ZKRYPT is designed so that we cannot read your messages — ever. End-to-end encryption means only you and your contact hold the keys.
ZKRYPT collects the absolute minimum required to operate:
DE2B8674). This is not linked to your name, email, or phone number.All messages are end-to-end encrypted using:
Your private key never leaves your device. It is stored in the app's local storage and is never transmitted to our servers.
Messages are automatically deleted from our servers after 12 hours. Once deleted server-side, they cannot be recovered. Messages are also immediately removed from the server when you delete them manually.
Your identity keys, contacts, and PIN are stored exclusively in your device's local storage. We have no access to this data. If you uninstall the app or reset your identity, this data is permanently erased from your device.
ZKRYPT uses Supabase as its backend infrastructure to relay encrypted messages between users. Supabase only handles encrypted data — it cannot read message content. Supabase's privacy policy is available at supabase.com/privacy.
We do not use Google Analytics, Firebase, Meta Pixel, or any advertising or tracking SDKs.
ZKRYPT is not directed at children under the age of 13. We do not knowingly collect any personal information from children.
Because we do not collect personally identifiable information, there is no personal data to access, correct, or delete on our end. You can erase all local data at any time by using Settings → Reset Identity inside the app.
If we make material changes to this privacy policy, we will update the effective date above. Continued use of the app after changes constitutes acceptance of the updated policy.
Questions? Email us at: info@servicelocal.ca