SECRETSECRET
SecurityContactPL
SECRET · Privacy Policy

Privacy Policy

Last updated: 22 August 2026

This Privacy Policy explains how the SECRET Android messaging application and its supporting infrastructure process user data during the Public Preview phase.

Design principle: SECRET does not require a phone number, legal name or uploaded address book to create a messenger identity.

1. Controller and contact

The data controller is the publisher of the SECRET application identified in Google Play. Privacy contact: developer@secretapp.pl.

2. Data processed

  • pseudonymous SECRET ID;
  • public cryptographic identity/encryption keys and signed prekeys;
  • technical authentication and anti-abuse information;
  • encrypted message/attachment packages waiting for delivery;
  • minimal routing, delivery receipt and live presence information;
  • FCM device token when push notifications are enabled;
  • transient IP/network information needed for connections, rate limiting and service protection.

Private installation keys are generated on-device and are not intended to be uploaded to the SECRET server. Local contacts, chats, attachments and settings are stored on the user's device and protected by local application security mechanisms.

3. Data not required for core messaging

  • phone number;
  • legal name;
  • email address as messenger identity;
  • automatic upload of the phone address book;
  • location data for message routing.

4. Purposes

Data is processed to authenticate device identity, establish encrypted communication, relay messages and attachments, handle delivery/read receipts and live presence, send minimal push wake-ups and protect the service from abuse.

5. Third parties

ProviderPurpose
Google Firebase Cloud MessagingPush token and a minimal technical wake-up signal indicating that a message is available; message content is not included in that notification payload.
OVHcloudHosting of the public secretapp.pl website. The hosting provider may process technical connection logs for operational and security purposes.

SECRET does not sell user data or use it for behavioural advertising.

6. Retention

  • Undelivered encrypted messages: up to 7 days.
  • Delivered messages: removed from the server delivery queue after successful delivery.
  • SECRET ID/public key registration data: while operationally required for the identity or until a valid deletion request.
  • FCM token: until replaced, invalidated or the identity is deleted.
  • Local app data: until deleted by the user, app data is cleared, or the app is uninstalled.

7. Deletion requests

Users may request deletion of server-side data associated with a SECRET identity by contacting developer@secretapp.pl and providing the SECRET ID. Additional proof of control of that identity may be requested for security reasons.

8. Security

SECRET uses end-to-end encryption, Android Keystore, encrypted local storage and cryptographic device authentication. No system can guarantee absolute security, especially on a compromised or unlocked endpoint.

9. Website

This is a static website. It uses no advertising trackers, marketing pixels or first-party analytics, and does not set marketing cookies. The hosting provider may keep technical service logs.

10. Changes

This policy may be updated when the application, server or applicable requirements change.

11. Contact

developer@secretapp.pl

© 2026 SECRET.
HomeSecurity