Belo Privacy Policy

Last Updated: September 13, 2026

1. Introduction

Belo ("we," "us," or "our") is a private messaging application built by GIOIA. This Privacy Policy explains what information we collect, how we use it, and the choices you have.

Please read Section 6 carefully. Belo is not an end-to-end encrypted messenger. Your messages are encrypted while travelling over the network and encrypted at rest on our servers, but we hold the keys and we are technically able to access message content. Some features, including optional mood analysis and our AI assistant, work by processing message text on our servers. Section 3.9 lists every one of those features and the providers involved.

Please also read Section 3.9 on flows. Belo has community spaces called flows. What you post in a flow room is read by automated features by default, whatever the flow's join settings are, and that is not something you turn on or off. Your direct messages and private groups are treated differently, and are governed by the single AI features consent described in Section 3.7.

This policy applies to the Belo mobile application and all related services. By using Belo, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the app.

For questions about this policy, see Section 17 (Contact Us).

2. Legal Basis for Processing Personal Data

We process your personal data based on the following legal grounds:

If you are in the European Economic Area (EEA) or United Kingdom, GIOIA acts as the data controller for your personal data.

3. Information We Collect

3.1 Account Information

When you create a Belo account, we collect:

3.2 Messages and Content

3.3 Contacts

3.4 Usage Information

3.5 Device Information

3.6 Calls and Peek

3.7 Mood Awareness and the AI Features Consent

Belo includes an optional ambient mood awareness feature that provides visual feedback about the emotional tone of your conversations (such as chat background colors and contact aura glows). It is governed by a single consent that also covers several other AI features, described below.

3.8 Cookies and Local Storage

Belo is a mobile application and does not use browser cookies. Local data is stored on your device using:

No tracking cookies or advertising identifiers are used.

3.9 AI Features and Message Content

Several Belo features work by sending message text from our servers to third-party AI providers. This section lists all of them, what each one reads, where the text goes, and what causes it to run. We consider this the most important disclosure in this policy.

Flows are community spaces. A flow is a shared community, and the rooms inside it are community spaces. The AI features below operate on flow rooms by default, whatever the flow's join settings are: open to anyone, request to join, invite only, or restricted to a role. A flow being private does not make its rooms exempt, and this is not conditional on your consent or on anyone else's. Treat a flow room as a place where what you write is read by automated features. If you would not want that, do not post it in a flow room.

The exception: private one-to-one rooms inside a flow. Some rooms in a flow are conversations between two people rather than community spaces. These are member-to-member rooms (a private one-to-one room you share with another member of the flow) and personal rooms, such as a one-to-one feedback room with the flow's staff. They are not community spaces. We treat them like direct messages, which means the rules in the "When it runs" column that apply to direct messages and private groups apply to them too, not the community rules.

FeatureWhat it readsProviderWhen it runs
Mood awareness (Section 3.7)Each message you send, plus the 2 preceding messagesOpenAIOnly when every participant has turned AI features on
AI assistantConversations and content you already have access to, when needed to carry out your requestOpenAIWhen you ask the assistant to do something. For direct messages, private groups, and private one-to-one rooms inside a flow: only when every participant, including you, has turned AI features on. If anyone in the conversation has it off, the assistant is shown nothing from that conversation and says so. For flow rooms: always, whatever the flow's join settings
Composer assist / tone checkYour draft plus up to 20 recent messages in that conversationOpenAIWhen you use the assist control (tone check runs automatically as you type), only when every participant has turned AI features on. If someone in the conversation has not, only your own draft is sent and none of the conversation
Writing style (composer assist)Your own text messages in direct messages, up to 1000 per run, to learn how you write. Never anyone else's messages, never anonymous chatsOpenAIOnce you have sent 20 direct messages, then every second night while AI features is on. The learned profile is deleted when you turn AI features off
Flow and room summariesRecent messages in flow rooms. Private one-to-one rooms inside a flow are excludedOpenAIAutomatically, for every flow room, whatever the flow's join settings. Not conditional on consent
Search indexText of messages, threads, posts, events and pops, converted into a numeric representation and stored as a second copy on our servers to make search workOpenAIDirect messages, private groups, and private one-to-one rooms inside a flow: only when every participant has turned AI features on. Community content (flow rooms whatever their join settings, posts, events, pops): always
Interest suggestionsPosts in flow rooms, whatever the flow's join settings. Never direct messages, private groups, or private one-to-one rooms inside a flowOpenAIAutomatically. Not conditional on consent

Two safeguards apply to all of the above:

OpenAI processes data in the United States. See Section 14 on international transfers.

4. Information We Do NOT Collect

5. How We Use Your Information

We use the information we collect to:

We do NOT use your information for:

6. How We Protect Your Messages

We want to be direct about this, because earlier versions of this policy were not.

