Privacy Policy

Last updated: September 10, 2026

This policy explains what Secure Chat ("we", "the service") stores when you use the app, and — just as important — what it can never see. The short version: your messages, photos, voice notes, and calls are end-to-end encrypted, and the server that carries them only ever handles ciphertext it cannot decrypt.

1. What we store

2. What we can never see

3. Sign-in

You can sign in with a one-time code sent to your email, or with Google Sign-In. For email codes we use Resend to deliver the message (they process the email address for delivery only). For Google Sign-In we receive only your verified email address, name, and profile photo from Google's verification response. We do not request or receive your Google password, and we cannot post or read your Gmail.

4. Third parties we rely on

We do not run advertising SDKs, analytics profiles, or crash-reporting SDKs, and we never sell or share your data with anyone.

5. Server logs

Standard web-server and error logs are kept briefly for troubleshooting and may include IP addresses and request timestamps. One-time codes are stored only as cryptographic hashes. We don't build behavioral profiles from logs.

6. Data retention and deletion

Undelivered encrypted messages are purged after delivery or expiry; delivered message data and media blobs are purged within 30 days. To delete your account (email, profile, public keys, and any stored blobs), use "Report a problem" in the app with the request, or contact us at the address below. Because message history and private keys exist only on your devices, deleting the app data on a device permanently removes that device's history.

7. Children

The service is not directed at children under 13.

8. Changes to this policy

If we change this policy we will update the date above and, for significant changes, notify you in the app.

9. Contact

Questions or deletion requests: use "Report a problem" inside the app, or email [email protected].