Privacy Policy – PENA
This Privacy Policy describes how PENA ("we", "us", or "services") collects, uses, and protects information related to the use of the PENA app and other supporting sites, features, and services (hereinafter referred to as the "Platform").
PENA is designed to provide a secure, private, and fully encrypted communication experience, so your conversations remain entirely yours.
By installing or using PENA, you are deemed to have read and agreed to this policy.
1. Our Commitment to Your Privacy
Privacy is not just a feature for PENA. Privacy is a fundamental right of every individual and is the fundamental foundation of the entire system we build.
PENA is built on the core principle of privacy. PENA also does not collect user data in any form. The entire system is designed with the highest level of security standards and next-generation encryption technology, including protection against threats that do not exist today
We cannot view, store, or access your messages, and do not have the ability to read or record any communications that occur within PENA. All data and activities are completely under the control of the user.
All messages, communications, and data can only be viewed and stored by you. PENA does not own, does not store, and does not control any information from user activities within this application.
From the beginning, PENA was designed to ensure that full control of communications was in the hands of users, not in the hands of any company, server, or third party.
Privacy From the First Moment
PENA can be used without:
- Phone number
- Email address
- Original name
- Any personal identity
We believe that secure communication should not depend on identity. Therefore, PENA never asks for data that is not needed.
We Do Not Collect Personal Data
We are committed to:
- Not collecting users' personal data
- Not saving identity
- Not creating a user profile
- Not tracking communication activity
We don't know who you are, who you're talking to, or what you're talking about—and we don't want to know.
Communication Without a Central Server
PENA uses a peer-to-peer (P2P) architecture, which means:
- Messages are sent directly from device to device
- No central server to store data
- There is no single point to be tapped or hacked
With this approach, the risk of mass surveillance and data leakage can be significantly minimized.
Uncompromised Encryption
All communications at PENA are protected by:
- End-to-End Encryption
- Post-Quantum Encryption (PQE)
- Security mechanisms that are ready for future threats (post-quantum)
Only the sender and receiver can read the content of the message. Even we as developers don't have access.
Zero-Knowledge by Design
The PENA system is built on the principle of zero-knowledge:
- We don't store encryption keys
- We can't decrypt messages
- We cannot pass on the content of communications to anyone
If we don't have your data, then it can't be misused.
Your Data Stays on Your Device
- Messages and files are stored locally
- No cloud storage
- No hidden backups
When you delete something, the data is permanently lost, without any copies.
Additional File Security & Protection
To protect your device:
- Every incoming file is scanned with an anti-malware system
- The scan is carried out without compromising the privacy of the content of the communication
Peace must not come at the expense of freedom.
Freedom Comes With Responsibility
We give you complete freedom of communication.
However, we also believe that true freedom always comes with personal responsibility.
PENA does not monitor conversations, but users remain responsible for their actions in accordance with applicable law.
Long-Term Commitment
Privacy is not a momentary trend. We are committed to:
- Continuously improve security
- Keeping up with digital threats
- Not sacrificing privacy for commercial interests
Transparency & Trust
We strive to always be transparent about:
- How our system works
- Existing technical limitations
- The principles we hold
Trust is not required. Trust is built.
2. Information We Collect
PENA is designed with the principle of data minimization, which is to process only information that is really technically necessary, without compromising user privacy.
Basic Principles of Information Collection
PENA is designed with the principle of data minimization, which is to process only information that is really technically necessary, without compromising user privacy.
In general:
- We do not collect personal data
- We don't store user identities
- We don't have a database of users
Information We Do NOT Collect
PENA does not collect, store or process the following information:
- User's real name
- Phone number
- Email address
- Residential address
- Official identity document
- Device contacts
- Precise geographic location
- The content of a message or communication file
- Conversation history
- Communication metadata for user tracking
Content of Communication
All messages and files are end-to-end encrypted.
Content of communication:
- Inaccessible by PENA
- Not stored on the server
- Not processed for any purpose
Due to the peer-to-peer architecture, data moves directly between the user's devices.