Belo does not currently provide end-to-end encryption for message content. Messages are not encrypted on your device in a way that prevents us from reading them. What we do provide is:

What this means in practice: we are technically able to read message content, our servers do process it for the features described in Section 3.9, and we can be compelled to produce it under valid legal process (see Section 7.4). If end-to-end encryption is a requirement for you, Belo does not meet it today.

Where we do use end-to-end encryption. Belo uses X25519 key exchange and AES-256-GCM encryption to protect two specific things, and these genuinely are encrypted end to end:

Encryption keys for these purposes are generated on your device and stored in secure storage (iOS Keychain / Android EncryptedSharedPreferences). They are not used to encrypt message content.

7. Data Sharing

7.1 Other Belo Users

When you use Belo, certain information is visible to people you communicate with:

Users you communicate with may save, copy, or share the content you send them outside of Belo. We cannot control how recipients use content after delivery.

7.2 Third-Party Service Providers

We use the following third-party services to operate Belo:

ProviderPurposeData Shared
TelnyxPhone number verification (SMS)Phone number
Firebase Cloud Messaging (Google); delivery to Apple devices via Apple Push Notification servicePush notification deliveryDevice token, platform type, and notification content, which for a new message or reaction may include the sender's name and the message text
LiveKitGroup video/audio callsCall streams (real-time, not stored)
Google STUN Servers (Google)P2P call/Peek connection setupIP address (for NAT traversal only)
KlipyGIF and sticker searchYour search query text (sent from our servers; your IP address is not shared with Klipy)
MapboxMaps and location displayApproximate location, IP address, and map-interaction/device diagnostics (collected directly by the Mapbox SDK on your device)
OpenAI (United States)Mood analysis (opt-in), AI assistant, composer assist, flow and room summaries, search index, interest suggestionsMessage and post content — see Section 3.9

These providers process data only as necessary to provide their services and are bound by their own privacy policies. OpenAI receives message content and is the most sensitive processor on this list, which is why Section 3.9 describes it in detail.

7.3 Corporate Structure

Belo is operated by GIOIA. Your data may be shared within our corporate group for the purposes described in this policy. Any affiliated companies are bound by the same data protection obligations.

7.4 Law Enforcement

We may disclose information if required by law, valid court order, or legal process.

Information we can be compelled to provide includes:

We will evaluate each request on its merits and may challenge requests we believe are overly broad or unlawful. We will notify affected users unless prohibited by law.

7.5 Assignment and Change of Control

In the event of a merger, acquisition, reorganization, or sale of assets, your personal data may be transferred to the successor entity. We will notify you of any such change and any choices you may have regarding your data.

7.6 We Do NOT

8. Keeping Your Data Safe

8.1 Infrastructure Security

8.2 Message Content

Message content is encrypted in transit and at rest, but we hold the decryption keys, so we are able to access it. Access to production data is limited to personnel who need it to operate the service, and automated features may only access content within the permission boundaries described in Section 3.9. We do not have a technical guarantee against our own access, and we do not claim one.

8.3 Local Device Security

Encryption keys, authentication tokens, and sensitive credentials are stored in your device's secure enclave (iOS Keychain / Android EncryptedSharedPreferences). Message history is cached in a local encrypted database.

8.4 Mood Data Security

Mood scores are stored as numeric metadata alongside the associated message. The scores themselves cannot be used to reconstruct message text. The message text used to produce them is, however, sent to a third-party AI provider when you have opted in, as described in Sections 3.7 and 3.9.

9. Data Retention

10. Your Rights and Choices

10.1 In-App Controls

You can directly control:

10.2 Account Deletion

You can permanently delete your account at any time. This will:

10.3 Data Access and Portability

You have the right to:

To exercise these rights, contact us at the address in Section 17.

10.4 EEA, UK, and Other Jurisdictions

If you are in a jurisdiction with data protection laws (such as GDPR, UK GDPR, or similar), you have the right to lodge a complaint with your local data protection supervisory authority.

11. Safety, Spam, and Abuse

To keep Belo safe for all users:

12. Third-Party Links and Services

Belo may display previews of links shared in conversations. These link previews are generated by our servers and do not share your identity with the linked website. When you tap a link to open it, you leave Belo and are subject to that website's privacy policy.

13. Children's Privacy

Belo is not intended for children under the age of 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal information from children. If we learn that we have collected data from a child under the applicable age, we will take steps to delete it promptly. If you believe a child has provided us with personal data, please contact us at the address in Section 17.

14. International Data Transfers

Your information may be transferred to and processed in countries other than your own. In particular:

When we transfer personal data outside the EEA or UK, we seek to put appropriate safeguards in place, such as:

If you would prefer that your message content not be sent to an AI provider, leave AI features off in Settings. With it off, your messages in direct chats, private groups, and private one-to-one rooms inside a flow are not sent for mood analysis, are not indexed for search by meaning, are not used by composer assist or the tone check, and cannot be read by the AI assistant. That last part applies even when someone else in the conversation is the one asking the assistant: with your setting off, the assistant is shown nothing from that conversation, for anyone in it.

