Privy Privacy Policy

Last Updated: January 12, 2026
Effective Date: January 12, 2026

Introduction

Welcome to Privy. We are committed to protecting your privacy and giving you control over your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our end-to-end encrypted messaging service.

Our Core Privacy Commitment:

  • We use end-to-end encryption - we cannot read your messages
  • We collect minimal metadata - only what's essential for service delivery
  • We provide transparency - clear disclosure of what we collect and why
  • We give you control - tools to manage your data and privacy

Please read this Privacy Policy carefully. By using Privy, you agree to the collection and use of information in accordance with this policy.

Table of Contents

  1. Information We Collect
  2. How We Use Your Information
  3. Information We Cannot Access (Zero-Knowledge)
  4. How We Share Your Information
  5. Data Security
  6. Data Retention
  7. Your Privacy Rights
  8. Children's Privacy (COPPA Compliance)
  9. State-Specific Privacy Rights
  10. International Data Transfers
  11. Cookies and Tracking Technologies
  12. Changes to This Privacy Policy
  13. Contact Us

1. Information We Collect

1.1 Information You Provide Directly

Account Registration:

Profile Information:

Communications:

1.2 Information Collected Automatically

Device Information (Device Fingerprint):

For security and fraud prevention, we collect:

Purpose:

This information helps us detect and prevent fraud, spam, and abuse; identify suspicious login attempts; enforce rate limits and security policies; and comply with legal requirements.

Session Information:

Message Metadata:

Note: We do NOT collect:

1.3 Information from Third Parties

Email Service Providers:

Infrastructure Providers:

2. How We Use Your Information

2.1 Service Delivery

2.2 Security and Fraud Prevention

2.3 Service Improvement

2.4 Legal Compliance

2.5 Communications

We do NOT use your information for:

  • ❌ Advertising or marketing
  • ❌ Selling to third parties
  • ❌ Profiling or behavioral tracking
  • ❌ Training AI models
  • ❌ Creating shadow profiles

3. Information We Cannot Access (Zero-Knowledge)

Due to our end-to-end encryption implementation, we CANNOT access:

  • Message Content: All messages are encrypted on your device and can only be decrypted by the recipient
  • Shared Media: Photos, videos, and files are encrypted end-to-end
  • Contact Lists: Your contacts are stored locally on your device
  • Group Chat Content: Group conversations (when implemented) will also be encrypted
  • Encryption Keys: Your private keys never leave your devices

Important Implications:

4. How We Share Your Information

4.1 We Do Not Sell Your Data

We do NOT sell, rent, or trade your personal information to third parties for monetary gain or any other consideration.

4.2 Service Providers

We share limited information with trusted service providers who assist in operating our service:

Infrastructure Providers:

Email Service Providers:

4.3 Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities:

Law Enforcement Requests:

Transparency: We may publish transparency reports detailing law enforcement requests we receive.

4.4 Business Transfers

In the event of a merger, acquisition, or sale of assets:

4.5 Protection of Rights

We may disclose information to:

5. Data Security

5.1 Encryption

End-to-End Encryption:

Transport Layer Security:

At-Rest Encryption:

5.2 Security Measures

Access Controls:

Infrastructure Security:

Data Protection:

5.3 Security Limitations

No system is 100% secure.

While we implement industry best practices, we cannot guarantee absolute security against advanced persistent threats, zero-day vulnerabilities, physical server compromise, insider threats, or user device compromise.

Your Responsibility:

6. Data Retention

6.1 Account Data

Active Accounts:

Deleted Accounts:

6.2 Message Data

Encrypted Messages:

Message Metadata:

6.3 Session Data

6.4 Log Data

6.5 Backup Data

7. Your Privacy Rights

7.1 Access and Portability

Right to Access:

Right to Data Portability:

How to Exercise: Contact privacy@privyapp.org or use the data export feature in the app.

7.2 Correction and Deletion

Right to Correction:

Right to Deletion:

How to Exercise: Use account settings in the app or contact support@privyapp.org.

Limitations:

7.3 Restriction and Objection

Right to Restrict Processing:

How to Exercise: Contact privacy@privyapp.org with specific restrictions you'd like to implement.

7.4 Withdraw Consent

You may withdraw consent at any time by:

Note: Withdrawing consent may limit or prevent use of certain features.

8. Children's Privacy (COPPA Compliance)

8.1 Age Requirement

Privy is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13 years of age.

8.2 Parental Consent

If you are between 13 and 18 years old (or the age of majority in your jurisdiction), you may only use Privy with the permission and supervision of a parent or legal guardian.