Non-Identifying Technical Information
To ensure that the application can function properly, PENA may process limited technical information, which is non-identifiable, including:
- App version information
- Operating system information
- An anonymous crash log
- Temporary technical data for connection stability
This information:
- Not associated with user identity
- Not used for tracking
- Not sold or shared with third parties
Payment Information (Premium Service)
For Premium services, payments are processed by third-party providers.
PENA:
- Not storing card data
- Not storing account information
- Not having access to payment details
Payment information is fully subject to the privacy policy of the relevant payment provider.
Information Storage
All communication data is stored locally on the user's device.
PENA does not provide:
- Cloud storage
- Online backup
- Server-based cross-device synchronization
Deletion of Information
Users can delete data at any time.
Once removed:
- Data is permanently lost
- Irreversible
PENA does not have a copy of the data to restore.
Legal Obligations
Because PENA does not collect or store the content of communications, PENA cannot provide user communication data to any party.
Legal compliance is carried out without compromising the principles of privacy and anonymity.
Changes to Information Collection Policy
In the event of a change in the type of technical information processed, PENA will:
- Update this policy
- Announcing changes through official platforms
Changes are effective from the date they are announced.
3. Messages and Calls
Key Principles
Messages and calls in PENA are built on one simple principle: only the sender and receiver can know the contents.
PENA does not act as an intermediary that can read, store, or control user communications.
Message Encryption
All text, voice, and file messages:
- End-to-End Encrypted
- Using Post-Quantum Encryption (PQE)
Each communication session:
- Using a unique encryption key
- Not reusable
- Dynamically changing (polymorphic)
PENA:
- Doesn't have an encryption key
- Unable to decrypt messages
- Not keeping a copy of the message
Voice Calls & Secure Calls
Voice calls at PENA are made by:
- Direct peer-to-peer between devices
- No central server
Whole calls:
- Real-time encrypted
- Not recorded
- Not saved
- Inaccessible by PENA
PENA does not store:
- Call history
- Call metadata for tracking
- Time or duration information that can identify users
Peer-to-Peer (P2P) Architecture
Messages and calls are sent directly from the sender's device to the receiving device.
No server that:
- Save messages
- Forwarding the content of the communication
- Archive calls
The risk of mass data leaks is minimized because:
- No data storage center
- There is no single point of failure
Post-Quantum Encryption (PQE)
PENA is designed to deal with future computing threats.
Encryption systems consider:
- Quantum computer attacks
- Decrypt now, read later attacks
Communication keys:
- Unpredictable
- Cannot be saved for future decryption
Metadata & Privacy
PENA does not:
- Collect message metadata
- Create communication graphs
- Track who's talking to whom
Temporary technical information is only used for:
- Completing a P2P connection
- Maintain service stability
This information is temporary and not stored.
Message Deletion
Messages can be deleted manually or automatically.
Once removed:
- Not saved on the device
- Not stored on the server
- Irreversible
The Auto-Delete feature ensures that messages do not leave a digital footprint.
Technical Limitations
The quality of messages and calls can be affected by:
- Quality of user network
- Devices used
PENA does not guarantee:
- Connection is always stable
- Sound quality is always optimal
However, security remains a top priority.
User Responsibility
The user is responsible for the content of messages and calls made.
PENA does not moderate, record, or intervene in user communications.
4. How We Use Data
Principles of Data Use
PENA uses data with one main goal: to keep applications running safely, stably, and as they function — without compromising user privacy.
We do not use data to:
- Profiling
- Tracking
- Advertisement
- Monetization of user behavior
Data Used Technically
PENA only uses non-identifying technical data that is necessary to:
- Perform the basic functions of the app
- Keeping peer-to-peer connections stable
- Improve communication security
- Detecting and preventing technical glitches
This data is of the nature:
- While
- Anonymous
- Not connected with user identity
Use of Communication Data
Fill messages, calls, and files:
- Unread
- Not analyzed
- Not stored by PENA
End-to-end encryption ensures:
- PENA does not have access to the content of the communication
- No third party can read the data
All communication takes place directly between the user's devices.
