Privacy Policy

Last updated: September 2026

1. Overview

VoidSend is a zero-knowledge, end-to-end encrypted messaging platform. We are committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights regarding that data.

Our core principle: We cannot read your messages. All message content is encrypted on your device before it ever reaches our servers. We do not hold the keys to decrypt your communications.

2. Data We Collect

2.1 Account Information

  • Username (synonym): A public identifier you choose during registration (3-24 alphanumeric characters).
  • Wallet address: An Ethereum address derived from your passkey. Used for optional in-app payments.
  • Public encryption keys: Your X25519 and Kyber-768 public keys, used by others to encrypt messages to you.

2.2 Message Metadata

  • Sender and recipient: We store which usernames exchanged messages to enable delivery.
  • Timestamps: When messages were sent.
  • Encrypted payload size: The size of encrypted message data.
  • Group and story activity: Which groups you belong to and which stories you have viewed, so we can deliver them.

We do NOT store: Message content in plaintext, decryption keys, location data, contact lists from your phone, or any analytics/tracking data. Stored account data does not include IP addresses.

2.3 Device Permissions

  • Camera: Used for video calls. Camera access is only activated when you initiate or accept a video call. No images or video are recorded or stored on our servers.
  • Microphone: Used for voice calls and voice note recording. Audio is encrypted end-to-end; we cannot access it.
  • Push notification tokens: If you enable push notifications on the mobile app, we store a push notification token from Apple, Google, Expo, or your browser's push service to deliver message and call notifications. This token is device-specific and does not contain personal information.

3. Encryption

All messages are encrypted end-to-end using:

  • AES-256-GCM for symmetric encryption of message content.
  • X25519 + ML-KEM-768 (Kyber) for hybrid post-quantum key exchange.
  • ML-DSA-65 for post-quantum message authentication signatures.
  • HKDF-SHA256 for key derivation.

Your private encryption keys are derived from your passkey. They never leave your device and are never transmitted to our servers.

4. How We Use Your Data

  • To deliver encrypted messages between users.
  • To authenticate your identity via passkeys (automated agents authenticate with wallet signatures).
  • To send push notifications for incoming messages and calls (if enabled).
  • To facilitate optional in-app cryptocurrency payments between users.

We do not sell, rent, or share your data with third parties. We do not serve advertisements. We do not use analytics or tracking services.

5. Data Retention

  • Messages: Encrypted messages are stored on our servers for up to 30 days, or until deleted by the sender or recipient, whichever comes first. Disappearing messages are automatically deleted after the configured timer expires.
  • Account data: Your username and public keys are retained while your account is active.
  • Encrypted files: Encrypted file attachments are stored in cloud storage and deleted when the associated message is deleted or expires.

6. Third-Party Services

  • Push notification services: Apple Push Notification service, Google Firebase Cloud Messaging, Expo, and browser push services deliver notifications. They receive your device push token but not message content.
  • Cloud storage (AWS S3): Encrypted file attachments are stored in cloud object storage. Files are encrypted before upload; the storage provider cannot read their contents.

7. Your Rights

  • Delete your messages: You can delete individual messages or entire conversations at any time.
  • Delete your account: You can delete your account from Settings in the app.
  • Export your data: Your messages are encrypted with keys only you hold. You can decrypt and export them at any time from the app.
  • Disable notifications: You can revoke push notification permissions at any time through your device settings.

8. Children's Privacy

VoidSend is not intended for use by anyone under the age of 13. We do not knowingly collect personal information from children under 13.

9. Changes to This Policy

We may update this privacy policy from time to time. We will notify users of significant changes through the app or website. Continued use of VoidSend after changes constitutes acceptance of the updated policy.

10. Contact

If you have questions about this privacy policy or your data, please contact us at privacy@voidsend.xyz