Legal
Privacy Policy
Last updated: 16/08/2026
1.OUR APPROACH
Vulpine is built on a simple principle: we should not be able to access your private communications, so we designed the Service so that we cannot. This Privacy Policy explains what limited data we do process, why, and what we do, and do not, do with it.
2.WHAT WE COLLECT
- Message content:
- we do not collect it. Messages are encrypted end-to-end on your device, we never see plaintext content, and we hold no decryption keys.
- Phone number:
- not required to create or use an account.
- Account identifier:
- yes, in the form of the account identifier or username associated with your account.
- Contacts list:
- we do not collect your device contacts unless you actively choose to sync them.
- Metadata:
- we process the minimum connection and routing metadata required to deliver messages between devices.
- Device and technical data:
- limited technical data such as app version, operating system type, and crash logs, used for debugging and security purposes.
- IP address:
- processed transiently for the purpose of routing your connection, and not retained beyond what is operationally necessary.
3.WHAT WE CANNOT DO
Because of our encryption architecture:
- We cannot read the content of your messages, ever, under any circumstances, including in response to a lawful request, because we do not possess the keys required to decrypt them.
- We cannot hand over message content to third parties, governments, or in the event of a data breach, because it does not exist on our servers in readable form.
- We cannot restore lost message history if you lose your device and have no backup, for the same reason.
4.WHAT WE SHARE
We do not sell, rent, or share your personal data with advertisers or data brokers. We may disclose the limited metadata described in Section 2 only:
- When legally compelled by a valid order or legal process enforceable against us, and only to the extent of data we actually possess, which excludes message content.
- With service providers strictly necessary to operate the Service, under confidentiality obligations.
- With your consent.
Where legally permitted, we will notify affected users of legal requests concerning their data.
5.DATA RETENTION
Message ciphertext is removed from our servers once it has been delivered to the recipient device. Account metadata is retained for as long as your account remains active and is deleted upon account deletion, except where retention is required by applicable law. Technical logs are retained only as long as necessary for security and debugging purposes.
6.YOUR RIGHTS
Depending on your location, you may have rights to access, correct, delete, or export your data, and to object to or restrict certain processing, including under the Swiss Federal Act on Data Protection and, where applicable, the EU General Data Protection Regulation. Because we hold minimal data and cannot access message content, requests to access or export your data will return only the metadata described in Section 2. To exercise these rights, contact [email protected].
If you are located in Switzerland, you also have the right to lodge a complaint with the Federal Data Protection and Information Commissioner. If you are located in the European Union or European Economic Area, you have the right to lodge a complaint with your local data protection authority.
7.SECURITY
We use industry-standard end-to-end encryption to protect message content. While we take reasonable measures to secure our infrastructure and the limited metadata we hold, no system is completely immune to compromise, and you are responsible for the security of your own device and credentials.
8.CHILDREN'S PRIVACY
Vulpine is not directed at children under 15. We do not knowingly collect data from children under this age. If we become aware that we have, we will delete the account and associated data to the extent our architecture allows.
9.INTERNATIONAL DATA TRANSFERS
Vulpine LLC is a Delaware, United States entity, and use of the Service may involve the transfer of limited metadata described in Section 2 to infrastructure located outside your country of residence, including the United States. Where required by applicable law, we rely on appropriate safeguards for such transfers.
10.CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. Material changes will be communicated through an in-app notice or by email, and the "last updated" date at the top of this document will reflect the most recent revision.
11.CONTACT
For privacy questions or to exercise your data rights, contact [email protected].