Service Enhancement
Anonymous technical data can be used to:
- Fix bugs
- Improve app performance
- Adjust device compatibility
- Develop new security features
This use is carried out without:
- Storing user history
- Track individual activity
Legal Compliance
Because PENA does not store the content of communications or user identities, our ability to hand over data is severely limited.
Legal compliance is carried out to the extent possible without violating the principles of privacy and anonymity of users.
Paid Services (Premium)
Data associated with the Premium subscription is used only for:
- Enable paid features
- Manage subscription status
Payment information is managed by third parties and is not used for any other purpose by PENA.
No Ads & No Tracking
PENA:
- Not showing ads
- Not using a third-party tracker
- Not selling user data
We don't build a business from your data.
Control in the Hands of the User
The user has complete control over:
- Local data
- Message history
- Deletion of information
Once the data is deleted, it will:
- Permanently lost
- Irreversible
5. Control of Data
Principles of Data Ownership
In PENA, the data belongs entirely to the user.
PENA does not claim ownership of:
- Ask
- Call
- File
- Communication history
We only provide technology, not control data.
Full Control on User Devices
All communication data is stored locally on the user's device.
There is no cloud storage, backup servers, or central archives.
Independent users:
- Managing
- Storing
- Delete data at any time
Right to Delete Data
Users can remove:
- Ask
- File
- Conversation history
Once removed:
- Data is permanently lost
- Irreversible
- No copy left in the PENA system
Removal is instant and final.
No Remote Access
PENA does not have:
- Remote access to the user's device
- Data collection mechanism
Even under certain conditions:
- PENA cannot read data
- PENA cannot recover data
Control over Files & Media
Each file received:
- Stored locally
- Can be removed manually or automatically
Anti-malware features:
- Protecting users
- Not saving files
- Not uploading files to PENA servers
Control over Identity
PENA does not use:
- Phone number
- Official identity
No centralized account should be closed.
Deleting an app means:
- Delete all data
- End use completely
Rights of Access & Portability
Because PENA does not store user data, requests:
- Copy of data
- Data transfer
- Data access by other parties
Technically not available.
All control is in the hands of the user.
Technical Limitations of Data Control
Losing the device means:
- Data loss
- Irrecoverable by PENA
Users are recommended:
- Keep your device secure
- Using additional security (PIN, biometrics, wipe code)
Affirmative Statement
We do not hold your data.
We don't control your data.
You are in full power.
6. Children's Privacy
Child Protection Principles
PENA is committed to protecting the privacy and safety of children in the digital space. We expressly limit the use of the service so as not to violate applicable child protection laws.
User Age Restrictions
PENA is not intended for children under the age of 13, unless legally permitted by the applicable laws in the user's territory.
By using PENA, users represent and warrant that:
- They have met the minimum age limit, or
- Have the valid consent of a parent or legal guardian (if required by local law).
No Child Data Collection
PENA does not knowingly collect personal data from children, including but not limited to:
- Name
- Identity
- Contact information
- Location
- Content of communication
Because PENA:
- Not asking for identity
- Not keeping a centralized account
- Not managing user databases
therefore, technically PENA does not have a mechanism to identify the age of individual users.
Content & Communication
PENA does not moderate or monitor the content of user communications because:
- All communications are end-to-end encrypted
- Takes place on a peer-to-peer basis
Responsibility for the use of the app by the child lies solely with:
- Parents
- Legal guardian
- Who grants device access
Actions in the event of a violation
If PENA becomes aware of any use of the services by a child in violation of applicable law:
- We reserve the right to restrict or terminate access to the service
- No obligation to store or process such user data
Because the PENA architecture does not store data, the actions that can be taken are technical and limited.
