Privacy policy

Last updated: 2026-09-30. It applies to the SecureChat app and to this website.

Summary

Who the controller is

The controller of the data processed by the SecureChat service is SecureChat. Contact for any privacy matter: soporte@securechat-app.com.

Each business you talk to is an independent controller of the data it receives on its systems (see The business you talk to).

What we cannot see

When you redeem an invitation, your phone generates a key for that conversation and encrypts it separately for you and for the business. Each message is encrypted on the device that sends it and is only decrypted at the other end (your phone or the business’s server). We only receive, store and deliver the encrypted text.

The technical details and the limits of this model are in Security.

What we do process

For the service to work, there is data we inevitably see. It is metadata, and quite a lot can be inferred from it about your relationship with each business. That is why we list all of it:

Data processed by SecureChat
DataDetails
User identifier (userId)Generated by the server when your account is created. It is not tied to your phone number or your email. If you choose a display name or a language, they are stored too.
Which businesses you talk toWhich conversations you have, with which business, their status and, if the business provided it when inviting you, its internal reference (for example, a ticket number).
WhenDate and time of creation, redemption, each message, delivery and read.
Message sizeApproximate: encryption pads each message to a multiple of 256 bytes, so we see the rounded size, not the exact one.
Encrypted messagesThe encrypted text of each message, which we cannot decrypt, so we can deliver it to your device.
Encrypted attachmentsPhotos and documents sent in a conversation, encrypted on the device that sends them. We don’t see their name, type or content (they travel inside the encrypted message). We do see the size of the encrypted file, practically the same as the original, when it is uploaded and downloaded, in which conversation and who sends it.
Your device’s public keyWe need it so the business can encrypt for you. It cannot be used to decrypt anything.
IP addressWe use it for rate limits and abuse protection, and it appears in the server’s technical logs.
Device detailsPlatform (iOS or Android), model and app version, which arrive with requests and with the error reports the app sends (without message content).
Push notification tokenThe identifier Apple or Google assigns so we can send notifications to that device.

What we use it for

The legal basis is the performance of the service you request by installing the app and redeeming an invitation, and our legitimate interest in keeping it secure.

The business you talk to

The business that invites you is the other end of the encryption: it receives your decrypted messages and attachments on its own systems (its CRM, its helpdesk…), as well as your userId, the dates and the reference it attached to the invitation. From then on it is an independent controller of that data, which is governed by its own privacy policy. If the business sends the messages to another provider, that provider may see them.

We verify that businesses legally exist and that they control their domain and the WhatsApp number they invite from, but we don’t control what they do with your messages once decrypted.

How long we keep it

Retention periods
DataPeriod
Encrypted messagesIndefinitely while your account exists: conversations don’t expire. They are deleted when you delete your account.
Encrypted attachmentsSame as messages: while your account exists, and they are deleted when you delete it. An uploaded attachment that is never sent in a message is deleted automatically after 24 hours.
Account, public key and push tokenUntil you delete your account.
ConversationsWhen you delete your account they are closed and unlinked from your userId. A record without your identifier remains showing that the business had that conversation (dates and its internal reference).
Log of deliveries to the business (webhooks)30 days. It includes the event sent, with the encrypted messages.
App error reports90 days.
Server technical logs (including IP)Between 30 and 90 days.
Rate-limit countersMinutes or hours.

How to delete your account: Delete account. When you do, we notify each business you were talking to so it can act on its copy.

Providers and transfers

These providers process data on our behalf and only to provide the service.

No analytics or advertising

The app and this website include no third-party analytics, tracking pixels, advertising or tracking cookies. This website does not use JavaScript. Its only cookie is sc_lang, a technical cookie that remembers for one year the language you choose in the language selector; it does not identify you and cannot be used to track you. If you haven’t chosen a language, we use the language preference your browser sends to show you the home page in your language, without storing it.

To know how many invitations turn into conversations, we count events such as “link opened” or “invitation redeemed” on the server: they are counters aggregated per business and per day, with no user identifier, IP, content or cookies. We don’t sell or share data with third parties for commercial purposes.

Business portal users

If you work at a business that uses the portal (/business), we process your email address, a hashed version of your password, your two-step verification secret (encrypted), your role, sign-in dates and the IP of your requests. To verify the business, we process its legal details and the documents it provides, which are kept in private storage and are only seen by the review team.

Your rights

You can request access, rectification, erasure, restriction, objection and portability by emailing soporte@securechat-app.com. The fastest way to erase your data is to delete your account from the app. As we don’t ask for a phone number or email, we may need you to write to us from the app itself or tell us your userId to find your account. You can also lodge a complaint with the data protection authority in your country.

For the data each business holds, contact that business: it is an independent controller.