Legal

Privacy Policy

Effective Date: February 18, 2026

At Secria, your privacy is our highest priority. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Secria application ("App"), including our web app, iOS app, and Android app. For the secria.me website privacy policy, please refer to our Website Privacy Policy.

1. Information We Collect

We collect minimal information necessary to provide our services effectively and securely. This may include:

1.1 Account Information

What We Collect:

  • When you register for an account, we collect your email address, name, and any other details you choose to provide (e.g., username).

Why We Collect It:

  • To create and manage your user account, facilitate secure communication, and provide customer support.

This data is never sold.

1.2 Usage Data

What We Collect:

We collect only the data you provide when logging in. This includes your account name, selected subscription plan, login timestamps, and message transmission times.

Why We Collect It:

To operate the service, maintain account functionality, and troubleshoot any issues that may arise.

Privacy Note:

By default, we do not keep permanent IP logs associated with your account. Temporary server logs may exist for abuse prevention and security purposes but are not linked to your account and are not retained long-term. We do not collect device fingerprints or background telemetry. No data is sold, tracked, or shared for marketing. All collected usage data is minimal and limited strictly to what's needed for core functionality.

1.3 Permissions, Local Storage & Third-Party SDKs

Permissions (Mobile):

On iOS and Android, the Secria App may request the following device permissions:

  • Network Access: Required to send and receive encrypted emails.
  • Push Notifications: To alert you of new messages. If you enable push notifications, we store a device token and basic device information (device model, operating system, and app version) to deliver notifications. On iOS, notifications are delivered via Apple Push Notification service (APNs). On Android, notifications are delivered via Firebase Cloud Messaging (FCM). You can disable notifications at any time in your device settings, and you can unregister your device from within the app.
  • File/Photo Access: Only when you choose to attach files to an email. We do not scan or access your files otherwise.

Permissions (Web):

The Secria web app runs in your browser and does not request any special device permissions beyond standard network access. No browser extensions or plugins are required.

Local Storage:

Your encryption keys and decrypted message content are stored locally on your device (or in your browser's local storage for the web app) and are never transmitted to our servers in unencrypted form. On mobile, uninstalling the App removes locally stored data. On web, clearing your browser data will remove locally stored keys.

Third-Party SDKs:

Secria does not include any third-party analytics, advertising, or tracking SDKs on any platform. We do not use Firebase Analytics, Google Analytics, Facebook SDK, or any similar tools.

1.4 Content Data

What We Collect:

Secria does not collect or access the content of your messages. All message content is secured using end-to-end and zero-knowledge encryption, making it technically inaccessible to us at any point—whether in storage or transit.

If You Share Logs:

In rare cases where you explicitly provide debug logs for support, those may include limited metadata or diagnostic data but never message content. This is entirely voluntary and used solely to resolve technical issues.

Why We Collect Diagnostic Data (When Shared):

Only to operate and troubleshoot the service effectively, in situations where you've chosen to involve us. We do not and cannot access message content, even under legal request.

Encryption:

We use end-to-end encryption and a zero-knowledge architecture to ensure your communications remain private, secure, and unreadable to anyone but you and your verified contacts.

1.5 Payment Information

What We Collect:

If you subscribe to premium services, payments are processed by one of the following third-party providers depending on your platform:

  • iOS: Payments are handled by Apple through the App Store. Secria receives a transaction confirmation and subscription status from Apple but never sees your payment details. Apple's billing is governed by Apple's Privacy Policy.
  • Web & Android: Payments are handled by Stripe, a PCI DSS Level 1 certified payment processor. Secria receives a transaction confirmation and subscription status from Stripe but never stores your full card number or billing details. Stripe's data handling is governed by Stripe's Privacy Policy.

Why We Collect It:

  • To verify your subscription status and provide access to premium features.

Note: Secria does not store your payment card details, billing address, or any financial information. All payment processing is handled entirely by Apple, Google, or Stripe.

2. How We Use Your Information

We use your information to:

  • Operate and Provide Services: Facilitate secure messaging, account management, and user support.
  • Improve Our Services: Analyze platform usage and performance to enhance security features, develop new functionalities, and optimize user experience.
  • Communicate With You: Send important updates, security alerts, or administrative messages.

