At a glance
ZeroChat does not sell personal data, show ads, or use cross-app tracking. One-to-one message content is end-to-end encrypted. Calls use encrypted WebRTC media.
This policy applies to the ZeroChat mobile application, this website, and related support interactions. Vault Limited operates ZeroChat and is the controller responsible for the personal data described in this policy. “ZeroChat,” “we,” and “us” refer to Vault Limited and the ZeroChat service. The service is invite-only, but an invitation does not verify a person’s identity or guarantee their conduct.
We process the minimum account, device, routing, and security data needed to register users, deliver encrypted communications, prevent abuse, and keep the service reliable. We do not use message plaintext for advertising or profiling.
Data we process
Account and access data
- Your username, a securely hashed password, when the account was created, its status, and how its invitation was used. We never store your password itself.
- An optional recovery email, whether it is verified, and short-lived information used to verify the address or reset your password.
- Sign-in security information such as a protected session identifier, IP address, app or browser information, sign-in and last-active times, expiry, and why a session ended.
Device and encryption data
- Device identifier, device name, platform, app version, locale, registration and last-seen times, and device revocation state.
- Push-notification tokens and delivery status. Push tokens are used to wake the app and deliver call or message notifications; they are not used for advertising.
- Public encryption keys used to start end-to-end encrypted conversations. Private encryption keys stay on your devices or in an encrypted backup that ZeroChat cannot read.
Communication and service data
- Encrypted messages waiting for delivery. Depending on what you send, a message can contain text, photos, videos, voice messages, files, precise location, or a contact card. We also process the sender, recipient, message identifier, time, and delivery or read status needed to deliver it.
- Encrypted attachments and limited delivery details such as file size, file type, and expiry.
- Call connection information, including the participants and devices, call identifier, timing, whether the call connected or ended, and any network relay used. ZeroChat does not record call audio or video.
- Short-lived presence, typing, notification, and call-capability state. Your in-app settings control whether supported presence, typing, and read-receipt signals are sent.
- If you enable backup, the encrypted backup and basic details such as its size, format, and update time. Restoring it requires recovery material held by you.
Support and website data
When you email support, we receive the address you use, message contents, attachments, and ordinary email delivery details. When you visit this website, hosting and network-security systems process standard connection information such as IP address, browser details, requested page, and time. This site does not use advertising or cross-site analytics trackers.
Crash diagnostics
When crash reporting is enabled in a staging or released iOS build, a fatal app crash may send a limited technical report to our self-hosted crash service. It can include the app and build version, iOS version, device model, and where the app stopped working. The service receives a connection IP while accepting the report, but it is configured not to retain the full address.
Crash reports are not linked to a ZeroChat account and do not include message or attachment content, user identity, application logs, navigation breadcrumbs, screenshots, screen structure, network activity, analytics, or performance monitoring. We use them only to identify and fix reliability problems.
Encrypted communications
ZeroChat encrypts one-to-one message content on the sender’s device for each recipient device. Our servers route and temporarily store the encrypted content, but do not have the encryption keys needed to read it. Notifications contain only the limited information needed to wake the app or route a call or message, not message text.
Voice and video calls are encrypted while they travel. A relay may see network addresses, timing, connection information, and encrypted traffic, but not call audio or video. ZeroChat uses only the limited information needed to connect the correct devices.
End-to-end encryption does not prevent a participant from saving, forwarding, or reporting content they can already see. A selected message excerpt is disclosed to our moderation system only when the reporting user explicitly chooses to include it, as described below.
How we use data
We use the data described above to:
- create and authenticate invite-only accounts;
- deliver encrypted messages, attachments, calls, and notifications;
- sync authorized devices and provide optional encrypted backups;
- provide recovery-email and password-reset functions;
- apply block settings and investigate user-submitted safety reports;
- protect users and the service from fraud, abuse, and unauthorized access;
- diagnose failures, maintain availability, and improve reliability; and
- comply with law and enforce our Terms of Service.
Depending on where you live, these activities rely on performing our agreement with you, our legitimate interests in operating and securing the service, your choices or consent for optional features, and legal obligations.
Blocking and safety reports
Blocking
When you block someone, the service enforces the block between both accounts. It stops new direct messages, notification wakes, typing and presence delivery, and call invitations between you. Your block list is visible only to your account. We do not tell the other person that they were blocked.
Reporting
A report contains the report category, the reported account, your account, time and status, and any optional comment you provide. For a message report, ZeroChat also receives the selected message’s identifier so it can confirm that the message was sent to you.
