Privacy
Privacy Policy
This notice explains what the mysecret.chat messaging app processes, why it is needed, what encryption does and does not hide, and how you can delete your account.
1. Scope and operator
This policy covers the mysecret.chat iOS app and the messaging service at mysecret.chat. The operator and data controller is Victor Eliot, sole trader (fyzická osoba podnikající), IČO 08514127, Svahová 984/18, 360 01 Karlovy Vary, Czech Republic. Privacy contact: support@mysecret.chat.
The iOS app is a focused messenger. It excludes cryptocurrency wallets, blockchain balances, transaction signing and crypto-payment functionality. It also does not provide random stranger matching, a public user directory, or voice/video calls.
2. Data we process
| Data | Purpose and handling |
|---|---|
| Account and identity | Username, optional display name and avatar, public encryption key, encrypted identity-recovery material, account and session timestamps. The account password is transmitted over TLS during registration/login and processed for authentication; the service stores a salted password verifier rather than the plaintext password. |
| Routing metadata | Sender and recipient account IDs, group membership and roles, message IDs and types, timestamps, delivery/read state, invite state, and ciphertext needed to route and synchronize conversations. |
| Message content | Text, files, photos, voice messages, reactions and other payloads are encrypted and signed on the sender's device before relay. When a recipient is offline, the service may hold an encrypted delivery envelope until delivery. The current normal offline queue has size limits but no promised fixed time expiry. |
| Notifications | An APNs device token, platform, token hash and update time are associated with the account to deliver notifications. The iOS push alert is generic and does not contain message text or the sender's name. |
| Network and security | The server, reverse proxy, hosting provider and network services necessarily process connection information, including an IP address and connection time. The application uses the IP address forwarded by its trusted reverse proxy for in-memory rate limiting; it does not add that address to the durable account or message store. Cloudflare, the Hostinger network and VPS, Traefik/container logging, and firewalls may nevertheless process or log IP addresses, request paths, connection times and security events. We do not claim that IP addresses are invisible or never logged. |
| Diagnostics | First-party error telemetry can include an error message, stack trace, app path and user agent. The relay keeps no more than the latest 500 client-error events in memory; older events are evicted and a process restart clears that buffer. Shortened error messages and Content Security Policy reports may also be written to operational container logs. Those logs use size-based rotation, so no fixed number of retention days is promised. Do not put secrets in an error report. |
The current iOS App Store release contains no advertising SDK and no cross-app tracking. It does not request address-book contacts, location, health data or payment information.
3. What encryption protects
Message and attachment content is encrypted and signed on the sender's device before it reaches the relay, and local account records are encrypted on the device. The relay routes ciphertext.
Encryption does not hide all operational metadata. It does not protect plaintext displayed on an unlocked or compromised device, screenshots, content saved by a recipient, or evidence that you deliberately include in a safety report. We do not describe the service as “zero metadata,” “unbreakable,” or independently audited.
4. Reports and moderator access
When you explicitly submit a safety report, the evidence you select is encrypted for the designated safety moderator. That moderator can decrypt and read the selected report evidence to investigate it. The ordinary message relay stores the report as ciphertext; other messages are not automatically attached.
A report record also includes the reporter and reported account IDs, category, optional group and message IDs, status, and timestamps. Do not include unrelated private information. Blocking is stored with your account and is enforced by the service for direct interactions.
6. Retention and deletion
- Account and group records remain while the account is active, unless a shorter feature-specific expiry applies.
- Encrypted offline envelopes remain until delivered or removed by queue limits, blocking, guest expiry or account deletion; no fixed normal-queue time limit is currently promised.
- Idle authenticated sessions are designed to expire after 30 days.
- Guest accounts and time-limited invite capabilities expire according to their configured timer.
- Successful account deletion removes the active account record, sessions, push registrations, invites, related queued ciphertext and memberships. Rotating application backups may contain the prior state for up to 7 days under the current deletion policy, after which they are pruned.
- The first-party client-error buffer holds no more than 500 events in memory. Operational container logs are size-rotated rather than retained for a promised fixed number of days. Cloudflare, Hostinger and Apple may keep their own network, security or delivery logs for periods determined by their current service configuration, security needs and legal requirements; we do not control or promise a fixed maximum for those provider logs.
- Local encrypted records remain on a device until deleted by the app, a feature timer, or the operating system.
Deletion cannot erase messages, files, screenshots or exports already held by another participant, or records another party must keep under applicable law.
7. Your choices
- Use a username that is not your legal name and leave the optional avatar blank.
- Control notification and microphone permission in iOS Settings.
- Use disappearing-message timers while understanding they cannot prevent screenshots or recipient copies.
- Block a user or submit a narrowly scoped safety report.
- Permanently delete your account from inside the app. Signing out or removing local data is not account deletion.
Depending on where you live, applicable law may also give you rights to access, correct, export, restrict or object to processing, or complain to a regulator (in the Czech Republic, the Office for Personal Data Protection / ÚOOÚ). To exercise those rights, email support@mysecret.chat.
See the account deletion instructions for the exact effects.
8. Contact and complaints
Operator and data controller: Victor Eliot, sole trader (IČO 08514127), Svahová 984/18, 360 01 Karlovy Vary, Czech Republic. Privacy and complaints contact: support@mysecret.chat. Do not send passwords, private keys or message content by email.
See Support for service status and safe reporting options.