Privacy Policy

Last updated: 2026-08-11

What We Collect

  • A device-generated identifier and an anonymous authentication ID. We do not collect your phone number, email address, or real name to create an account.
  • A display name you choose, and can change.
  • The birth year you enter to confirm you meet the app's minimum age.
  • The encrypted form of messages you send, and the groups and connections you are part of. We cannot read the content of your messages — see How It's Stored below.
  • Cryptographic public keys your device generates automatically when you first sign in, stored in our cloud so that other users' devices can establish encrypted sessions with you. Your private keys never leave your device.
  • Standard technical data needed to operate the service, such as timestamps and error logs, through our cloud-based backend infrastructure.
  • Crash reports and a small set of anonymous usage events, described fully in Crash Reports and Analytics below.

What We Don't Do

  • We don't sell your data.
  • We don't run personalised or behavioural advertising, and we don't send any account data to ad networks for targeting purposes.
  • We don't read your conversations to target ads at you — or for any other purpose. We cannot: your messages are end-to-end encrypted.
  • We don't require contacts, a phone number, or an email address to use the app.

How It's Stored

Data is stored in cloud-based databases, encrypted in transit and at rest using industry-standard encryption.

Text messages are end-to-end encrypted. When you send a message, it is encrypted on your device before it is transmitted, using keys that only you and the other members of your group hold. VOPE receives and stores the encrypted data but cannot read what it says. The same is true for our infrastructure providers.

Photos you send in a chat are also encrypted on your device before they are uploaded, using a key held only by the members of that chat. Someone who obtained the stored file without being a member of the chat would get unreadable data.

Your Encryption Keys

When you first sign in, the app generates a set of cryptographic keys on your device and stores them in your device's secure hardware storage — the Keychain on iOS, the Keystore on Android. Your private keys never leave your device and are never sent to us.

Your public keys — the part of your key pair that other users' devices need to start encrypted sessions with you — are stored in our cloud. Public keys are not secret: they are designed to be shared.

You can back up your private keys using the Key Backup feature in Settings. A backup is protected by a passphrase you choose. We never see your passphrase or your private key material. If you lose your device without a backup, you cannot recover your keys. Existing contacts will need to re-establish encrypted sessions with your new device, and you will not be able to read messages that were encrypted to your old keys.

Who Can See What

Only members of a group can read that group's messages, enforced by both server-side security rules and end-to-end encryption. Even VOPE cannot read the content of your messages — only the members of your group hold the keys needed to do so.

Friend request and connection metadata is visible only to the two people involved in that request.

Crash Reports and Analytics

We use cloud-based tools to understand whether the app is working and being used, and we have deliberately kept them apart from anything you say to another person.

If the app crashes or hits an unexpected error, we receive a technical crash report: what went wrong, a stack trace, a short label for which part of the app was running, and your device model, operating system, and app version. We never see your messages, your photos, or your display name in a crash report, because none of those are ever included in what gets sent, by design in how the app is built rather than by a filter applied afterwards.

Separately, we collect a small, fixed set of anonymous usage events, such as a message being sent, a chat being opened, a group being created or joined, or a security feature being turned on. Every one of these events is stripped down to a yes or no, or a short label like "PIN" or "biometric", before it leaves your device. There is no free-text field anywhere in this system, so there is no way for message content, a display name, or a join code to end up inside it, even by mistake.

We also record two broad traits about your account: an age bracket (such as "25–34"), computed from the birth year you enter to confirm your eligibility, and which language VOPE's interface is showing you. Neither is your exact birth date, and neither is tied to your messages or your identity beyond your anonymous account. We use these only to understand our userbase in aggregate — never to target ads, and never combined with your message content.

Our analytics platform also automatically attaches standard technical metadata to every event it receives: your device model, operating system, app version, and a coarse geographic location such as country or city. This location is derived momentarily from your device's network address by our service provider's infrastructure and is not stored as a precise coordinate. It is standard behaviour of the analytics platform, not something we configured beyond choosing to use it.

Analytics is switched off completely, not just limited, for any account we know is underage, including the age bracket and language traits above. It can also be switched off entirely by us at any time without an app update, and is always off while we are testing the app ourselves.

Child Safety

We take the safety of children on this platform seriously. Because messages are end-to-end encrypted, VOPE cannot read their content. We state this plainly, because honesty about what we can and cannot do matters more to us than the appearance of protections we are unable to deliver.

What we do:

  • If content is reported to us, we place a legal hold on the reported message immediately, preventing our routine deletion schedule from removing it while it is under review. Because messages are end-to-end encrypted, the preserved record is the encrypted form only — we cannot read its content ourselves.
  • If we become aware of apparent child sexual abuse material, we are legally required to report it to the relevant authorities and to preserve the related account data for the period the law requires. This overrides any deletion request you make for that specific content.
  • We may disclose relevant account and metadata to law enforcement and relevant authorities where we are required or permitted to do so.
  • We may remove content and disable accounts that breach our Terms, including permanently.
  • We keep an internal record of moderation actions we take, so that we can answer questions from regulators and demonstrate how a report was handled.

What we do not do:

  • We do not read your conversations — we cannot, because they are end-to-end encrypted.
  • We do not monitor your messages routinely or proactively scan chats.
  • We do not notify a reported user that they have been reported, because doing so could interfere with an investigation.

If you are under the app's minimum age, or we learn that an account belongs to someone under the applicable minimum age, we will disable and delete that account and its associated data promptly.

Retention and Deletion

You can delete your account from within the app. This removes your profile and your membership in groups. Messages you have already sent to groups that are still active are retained as part of those conversations, because they form part of other people's chat history rather than only your own.

You can also reset the app entirely, which erases your profile, your chats, your local encryption keys, and all other locally stored data on this device, and gives you a new blank account. This cannot be undone, and we cannot recover anything afterwards.

Photos and other media sent in a chat are automatically and permanently deleted from our storage approximately 12 months after they were sent, whether or not the account or group is still active. This runs on a fixed schedule and is not something you can opt out of or delay. Message text is not subject to this automatic deletion.

The single exception is content under legal hold, as described in Child Safety. Content that has been reported, or that we have actioned, is kept until the applicable legal retention period has passed and an authorised person has released the hold.

App Lock and Your PIN

If you turn on a PIN or biometric lock, that credential stays on your device. Your PIN is stored only as a salted, irreversible hash inside your device's secure hardware storage. It is never sent to us and we never see it.

This means we genuinely cannot help you if you forget it. We cannot unlock the app, reset your PIN, or recover anything protected by it. The only way back in is a full reset, which erases your content permanently. You are fully in control, and that includes the consequences.

Changes

We may update this Privacy Policy from time to time. Material changes will be reflected in the app.

Contact

Questions, data requests, deletion requests, or child safety concerns: team@vope.me

Child safety reports can also be made in the app by long-pressing a message and choosing to report it.