Last updated: September 10, 2026
This policy explains what Secure Chat ("we", "the service") stores when you use the app, and — just as important — what it can never see. The short version: your messages, photos, voice notes, and calls are end-to-end encrypted, and the server that carries them only ever handles ciphertext it cannot decrypt.
You can sign in with a one-time code sent to your email, or with Google Sign-In. For email codes we use Resend to deliver the message (they process the email address for delivery only). For Google Sign-In we receive only your verified email address, name, and profile photo from Google's verification response. We do not request or receive your Google password, and we cannot post or read your Gmail.
We do not run advertising SDKs, analytics profiles, or crash-reporting SDKs, and we never sell or share your data with anyone.
Standard web-server and error logs are kept briefly for troubleshooting and may include IP addresses and request timestamps. One-time codes are stored only as cryptographic hashes. We don't build behavioral profiles from logs.
Undelivered encrypted messages are purged after delivery or expiry; delivered message data and media blobs are purged within 30 days. To delete your account (email, profile, public keys, and any stored blobs), use "Report a problem" in the app with the request, or contact us at the address below. Because message history and private keys exist only on your devices, deleting the app data on a device permanently removes that device's history.
The service is not directed at children under 13.
If we change this policy we will update the date above and, for significant changes, notify you in the app.
Questions or deletion requests: use "Report a problem" inside the app, or email [email protected].