1. Introduction
At Evercrypted ("We", "Us", "Our"), we take your privacy seriously. This Privacy Policy explains how we collect, use, and protect your information when you use our secure messaging application.
By using Evercrypted, you agree to the collection and use of information in accordance with this policy.
2. Privacy and Data Protection
2.1 End-to-End Encryption
- For premium license accounts, messages and shared content are end-to-end encrypted and may be password encrypted on top.
- We cannot access, read, or decrypt your communications.
- Your communications are private between you and your intended recipients.
- Message history is stored locally on your devices, and between their delivery may be temporarily stored on our servers also.
2.2 Data Collection and Processing
We strictly limit data collection to what is necessary to operate the Service:
Account Information:
- Email Address (required for account creation and password recovery)
- Profile name and picture (optional, end-to-end encrypted)
- Account settings and preferences (stored securely)
Technical Information:
- Device identifiers and push notification tokens (to deliver messages)
- Connection information (IP addresses, timestamps - ephemeral logs for security)
- Performance and diagnostic data (anonymized where possible)
- Crash reports and error logs (to improve app stability)
2.3 Data Retention and Deletion
- Messages are queued temporarily on servers only to insure delivery to offline devices.
- Messages are deleted from servers immediately once delivered.
- We retain minimal technical data only as long as necessary for service operation and security.
- You can delete your account and associated data at any time through the app settings.
- Account deletion is permanent and irreversible.
3. Data Permissions and Compliance
3.1 GDPR Compliance
For users in the European Economic Area (EEA), UK, and Switzerland:
- We are the data controller for your personal information.
- You have rights to access, rectify, erase, restrict, and port your data.
- You have the right to withdraw consent and object to processing.
- We process data based on consent, legitimate interests, and contractual necessity.
- Data transfers outside the EEA are protected by appropriate safeguards.
- Contact team@evercrypted.com to exercise your rights.
3.2 International Data Transfers
- Data may be transferred to countries outside your jurisdiction to provide the Service.
- We implement appropriate safeguards including encryption and contractual protections.
- For EEA users, transfers comply with GDPR requirements.
3.3 Law Enforcement Cooperation
- We may cooperate with law enforcement when legally required.
- Due to end-to-end and password-based encryption, we cannot access or provide encrypted message content.
- We may provide non-content information (e.g. registration date) only when compelled by valid legal process.
- We will publish transparency reports regarding government requests where permitted.
4. Contact Information
For questions about this Privacy Policy or your data:
Effective Date: 28 October 2025