Trust
Transparency
Last updated 18 August 2026. The useful question is not what we promise but what we could be forced to produce. This page answers that one first.
Everything we hold
- Your conversations
- Held, but encrypted with a key derived from your password. We can see that a row exists and how large it is. We cannot read what is in it, and neither can anyone who compels us to produce it.
- Your account
- A username, a password hash, and the plan you are on. No email address, no phone number, no name — none of them are asked for, so none of them can be handed over.
- Your payments
- If you subscribed: the plan, the period, the status and an opaque customer reference. Card details are entered on the payment provider's own page and never reach us at all.
- Operational logs
- The ordinary records a server keeps to stay up and to stop abuse. They are short-lived and are not joined to conversation content, which is encrypted regardless.
How we respond to legal requests
We require valid legal process appropriate to the jurisdiction making the request. A request that is over-broad, or that asks for accounts it has not identified, is pushed back on rather than answered.
Where the law permits it, the affected user is notified before anything is produced, so that the request can be challenged by the person it is actually about.
We produce only what we hold, and what we hold about conversations is ciphertext. That is not an act of defiance; it is arithmetic about where the key lives.
Why there is no request table yet
Most transparency reports open with a count of government and law-enforcement demands. This page does not, because a published count is a statement of fact about an inbox, and stating it is the operator's job rather than a design decision that can be baked into a page.
When there are figures to publish, they will appear here with the period they cover. Until then, read the absence of a table as an absence of a table — not as a claim in either direction.
What we do not do, and cannot start doing quietly
We do not sell or share personal information, and there is no aggregate-statistics business behind the product — the one that existed was removed rather than paused, which is documented in full on the do-not-sell page.
Conversations are not used to train models. There is no advertising on the site, so there is no profile worth building, and the Global Privacy Control signal is honoured server-side when a browser sends it.
Every third party that can touch data on our behalf is listed publicly. If that list changes, the page changes with it.
Reporting and enquiries
Legal notices, takedown requests and data-protection enquiries: [email protected]. Security vulnerabilities: [email protected], and please leave room to fix a problem before it is disclosed.
The detail sits in the privacy policy, the data-sale page, the subprocessor list and the safety page.