Privacy policy
Private by architecture, clear about metadata.
Version 1.0. Last updated 30 August 2026.
1. Controller and contact
The controller is Mateusz Sury, a sole trader registered in CEIDG, ul. Biedronki 8 lok. 2, 52-200 Wysoka, Poland, VAT ID (NIP) 8961670846, REGON 545313843. Contact: theteroles@gmail.com.
Veilcord does not require a central user account. We cannot access your vault password, private keys, or decrypted messages, calls and files.
2. Data on your device
Your profile, cryptographic identity, contacts, spaces, message history and vault data are stored on your device. Optional quick unlock uses Android Keystore and BiometricPrompt or Windows Hello and DPAPI. Veilcord never receives your biometric data.
Deleting the profile or app data deletes that local copy. Veilcord has no central archive from which it can recover your password, profile or history.
3. Communications and connection metadata
Messages, calls and files are end-to-end encrypted on participant devices. Rendezvous carries bounded connection-establishment data without storing content. When direct delivery is unavailable, the hosted message relay may hold ciphertext in a bounded RAM queue until delivery or expiry. It has no content-decryption key and stores no message history.
A direct P2P connection exposes the network addresses required to connect to the other participant. Veilcord, Cloudflare and infrastructure providers may technically process an IP address, connection time, state and traffic volume to perform the service under Article 6(1)(b) GDPR and to protect it against abuse under the legitimate interests in Article 6(1)(f) GDPR. Veilcord application origins disable application access logs.
4. Anonymous operational metrics
Veilcord may collect aggregate service-health counters with a closed set of labels: active sessions, fixed success and rejection classes, handling time, frame counts and resource use. They contain no IP address or user, device, profile, space, route or message identifier, and no content. Local Prometheus retention is at most 15 days and Veilcord metrics are not sent to an external remote-write service by default.
5. Marketing analytics
The communicator at app.veilcord.xyz does not load PostHog, Google Analytics, advertising or marketing identifiers.
The marketing website may offer optional Google Analytics 4 and PostHog measurement only after consent. Rejecting is as easy as accepting and does not affect access. Events contain no Veilcord profile, device, space, route or message identifier; the selected provider still receives connection data needed to deliver its script and event request. Google Analytics uses no persistent client storage, Google signals or ad-personalisation signals. PostHog is configured with memory-only storage, no autocapture, session recording or person profiles, and IP collection disabled. You can revoke consent through Privacy settings. Both providers remain disabled until dedicated Veilcord identifiers are configured.
6. Payments
If Relay Pass sales are activated, Stripe or NOWPayments may process a payment under their privacy terms. Veilcord sends a random grant handle, not a communicator profile, device, space, message or route identifier. The seller retains the minimum transaction, refund and complaint record needed to perform the contract and comply with tax and accounting law under Article 6(1)(b) and (c) GDPR.
If Relay Pass sales are activated, a separate random grant and professionally reviewed anonymous-token mechanism will separate relay entitlement from the payment record. That production mechanism is not enabled yet. It will not make the transaction anonymous to the payment provider or authorities entitled to obtain it by law.
7. Providers and transfers
Current providers are Cloudflare and the infrastructure operated by Mateusz Sury. Stripe, NOWPayments, Google Analytics 4 and PostHog remain disabled until their respective features are activated. Where a provider processes personal data outside the EEA, the controller uses the GDPR transfer mechanism applicable to that provider and contract, such as an adequacy decision or Standard Contractual Clauses.
8. Your rights
You may request access, correction, erasure, restriction and portability where applicable; object to processing based on legitimate interests; withdraw consent; and complain to the President of the Polish Personal Data Protection Office (UODO). Send requests to theteroles@gmail.com. Because Veilcord intentionally keeps no central identity and no identifying technical-event record, we may be unable to link a person to an anonymous event.
9. Children, automated decisions and changes
Veilcord is not directed to children under 16 and does not profile communicator users or make solely automated decisions with legal or similarly significant effects. This policy will be updated before any new data category, provider, payment method or analytics integration is activated. Material changes will be announced with their effective date.