PRIVYN
Terms Sign in Home
PRIVACY

Privacy Policy

This Policy explains what information Privyn processes, what the server does and does not receive, why information is used, and the choices available to users.

Development environment. This policy describes the current development architecture. Privyn's final operating legal entity, registered address and production privacy contact will be identified before production launch.
Effective August 11, 2026
Updated August 11, 2026
Advertising None
CONTENTS
Scope Information processed Message plaintext Local device data How data is used Sharing Retention Security Your rights International processing Children Changes Contact
01

Scope

This Privacy Policy applies to the Privyn development website and the account, Contacts, Chats, Letters and related cryptographic-device functionality provided through dev.privyn.app.

02

Information Privyn processes

Account information

Privyn processes account identifiers such as your username and internal user ID.

Authentication information

Privyn may store the public information required to authenticate Passkeys, including credential identifiers and public-key information. Private Passkey material is controlled by your authenticator and is not required by Privyn's server for authentication.

Device information

Privyn processes device IDs, public device cryptographic keys, protocol information, registration timestamps and revocation status.

Contact information

The current development architecture stores one-way Contact relationships on the server so the service can provide Contact lookup and cryptographic identity discovery.

Communication routing metadata

To deliver encrypted communications, Privyn may process metadata such as:

  • sending and receiving device IDs;
  • protocol version or communication channel type;
  • creation, delivery, expiry and related timestamps;
  • encrypted message-envelope size;
  • encrypted ciphertext.

MLS public cryptographic material

Privyn may process public MLS identity information, public KeyPackages, device-binding signatures and related identifiers needed to establish encrypted conversations.

Session and network-security information

Privyn processes session information necessary to keep you signed in. Limited network and request information, such as IP address, request time, requested path and user-agent information, may also be processed where necessary to operate, secure and troubleshoot the service.

03

What the communication server does not receive

Message plaintext

Supported Chat messages and Letter subjects and bodies are encrypted by the Privyn client before they are uploaded for delivery.

The Privyn communication server is not designed to receive the plaintext content of supported encrypted Chats or Letters.

Privyn does not maintain a universal server-side key intended to decrypt all user communications.

This does not mean that Privyn hides all metadata. The service necessarily processes some account, device, routing and operational information to function.

04

Information stored on your device

Privyn stores certain cryptographic and application information locally in your browser or device.

Depending on the feature, this may include:

  • device private cryptographic keys;
  • MLS cryptographic state;
  • local trust records;
  • encrypted conversation metadata;
  • encrypted Chat history;
  • encrypted Letter mailbox data.

Clearing browser storage, losing a device or losing access to local cryptographic material may make locally stored information inaccessible.

05

How information is used

Privyn uses information to:

  • create and authenticate accounts;
  • register and authenticate devices;
  • establish encrypted communications;
  • route encrypted messages and Letters;
  • maintain Contacts and identity trust functionality;
  • prevent abuse and protect the security and reliability of the service;
  • diagnose technical problems;
  • comply with applicable legal obligations.
No advertising profile

Privyn is not designed around advertising and does not use message content to build advertising profiles.

No sale of user data

Privyn does not sell user personal data to advertisers.

06

When information may be shared

Privyn does not disclose personal data simply because it is commercially valuable.

Limited information may be processed by infrastructure or technical service providers acting on Privyn's behalf where necessary to operate, host, protect or maintain the service.

Information may also be disclosed where required by applicable law, valid legal process, or where reasonably necessary to protect users, Privyn, or others from fraud, abuse or security threats.

Where Privyn does not possess readable plaintext communication content, it cannot disclose plaintext from server records that it does not have.

07

Retention

Different categories of information are retained for different periods according to operational purpose.

  • Account and device records may remain while the account or registered device remains active and for any additional period reasonably required for security, dispute or legal purposes.
  • Encrypted delivery envelopes may remain until successfully acknowledged, deleted or expired according to the applicable delivery configuration.
  • Single-use or expiring cryptographic publication material may be deleted when consumed or expired.
  • Locally stored data remains on the user's device until removed by Privyn functionality, browser storage controls, account actions or other device-level processes.

Deletion from active systems may not instantly remove every residual copy contained in backups or limited security records where temporary retention is necessary and lawful.

08

Security

Privyn uses technical and organizational measures intended to protect information and reduce unnecessary access to communication content.

Current development measures include client-side communication encryption, device cryptographic identities, authenticated encrypted sessions and transport encryption.

No system is perfectly secure

Browser compromise, device compromise, malicious software, credential theft, implementation flaws and other threats can undermine otherwise strong cryptography.

09

Your privacy rights

Depending on where you live and the law applicable to the processing, you may have rights relating to your personal data, including rights to:

  • request access to personal data;
  • request correction of inaccurate data;
  • request deletion where applicable;
  • object to or request restriction of certain processing where applicable;
  • withdraw consent where processing depends on consent;
  • receive certain data in a portable form where applicable;
  • complain to an applicable supervisory or regulatory authority.

Because Privyn's server is not designed to possess plaintext copies of supported encrypted communications, a server-side data-access response may not contain readable message or Letter content.

10

International processing

Infrastructure and technical providers may process limited information in jurisdictions other than the user's own. Where applicable law imposes requirements on international transfers, Privyn will apply the protections required by that law.

11

Children

Privyn is not intended for people who cannot legally agree to the applicable Terms of Service. If applicable law requires parental or guardian consent, the service should not be used without that consent.

12

Changes to this Policy

This Privacy Policy may change as Privyn develops, legal requirements change or the service's processing practices change.

The “Updated” date at the top of this page will identify the current version.

13

Privacy contact

Privacy questions and requests may be sent to:

Privyn Privacy
privacy@privyn.app

PRIVYN

Development environment · dev.privyn.app

Home Terms Privacy Sign in