Privacy policy

Ready Up Messenger

Last updated 15 August 2026

This policy explains how Blossom Interactive LLC ("Blossom Interactive", "we", "us"), a Florida limited liability company located at 7901 4th St N, Ste. 300, St. Petersburg, FL 33702, United States, handles information when you use Ready Up Messenger and readyupmessenger.com (together, the "Service"). Ready Up is available worldwide. By using the Service you agree to this policy and to our Terms of Service.

1. The short version

  • Your one-to-one and group messages, media, voice notes, locations and calls are end-to-end encrypted. We cannot read or listen to them.
  • Encryption keys are generated on your device and protected by your PIN. We hold no master key and no key escrow.
  • We collect the minimum needed to run the Service: your phone number, account identifiers, and limited technical and billing records.
  • We do not sell or share your personal information for behavioural advertising, and we do not run ad networks or third-party trackers in the app.

2. Information you give us

  • Account data: your phone number, country, display name, optional About text, avatar colour or photo, and a hashed record used to verify your PIN.
  • Verification data: one-time codes and the timestamps of verification attempts, kept briefly for security and anti-fraud purposes.
  • Contacts you choose to match: when you grant contact access, phone numbers are processed to find people already on Ready Up. Numbers we cannot match are not retained as contact records.
  • Content you send: stored only in encrypted form we cannot decrypt, and deleted from our systems after delivery or on the retention schedule below.
  • Support, abuse reports and billing information you submit voluntarily. A report you submit includes the message content you choose to attach, which you decrypt for us at the moment you report it.

3. Information collected automatically

  • Service metadata: account identifiers, device and session identifiers, linked-device records, timestamps of connections, and coarse routing information such as IP address.
  • Technical logs: crash reports, error diagnostics, approximate delivery and call setup events used to keep calls connected.
  • Push notification tokens, if you enable notifications, provided by Apple, Google or your browser vendor.
  • We do not log the contents of messages or calls, and we do not maintain a record of who you message that is readable outside the encrypted envelope beyond what is technically required to deliver it.

4. Why we process information (legal bases)

Where the EU or UK GDPR applies, we rely on: performance of a contract (operating your account, delivering messages and calls, processing subscriptions); legitimate interests (security, abuse prevention, service reliability, and defending legal claims); consent (contact access, notifications, optional features, which you can withdraw at any time); and legal obligation (responding to valid legal process, tax and accounting records).

5. Service providers

We use a small number of processors under written data protection terms: cloud hosting and database infrastructure, object storage for encrypted media, TURN relay servers for call connectivity, an SMS provider for verification codes, a payment processor for subscriptions, and push notification gateways. Media and message payloads reach these providers only in encrypted form. We do not authorise them to use your information for their own purposes.

6. Payments

Subscription payments are handled by our payment processor. We do not receive or store full card numbers. We retain transaction records, plan status and the last four digits or brand supplied to us, as required for accounting, tax and dispute handling.

7. International transfers

We operate globally and our infrastructure is primarily located in the United States and in regional data centres. Where information is transferred out of the EEA, the UK, Switzerland or another jurisdiction with transfer rules, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful mechanism, together with the technical protection provided by end-to-end encryption.

8. Retention

  • Encrypted message and call-setup payloads are held only as long as needed for delivery and your chosen sync window, then deleted.
  • Encrypted media stored in Cloud Vault is retained while your subscription is active and deleted within 30 days of cancellation.
  • Account records are retained while your account exists and deleted within 30 days of deletion, other than records we must keep for tax, fraud, security or legal defence.
  • Verification, security and billing logs are kept for up to 12 months, or longer where a legal claim or investigation requires it.

9. Your rights

Depending on where you live, you may have the right to access, correct, delete, port or restrict your personal information, to object to certain processing, to withdraw consent, and to be free from discrimination for exercising these rights. Residents of California (CCPA/CPRA), the EEA and UK (GDPR), Brazil (LGPD), Canada (PIPEDA), Australia, Japan, South Korea, South Africa, India and other jurisdictions with equivalent laws may exercise the rights their law provides.

To make a request, email privacy@readyupmessenger.com from the number or email associated with your account, or delete your account in Settings. We verify requests before acting and respond within the period required by applicable law. We do not sell personal information or share it for cross-context behavioural advertising, so there is nothing to opt out of.

EEA and UK users may lodge a complaint with their local supervisory authority. We have no EU or UK establishment; where an Article 27 representative is required, details will be published on this page.

10. Security

We use end-to-end encryption (AES-256-GCM content encryption with ECDH P-256 key agreement), DTLS-SRTP for calls, encryption in transit and at rest, access controls, and row-level database isolation. No system is perfectly secure. Because we cannot recover your keys, losing your PIN and all linked devices means your history cannot be restored by us or by anyone else.

11. Children

The Service is not intended for children under 13, or under 16 in the EEA, the UK and any jurisdiction setting a higher digital-consent age. We do not knowingly collect information from children below that age. If you believe a child has created an account, contact privacy@readyupmessenger.com and we will delete it.

12. Legal requests and abuse

We respond only to legally valid requests properly served on Blossom Interactive LLC at the address below. We will produce only the limited account records we actually hold. We cannot produce message or call content because we do not possess the keys. Where permitted, we notify affected users.

13. Deleting your account

You can request deletion in Settings under Privacy & encryption. Deletion immediately signs out your devices and destroys access to your device-held encryption keys. Your encrypted message history and Cloud Vault files cannot be recovered after deletion. Limited billing, fraud-prevention, or legal records may be retained only where required.

14. Changes and contact

We may update this policy. Material changes will be announced in the app or by notice on readyupmessenger.com before they take effect, and continued use after that date means you accept the update. Questions or privacy requests: privacy@readyupmessenger.com.

Blossom Interactive LLC

7901 4th St N, Ste. 300, St. Petersburg, FL 33702, United States

Registered agent: Northwest Registered Agent LLC

Legal notices: legal@readyupmessenger.com · Privacy requests: privacy@readyupmessenger.com