Message text is not included by default. If you explicitly turn on the option to include the selected message, only that readable text excerpt is sent for moderation. Attachments, encryption keys, encrypted message data, and the rest of the conversation are not included.
Only authorized moderators can review reports, record a decision, or restrict an account. Report data is used for up to 180 days to investigate abuse, document action, and handle repeat or disputed reports, then removed through scheduled cleanup.
When data is shared
We do not sell your data. We disclose limited data only as needed to operate the service, respond to your requests, protect people, or meet legal requirements. Recipients include:
- Infrastructure providers that supply hosting, data storage, networking, monitoring, website delivery, and security services.
- Apple Push Notification service for app wakes, message notifications, and call invitations. Notifications contain only what is needed for delivery and the behavior you selected—not message text.
- Email-delivery providers for recovery-email verification and password-reset messages. They process the recovery email, delivery details, and the secure link sent to that address.
- Call-relay providers when a direct connection is not available. They can process IP addresses, connection details, and encrypted traffic, but not call audio or video.
- Support and legal recipients when you contact us, ask us to act, or when disclosure is reasonably necessary to comply with law, prevent harm, investigate abuse, or protect rights.
Providers may process data in countries other than yours. We use contractual, access-control, and security measures appropriate to the service and applicable law.
How long data is kept
Retention depends on the data’s purpose. We delete or de-identify data when it is no longer needed, subject to security, legal, and reliable disaster-recovery requirements.
- Account data: kept while your account is active, then handled through the deletion process below.
- Sessions: sign-in sessions normally expire after 90 days and may end earlier. Related security information remains until routine cleanup or account deletion.
- Message delivery and attachments: encrypted messages waiting for delivery and encrypted attachments are generally removed after approximately seven days. Recipient devices may keep their own copies longer.
- Encrypted backups: kept until replaced, removed, or the account is deleted.
- Presence and call state: most is short-lived; online presence expires within minutes, last-seen state is limited to 30 days, and temporary call connection information is removed after the call or about two hours of inactivity.
- Safety reports: retained for up to 180 days.
- Crash reports: retained for no more than 30 days and accessible only to authorized operators.
- Service logs and backups: access is restricted, and copies are kept only as long as needed for security and recovery. Backup copies are not used to restore a deleted account.
Account deletion
To permanently delete your account, sign in and open Settings → Delete My Account. Enter your current password and confirm the irreversible action. Account deletion is not offered on the sign-in screen.
When ZeroChat accepts the request, sign-in and account access end immediately. We remove the active account, sessions, devices, notification and recovery information, public encryption setup, messages waiting for delivery, and access to encrypted attachments and backups. Remaining encrypted files and temporary service copies are removed in the background, with a 24-hour service target. If it takes longer, the account remains deleted and cleanup continues until it finishes.
Messages or files already received by another person can remain on that person’s device or in their independently encrypted backup. A permanent reservation of the deleted username prevents someone else from registering it. We keep a detailed deletion confirmation for at least 30 days after cleanup. After that, we keep only a permanent record that deletion finished. It contains no username, email, account identifier, file path, or encryption key and cannot restore the account. Backup copies age out on their normal schedule and are never used to reactivate a deleted account.
Signing out is different: it removes the signed-in account’s local data from that device, but does not delete the account or its optional encrypted backup.
Your choices and rights
You can:
- change supported privacy and notification preferences in Settings;
- block or report another account from the relevant profile or message;
- sign out to clear account data from the current device;
- delete your account permanently in Settings; and
- contact us to ask about access, correction, deletion, objection, restriction, or portability rights available where you live.
We may need to verify that a request relates to your account. We will not ask you to send your password, recovery code, encryption keys, or a full sign-in token by email.
Security
We use end-to-end encryption for one-to-one messages, encrypted call transport, TLS for service connections, hashed passwords and session credentials, scoped administrative access, rate limits, and monitoring designed to avoid message plaintext and secret values. No system can guarantee absolute security, so keep your password and recovery material private and keep your device software current.
Children
ZeroChat is not directed to children who cannot lawfully consent to use an online communication service in their country. If you believe a child has provided personal data without the authorization required by local law, contact us so we can investigate.
Changes to this policy
We may update this policy when the service, providers, or legal requirements change. We will post the revised policy here. For a material change, we will provide an additional in-app notice when appropriate.
Contact
For privacy questions or requests, email us at info@vaultglobal.tech. Please do not include your password, recovery code, encryption keys, or full sign-in token.