This control does not cover what you post in flow rooms. Flow rooms are community spaces, and the features described in Section 3.9 read them regardless of this setting and regardless of the flow's join settings. If you do not want content sent to an AI provider, do not post it in a flow room.

15. U.S. State Privacy Rights

If you are a resident of California, Virginia, Colorado, Connecticut, Utah, or other U.S. states with consumer privacy laws, you may have additional rights including:

To exercise these rights, contact us at the address in Section 17.

16. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

Your continued use of Belo after changes are posted constitutes your acceptance of the updated policy. We encourage you to review this policy periodically.

DateChanges
September 13, 2026Composer assist can learn your writing style, under the same AI features consent. Section 3.7 now says that turning AI features on also lets the composer assist and tone check learn how you write, from your own direct messages only, so suggestions sound like you; Section 3.9 gains a row describing exactly what that reads, when it runs, and that the learned profile is deleted when you turn AI features off. This is a new use of your message text, so it applies to you only after you have seen the updated consent: people who turned AI features on before this date are not enrolled until they confirm the new wording in the app. Section 3.9 also now states what happens in a conversation where someone has AI features off: the composer assist and tone check still run on the message you are typing, and nothing from the conversation is sent.
August 4, 2026The AI assistant now needs everyone's consent, not just yours. The August 2 version said the assistant applied the AI features consent per author, so it could still read a private conversation while being shown only the messages of the people who had turned AI features on. That is no longer how it works. The assistant now reads a direct message, private group, or private one-to-one room inside a flow only when every participant, including you, has AI features on. If anyone in the conversation has it off, the assistant is shown nothing from that conversation, not even the messages of the person asking, and it says that it cannot read it. This matches the rule that already applied to mood analysis, composer assist and the search index. Nothing changed for flow rooms: they are community spaces and the AI features read them either way, with private one-to-one rooms inside a flow still treated like direct messages. Sections 3.7, 3.9 and 14 updated to match.
August 2, 2026Flows described honestly, and one AI features consent. Previous versions said interest suggestions read "posts in public flow rooms only," and Section 5 said we do not use group message content to suggest connections. Neither was accurate. Flow rooms can be invite only or restricted to a role, and our AI features read them either way. Sections 3.9 and 5 now say plainly that flow rooms are community spaces, that the AI features operate on them by default whatever the flow's join settings are, and that this is not conditional on consent. Private one-to-one rooms inside a flow, meaning member-to-member rooms and personal rooms such as feedback rooms with flow staff, are not community spaces and are treated like direct messages. Separately, the single consent previously called "Emotional Intelligence" is now called AI features and covers four things instead of two: mood colouring, search by meaning, composer assist and the tone check, and whether the AI assistant may read your direct messages and private groups. The assistant applies it per author, so it is shown only messages written by people who have turned AI features on, and it tells you when messages were withheld. Leaving it off now withholds your messages from the assistant, including when someone else in the conversation asks it something. Sections 1, 3.7, 3.9, 5, 10.1 and 14 updated to match. We also corrected a smaller inaccuracy in the same section: Section 3.9 said the search index "enforces the same permissions as the app itself," when for pops it is actually stricter than the app, and it now says so. No feature changed what it reads as a result of this update; the wording changed to describe what it already did.
July 28, 2026Change of AI provider. The features that read message text — mood analysis, the AI assistant, composer assist, and flow and room summaries — now use OpenAI in the United States instead of DeepSeek in China. Message content is no longer sent to any processor in China. Updated Sections 3.7, 3.9, 7.2 and 14 to match. Nothing else changed: the same features read the same text under the same consent rules.
July 23, 2026Significant correction. Previous versions of this policy stated that messages were end-to-end encrypted and that we could not read message content. That was not accurate, and we have corrected it. Section 6 now describes what we actually do (encryption in transit and at rest, with keys held by us). Section 3.7 previously stated that mood analysis ran entirely on your device; in fact message text was sent to a third-party AI provider. Mood analysis is now off by default and requires your explicit consent. Added Section 3.9 listing every AI feature that processes message content. Added DeepSeek and OpenAI to the processor table in Section 7.2. Corrected Sections 7.4 (law enforcement), 8.2, 8.4, 9 (retention), 11 and 14 to match. Corrected the SMS provider named in the Russian version of Section 7.2.
March 28, 2026Added mood awareness disclosure (Section 3.7), Google STUN server disclosure (Section 3.6), corrected encryption description (Section 6), updated contact emails.
March 25, 2026Initial privacy policy published.

17. Contact Us

If you have questions about this Privacy Policy, want to exercise your data rights, or have concerns about our data practices, contact us at:

Email: [email protected]

Website: https://belo.media/

For EEA/UK residents, you may also contact our data protection representative at:

Email: [email protected]