Legal
Privacy Policy
Drdesh is a private messenger built so that we hold as little of your data as technically possible. This policy explains exactly what our servers store, what they can never see, whom we share data with (almost no one), and the rights you have. It is written to match how the service actually works — nothing here is aspirational.
The short version
- Your messages and calls are end-to-end encrypted with the Signal protocol. We cannot read or listen to them — not our staff, not our servers, not by court order, not by design mistake we can toggle off.
- We keep no message history. The server holds an encrypted message only until your recipient's device confirms delivery, then deletes it. Undelivered messages are deleted after 30 days at the latest.
- No phone numbers, no contact-book upload, no ads, no trackers, no third-party analytics. Your email address is the only mandatory piece of personal data.
- You can delete your account — and everything we store about it — from inside the app, at any time.
What we store
To run the service, our servers keep this account data:
- Email address — your permanent account anchor. Used to sign you in (one-time codes), to move your account to a new phone, and to send security notices (for example, a warning whenever your account is registered on a new device). Never shown to other users.
- Profile — your @username, display name, about text, and profile photo. Profile photos (and group photos) are the one kind of media that is not end-to-end encrypted, so they can be shown to your connections and restored when you change phones.
- Your connections — which accounts you have sent requests to, accepted, declined, blocked, or marked as favorites. This graph exists for two reasons only: the server must enforce that nobody you haven't accepted can reach you (our consent gate is enforced server-side), and it lets you get your people back on a new phone. We are honest about this being sensitive social metadata: it never includes message content, and requests you decline are deleted, not archived.
- Group membership — the groups you are in, their names, photos, member lists, and admin roles. Group message content is end-to-end encrypted like everything else.
- Messages in transit (ciphertext only) — while a message is on its way, the server holds the encrypted blob, sender and recipient, and a timestamp. The row is deleted the moment the recipient's device acknowledges delivery; if a device never comes online, it is deleted after 30 days. There is no message-history database — by architecture, not policy.
- Encrypted media in transit — files, images, video, and voice notes are encrypted on your device before upload; the storage service only ever sees an opaque blob, and the decryption key travels inside the end-to-end encrypted message. Encrypted media blobs are automatically deleted from storage after 30 days.
- Public key material — the Signal-protocol public keys your device publishes so others can start encrypted sessions with you. Private keys never leave your device.
- Push tokens — the device tokens Apple and Google require for notifications. Our push payloads carry no message content at all — they only wake your app, which then fetches and decrypts locally.
- Registration-lock PIN (hash only) — if you enable the optional registration lock, we store a slow cryptographic hash (argon2id) of your PIN, never the PIN itself. There is no way for us to read or reset it.
- Reports you submit — if you report a conversation, your device forwards the reported messages (up to a small, bounded number) as evidence. This is the only path by which any message content can ever reach us, it is always initiated by a participant of that conversation, and reviewers see it labeled as reporter-forwarded material. See "Abuse reports" below.
- Hashed ban records — see "When you delete your account" below.
What we never store
- Message or call content, or any history of it. Your conversation history lives only on your device, in an encrypted local database.
- Call logs. Who called whom is not recorded server-side; call signaling is relayed and forgotten.
- Your private encryption keys.
- Phone numbers — there is no phone-number field anywhere in the system.
- Your address book. Drdesh never asks for, reads, or uploads your contacts; people find each other by @username or in-person QR code.
- Location data, advertising identifiers, browsing data, or any analytics profile. There are no third-party tracking or analytics SDKs in the apps, and no ads.
What we can observe anyway (metadata honesty)
Running a delivery service means some metadata necessarily passes through us: the server knows when your device is online, which accounts exchange (encrypted) traffic and roughly how much, and the sizes and timing of encrypted media transfers. We minimize this — queue rows die on delivery, typing and presence signals are relayed and never stored, and presence is only visible to connections you have accepted — but we would rather tell you it exists than pretend otherwise.
Who can see what
- Other users — your profile (@username, display name, photo, about) is visible to people who look up your exact @username or scan your QR code. Your online/last-seen status and typing indicators are visible only to connections you have accepted, and you control read receipts in Settings.
- Our staff — administrators can never read messages; no code path exists for it. The admin panel sees account metadata (profiles, ban state, aggregate charts) and user-submitted reports only, and every admin action is recorded in an append-only audit log.
Service providers
We use a small number of infrastructure providers, each of which sees only what its job requires:
- Email delivery (Amazon SES) — sees your email address and our security/sign-in notices to you. Never message data.
- Push delivery (Apple APNs, Google FCM) — see your device's push token and content-free wake-up pushes.
- Media storage (Cloudflare R2) — sees encrypted blobs it cannot decrypt, plus profile/group photos.
- Server hosting — our servers run on rented infrastructure; everything above about what servers do and don't hold applies there.
We do not sell, rent, or share your data with anyone else. We have no advertising or data partnerships.
Abuse reports
End-to-end encryption means we cannot moderate content we cannot see. Instead, when you report a conversation, your own device forwards the offending messages (a bounded, recent selection — never your whole history, never media files themselves) to our moderation queue, together with the reported account's @username. Report evidence is retained while the report is being handled and for as long as needed to enforce bans, and is never used for anything except trust & safety. Because evidence is forwarded by one participant, moderators treat it as a claim to be assessed, not as a verified transcript.
Retention
- Queued encrypted messages: deleted on delivery, or after 30 days if never delivered.
- Encrypted media blobs: deleted from storage after 30 days.
- Account data (profile, connections, groups, keys, push tokens): kept while your account exists; deleted when you delete it.
- Security logs and metrics: aggregate and content-free.
When you delete your account
Settings → Account → Delete account permanently removes your account row, devices, key material, connections, group memberships, queued messages, push tokens, and profile photo. This is immediate and irreversible — we cannot restore a deleted account, and your message history (which only ever existed on your devices) is not ours to return.
One thing survives deletion, and we want to be plain about it: if an account was banned for abuse, we keep a one-way cryptographic hash of its email address so the ban stays effective. The hash cannot be reversed into your address and is used for nothing except preventing banned users from re-registering. Evidence attached to abuse reports may also be retained as described above.
Your rights
If you are in the EU/EEA or UK, the GDPR (and equivalents) grant you rights of access, rectification, erasure, restriction, portability, and objection. Drdesh is built so you can exercise the important ones yourself, instantly, in the app:
- Erasure — in-app account deletion (above), no support ticket required.
- Rectification — edit your profile and email address in Settings at any time.
- Access — everything we hold about you is listed in "What we store"; for a copy of your account data, contact us below.
You also have the right to complain to your local data-protection authority. For anything you cannot do in-app, email us — we answer identity-verified requests within 30 days.
Children
Drdesh is not for children under 13 (or the higher minimum age your country sets for consenting to data processing — 16 in parts of the EU). We do not knowingly collect data from children below that age; if you believe a child is using Drdesh, contact us and we will delete the account.
Changes to this policy
If we change this policy in any meaningful way, we will notify you in the app before the change takes effect and keep prior versions available on request. The "Last updated" date above always reflects the current version.
Contact
Data controller: the Drdesh operator (full legal entity details will
be listed here at launch).
Privacy contact: privacy@drdesh.app