Scope
This Privacy Policy applies to the Privyn development website and the account, Contacts, Chats, Letters and related cryptographic-device functionality provided through dev.privyn.app.
Information Privyn processes
Account information
Privyn processes account identifiers such as your username and internal user ID.
Authentication information
Privyn may store the public information required to authenticate Passkeys, including credential identifiers and public-key information. Private Passkey material is controlled by your authenticator and is not required by Privyn's server for authentication.
Device information
Privyn processes device IDs, public device cryptographic keys, protocol information, registration timestamps and revocation status.
Contact information
The current development architecture stores one-way Contact relationships on the server so the service can provide Contact lookup and cryptographic identity discovery.
Communication routing metadata
To deliver encrypted communications, Privyn may process metadata such as:
- sending and receiving device IDs;
- protocol version or communication channel type;
- creation, delivery, expiry and related timestamps;
- encrypted message-envelope size;
- encrypted ciphertext.
MLS public cryptographic material
Privyn may process public MLS identity information, public KeyPackages, device-binding signatures and related identifiers needed to establish encrypted conversations.
Session and network-security information
Privyn processes session information necessary to keep you signed in. Limited network and request information, such as IP address, request time, requested path and user-agent information, may also be processed where necessary to operate, secure and troubleshoot the service.
What the communication server does not receive
Supported Chat messages and Letter subjects and bodies are encrypted by the Privyn client before they are uploaded for delivery.
The Privyn communication server is not designed to receive the plaintext content of supported encrypted Chats or Letters.
Privyn does not maintain a universal server-side key intended to decrypt all user communications.
This does not mean that Privyn hides all metadata. The service necessarily processes some account, device, routing and operational information to function.
Information stored on your device
Privyn stores certain cryptographic and application information locally in your browser or device.
Depending on the feature, this may include:
- device private cryptographic keys;
- MLS cryptographic state;
- local trust records;
- encrypted conversation metadata;
- encrypted Chat history;
- encrypted Letter mailbox data.
Clearing browser storage, losing a device or losing access to local cryptographic material may make locally stored information inaccessible.
How information is used
Privyn uses information to:
- create and authenticate accounts;
- register and authenticate devices;
- establish encrypted communications;
- route encrypted messages and Letters;
- maintain Contacts and identity trust functionality;
- prevent abuse and protect the security and reliability of the service;
- diagnose technical problems;
- comply with applicable legal obligations.
Privyn is not designed around advertising and does not use message content to build advertising profiles.
Privyn does not sell user personal data to advertisers.
Retention
Different categories of information are retained for different periods according to operational purpose.
- Account and device records may remain while the account or registered device remains active and for any additional period reasonably required for security, dispute or legal purposes.
- Encrypted delivery envelopes may remain until successfully acknowledged, deleted or expired according to the applicable delivery configuration.
- Single-use or expiring cryptographic publication material may be deleted when consumed or expired.
- Locally stored data remains on the user's device until removed by Privyn functionality, browser storage controls, account actions or other device-level processes.
Deletion from active systems may not instantly remove every residual copy contained in backups or limited security records where temporary retention is necessary and lawful.
Security
Privyn uses technical and organizational measures intended to protect information and reduce unnecessary access to communication content.
Current development measures include client-side communication encryption, device cryptographic identities, authenticated encrypted sessions and transport encryption.
Browser compromise, device compromise, malicious software, credential theft, implementation flaws and other threats can undermine otherwise strong cryptography.
Your privacy rights
Depending on where you live and the law applicable to the processing, you may have rights relating to your personal data, including rights to:
- request access to personal data;
- request correction of inaccurate data;
- request deletion where applicable;
- object to or request restriction of certain processing where applicable;
- withdraw consent where processing depends on consent;
- receive certain data in a portable form where applicable;
- complain to an applicable supervisory or regulatory authority.
Because Privyn's server is not designed to possess plaintext copies of supported encrypted communications, a server-side data-access response may not contain readable message or Letter content.
International processing
Infrastructure and technical providers may process limited information in jurisdictions other than the user's own. Where applicable law imposes requirements on international transfers, Privyn will apply the protections required by that law.
Children
Privyn is not intended for people who cannot legally agree to the applicable Terms of Service. If applicable law requires parental or guardian consent, the service should not be used without that consent.
Changes to this Policy
This Privacy Policy may change as Privyn develops, legal requirements change or the service's processing practices change.
The “Updated” date at the top of this page will identify the current version.
Privacy contact
Privacy questions and requests may be sent to:
Privyn Privacy
privacy@privyn.app