Legal Compliance & Security:

  • Comply with applicable laws, court orders, or governmental requests.
  • Prevent, detect, and investigate fraudulent or unauthorized activities.

3. Sharing Your Information

3.1 Service Providers

We may share your data with trusted third-party vendors (e.g., payment processors, cloud hosting) solely to help us operate our platform.

These vendors are contractually required to implement adequate safeguards and only process your data in accordance with our instructions.

3.2 Legal Compliance

We may disclose your data if required to comply with applicable laws, respond to a court order, or other legal process, or to protect our rights and property.

If we receive a law enforcement request for user data, we only disclose the minimal information necessary to comply, in keeping with our legal obligations.

3.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new entity. You will receive notice of any significant changes in ownership or data practices.

3.4 No Data Selling

We do not sell your personal information to third parties.

4. Data Retention

We retain your personal information only as long as necessary to fulfill the purposes described in this Privacy Policy or to comply with legal obligations.

For inactive accounts (e.g., no login activity for 2+ years), your data may be deleted in accordance with our data retention and backup policies.

In certain regulated contexts (e.g., financial or legal requirements), we may keep relevant records longer, but only to meet those specific obligations.

5. Security Measures

We implement rigorous security measures to protect your information, including:

  • State-of-the-art encryption for data in transit and at rest
  • Regular security audits and vulnerability assessments
  • Strict access controls for internal systems
  • Continuous monitoring for unauthorized access attempts

User Responsibility: While we strive for the highest level of security, no system is foolproof. We urge you to protect your account credentials and private keys and to use caution when sharing information online.

6. Your Privacy Rights

Depending on your location, you have specific rights regarding your personal information under applicable privacy laws.

For Users in the European Economic Area (GDPR)

Under the General Data Protection Regulation, you have the right to:

  • Access your personal data
  • Rectify inaccurate personal data
  • Request erasure of your personal data ("right to be forgotten")
  • Restrict or object to processing of your personal data
  • Data portability
  • Withdraw consent at any time

Our legal basis for processing is legitimate interest (operating the service) and, where applicable, your consent.

For Users in California (CCPA/CPRA)

Under the California Consumer Privacy Act and California Privacy Rights Act, you have the right to:

  • Know what personal information we collect and how it is used
  • Request deletion of your personal information
  • Opt out of the sale or sharing of personal information (Secria does not sell or share your data)
  • Non-discrimination for exercising your privacy rights

Exercising Your Rights

To exercise any of these rights, please contact us at hq@secria.me. We will respond to all valid requests within 30 days. You will not be charged a fee for exercising your rights.

7. Children's Privacy

Our services are not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If we learn we have collected information from a child under 16, we will delete that information.

8. Cookies and Tracking Technologies

What We Use:

Secria uses local storage and session tokens to maintain your authenticated session and store your encryption keys securely in your browser. We do not use third-party cookies, tracking pixels, or advertising cookies.

Analytics:

We use internal, self-hosted tools to monitor service health and aggregate usage metrics (e.g., total storage used, email volume). These metrics are anonymized and are never shared with third parties. We do not use Google Analytics, Mixpanel, or any external analytics platform.

Your Control:

You can configure your browser to refuse cookies or clear local storage at any time. However, doing so will require you to log in again and may require re-importing your encryption keys.

9. International Data Transfers

Secria operates globally. Your data may be transferred to and processed in countries outside your own, which may have different data protection laws.

We ensure that appropriate safeguards (e.g., standard contractual clauses, encryption) are in place to protect your information during such transfers.

10. Changes to this Privacy Policy

We reserve the right to update or modify this Privacy Policy at any time.

Notice of Material Changes: If we make significant updates, we will notify you via in-platform alerts, email, or other prominent means.

The Effective Date at the top of this Policy indicates the most recent revision date.

11. Contact Information

If you have questions or concerns about this Privacy Policy or our data practices, please reach out to us at:

hq@secria.me

By using Secria's services, you acknowledge that you have read and understood this Privacy Policy. Thank you for trusting Secria as your secure communication platform.