The Role of Parents and Guardians
Parents or guardians are responsible for:
- Monitor device usage
- Manage app access
- Educating children about digital safety
PENA recommends the use:
- Device security
- Parental control at the operating system level
Compliance with Child Protection Laws
PENA strives to comply with the general principles of child protection as set forth in applicable laws and regulations, including but not limited to:
- Children's privacy protection
- Data exploitation prevention
- Restrictions on information collection
However, this compliance is still carried out without compromising the principles of anonymity and user encryption.
Affirmative Statement
PENA is not designed to collect child data.
We don't build anyone's profile — including kids.
Security and privacy start with restrictions, not oversight.
7. Prohibited Use
You are not allowed to use the PENA for unlawful activities, including but not limited to:
- Scams
- Harassment
- Spread of malicious content
- Illegal access to data belonging to others
Accounts that are proven to have abused the service based on valid evidence may be restricted or disabled.
8. Requests from Law Enforcement
General Principles
PENA respects the applicable law. However, from the beginning, PENA was designed with the principle of privacy by design, so our ability to access or hand over user data is very limited technically.
We don't store data we don't own.
Limited Data Access
PENA does not store:
- The content of the message
- Call recording
- Communication files
- Encryption key
- User identity
All communications:
- End-to-end encryption
- Takes place directly between devices (peer-to-peer)
Technically, PENA cannot read, access, or decrypt user communications, even at the request of any party.
Acceptable Types of Requests
PENA can only respond to law enforcement requests that:
- Legal
- Delivered through official procedures
- Complies with applicable jurisdictions
However, our responses are still limited by:
- Application technical architecture
- Principle of user anonymity
Information That Might Be Conveyed
Under certain conditions and to the extent technically available, PENA can only provide:
General information about:
- How the system works
- Security architecture
- Privacy Policy
Non-identifying technical information that:
- Doesn't reveal the user's identity
- Not disclosing the content of the communication
Information We Can't Provide
PENA cannot and will not provide:
- Fill in the message or call
- Communication metadata for tracking
- User identity
- History of communication activity
- Encryption key or decryption access
- Data we never store
No Backdoor Access
PENA does not provide a backdoor, monitoring mechanism, or hidden access.
Providing such access would be contrary to:
- Security principle
- User privacy rights
- The main purpose of PENA
Transparency
Where legally possible, PENA reserves the right:
- Notify users of legal requests
- Denying requests that exceed legal authority
PENA cannot change the technical design of the application to meet data access requests.
Jurisdiction & Compliance
Each request is judged based on:
- Applicable law
- Legitimate jurisdiction
- Principles of human rights and privacy
Legal compliance is carried out without:
- Breach of encryption
- Sacrificing anonymity
- Changing the P2P architecture
Affirmative Statement
We respect the law.
But we don't keep what we shouldn't keep.
We cannot give up user privacy, because we do not have it.
9. Disclaimer
Nature of Service
PENA is provided as is and as available (as available).
We make no warranty that the service will:
- Always available without interruption
- Free from technical errors
- Always compatible with the entire device or network
No guarantee of communication success
PENA does not warrant that:
- Messages will always be sent
- Calls are always connected
- Communication quality is always optimal
Service performance may be affected by:
- The user's internet connection
- Hardware
- Operating system
- Third-party network factors
User Safety & Risk
PENA uses high-level security technologies, including:
- End-to-end encryption
- Peer-to-peer architecture
- Post-Quantum Encryption (PQE) mechanism
However, no system is completely risk-free.
Users understand and accept that:
- The risk of using technology remains
- The security of the user's device is beyond PENA's control
Data Loss
Because PENA does not store data on the server:
- Device loss
- App removal
- System malfunction
may result in permanent data loss.
PENA is not responsible for:
- Lost messages
- Lost files
- Loss of communication history
Responsibility for Content
All communication content is the responsibility of the user.