8.3 If We Learn We Have Collected Data from Children Under 13

If we become aware that we have collected personal information from a child under 13 without parental consent:

8.4 Parental Rights

Parents or legal guardians may:

To exercise these rights, contact: privacy@privyapp.org with subject line "COPPA Request"

9. State-Specific Privacy Rights

9.1 California Residents (CCPA/CPRA)

California residents have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

Right to Know:

Right to Delete:

Right to Opt-Out:

Right to Correct:

Right to Limit Use of Sensitive Personal Information:

Right to Non-Discrimination:

Authorized Agents:

How to Exercise California Rights:

Response Time: We will respond within 45 days (may extend up to 90 days with notice).

9.2 Virginia, Colorado, Connecticut, Utah Residents

If you are a resident of Virginia, Colorado, Connecticut, or Utah, you have rights under your state's privacy laws:

How to Exercise: Contact privacy@privyapp.org with your state's name in the subject line.

9.3 Nevada Residents

Nevada residents may opt out of the sale of personal information. We do not sell your personal information.

10. International Data Transfers

10.1 Data Location

Our servers are located in the United States. By using Privy, you consent to the transfer and processing of your data in the United States.

10.2 European Economic Area (EEA) Users

If you are in the EEA, please note:

Legal Basis for Processing:

GDPR Rights:

Data Protection Officer Contact: dpo@privyapp.org

10.3 UK Users

UK users have rights under the UK GDPR similar to EEA rights listed above.

10.4 Other International Users

If you are outside the U.S., your personal information may be transferred to and processed in the United States. We will take appropriate steps to ensure your data is protected in accordance with this Privacy Policy.

11. Cookies and Tracking Technologies

11.1 What We Use

Session Cookies:

Authentication Tokens:

Local Storage:

11.2 What We Do NOT Use

We do NOT use:

  • ❌ Third-party analytics (Google Analytics, etc.)
  • ❌ Advertising cookies or trackers
  • ❌ Social media pixels
  • ❌ Cross-site tracking
  • ❌ Behavioral profiling cookies

11.3 Do Not Track (DNT)

We respect browser Do Not Track signals and do not track users across websites.

11.4 Your Control

You can control cookies by:

Note: Disabling essential cookies may prevent you from using the service.

12. Changes to This Privacy Policy

12.1 Updates

We may update this Privacy Policy from time to time to reflect:

12.2 Notification

When we make changes:

12.3 Your Choices

If you disagree with the updated Privacy Policy:

12.4 Review

We recommend reviewing this Privacy Policy periodically to stay informed about how we protect your information.

13. Contact Us

13.1 Privacy Questions

For questions, concerns, or requests regarding this Privacy Policy or our data practices:

Email: privacy@privyapp.org
Subject Line: Include "Privacy Inquiry" or specific request type
Response Time: We aim to respond within 5 business days

13.2 Data Protection Officer (DPO)

For GDPR-related inquiries:

Email: dpo@privyapp.org

13.3 Data Rights Requests

To exercise your privacy rights (access, deletion, correction, etc.):

Email: privacy@privyapp.org
Subject Line: "[Your State/Country] Privacy Request"
Include:

13.4 Security Issues

To report security vulnerabilities:

Email: security@privyapp.org

Important: Do not publicly disclose security issues. We will respond promptly and work with you to address the issue.

13.5 Mailing Address

Privy
123 Privacy Lane, Suite 500
San Francisco, CA 94102
United States


14. Additional Information

14.1 Third-Party Links

Our service may contain links to third-party websites or services. This Privacy Policy does not apply to those third-party sites. We recommend reviewing their privacy policies before providing any personal information.

14.2 Data Breach Notification

In the event of a data breach that affects your personal information:

Note: Due to end-to-end encryption, message content cannot be exposed in a breach.

14.3 User Responsibility

You are responsible for:

We are NOT responsible for:

14.4 Open Source

Privy uses open-source components. Our use of these components does not affect your privacy rights under this policy.


15. Legal Compliance Summary

This Privacy Policy is designed to comply with:

Federal Laws:

State Laws:

International Laws:


Acknowledgment and Consent

By using Privy, you acknowledge that:

  1. You have read and understood this Privacy Policy
  2. You consent to the collection, use, and disclosure of your information as described
  3. You understand the limitations of our zero-knowledge architecture
  4. You are responsible for protecting your encryption keys and device security
  5. You are at least 13 years old (or have parental consent)
  6. You accept the transfer of your data to the United States
  7. You agree to receive essential service communications

If you do not agree to this Privacy Policy, you must not use Privy.


Last Updated: January 12, 2026
Version: 1.0.0

© 2026 Privy. All rights reserved.


Privacy Policy Change Log

Version Date Changes
1.0.0 January 12, 2026 Initial Privacy Policy