

For privacy questions, data requests, or other official needs, contact:

📩 [email protected]