PENA:
- Not monitoring the content of the message
- Not moderating communication
- Not knowing the content of the conversation
PENA is not responsible for:
- Illegal content
- Abuse of services
- Losses arising from user communication
Third-Party Services
PENA can rely on:
- Network infrastructure
- Third-party payment services
PENA is not responsible for:
- Third-party service interruptions
- System errors beyond PENA control
Limitation of Liability
To the extent permitted by law, PENA is not responsible for:
- Indirect losses
- Loss of profits
- Data loss
- Losses due to the use of or inability to use the service
No Legal or Professional Advice
PENA does not provide:
- Legal advice
- Professional safety advice
- Usage compliance guarantee
The use of the service is entirely the responsibility of the user.
Closing Statement
We build secure technology.
But the way that technology is used is entirely in your hands.
Use wisely.
10. Intellectual Property Rights
Ownership of Rights
All intellectual property rights contained in and related to the PENA application, including but not limited to:
- Software
- Source code and object code
- System architecture and security design
- PENA name, logo, and brand identity
- User interface (UI/UX)
- Documentation, text, and supporting materials
Is owned by PENA or legally licensed to PENA, and is protected by applicable copyright, trademark, and applicable laws and regulations.
License to Users
PENA grants users a limited, non-exclusive, non-transferable, and revocable license, to:
- Download
- Install
- Using the PENA app
This license is granted for personal and legitimate use only, in accordance with the terms of this service.
Restrictions on Use
Users are prohibited to:
- Copying, modifying, or distributing the PENA application without written permission
- Reverse engineering, decompilation, or code disassembly
- Remove or change copyright or proprietary notices
- Using the PENA brand, logo, or identity without official permission
- Exploiting the PENA system for commercial purposes without consent
User Content
All user-generated communication content (messages, files, media) remains the user's property.
PENA:
- Not claiming ownership of user content
- Do not use the content for any purpose
- Not having access to the content
Any license to user content is not granted to PENA, as PENA does not technically store such content.
Feedback & Suggestions
If a user provides feedback, suggestions, or ideas to PENA:
- The feedback can be used for service development
- No compensation obligation
Feedback is not considered confidential information, unless otherwise stated in writing.
Intellectual Property Rights Infringement
PENA reserves the right to take action against:
- Unauthorized use
- Copyright infringement
- Brand abuse
Actions can be:
- Access restrictions
- Termination of service
- Legal steps in accordance with applicable regulations
Rights Not Granted
All rights that are not expressly granted to the user remain the property of PENA.
Affirmative Statement
We are building this technology seriously.
Use with respect.
Copyright is not to hinder, but to protect.
11. Jurisdiction
Applicable Law
The terms of use, privacy policy, and all legal relationships between users and PENA are governed by and construed based on the applicable laws of the Republic of Indonesia, without regard to the principle of conflicts of laws.
Scope of Jurisdiction Application
This jurisdiction applies to:
- Use of the PENA application
- Access to services
- Rights and obligations of users and PENA
- Disputes arising out of or related to the service
These terms apply regardless of the physical location of the user when accessing the service.
Dispute Resolution
Any disputes, disputes, or claims arising from the use of PENA will be resolved first through deliberation or peaceful settlement efforts.
If a peaceful settlement is not reached, the dispute will be resolved through the authorized legal forum in the territory of the Republic of Indonesia, in accordance with the provisions of the applicable laws and regulations.
Foreign Jurisdiction Restrictions
Users understand and agree that:
- PENA is not automatically subject to foreign jurisdictions
- PENA does not guarantee compliance with all laws in every country
- It is the user's responsibility to ensure that the use of PENA does not violate local laws in their respective regions.
Technical Limitations Related to Jurisdiction
Because PENA:
- Not storing user data
- Not saving the content of the communication
- Not managing identities
then the exercise of certain jurisdictions may be technically restricted.
Users understand that these limitations are a consequence of PENA's privacy and security design.
No Waiver of Rights
The exercise of this jurisdiction does not eliminate or limit the rights of users protected by applicable law to the extent that it does not conflict with these terms of service.
Affirmative Statement
The law is still respected.
But privacy is not sacrificed.
Jurisdiction goes hand in hand with the principle of user protection.
12. Official Contact
For privacy questions, data requests, or other official needs, contact: