Effective Date: July 14, 2026
At Secria, your privacy is our highest priority. This Privacy Policy explains how we collect, use, disclose, and safeguard your information across all Secria services, including our website at secria.me, Secria Mail, and Secria VPN. Practices that apply only to Secria VPN are described in the dedicated VPN section below.
We collect minimal information necessary to provide our services effectively and securely. This may include:
What We Collect:
Why We Collect It:
This data is never sold.
What We Collect:
We collect only the data you provide when logging in. This includes your account name, selected subscription plan, login timestamps, and message transmission times.
Why We Collect It:
To operate the service, maintain account functionality, and troubleshoot any issues that may arise.
Privacy Note:
We do not use IP addresses, device fingerprints, browser details, or background telemetry to track or profile you, and our website sets no analytics or advertising cookies. We do process your IP address transiently, in hashed form, solely for security and abuse prevention (such as rate-limiting and login-lockout); enterprise administrators may also retain IP addresses in their own account's audit logs. No data is sold, tracked, or shared for marketing. All collected usage data is minimal and limited strictly to what is needed for core functionality and security.
What We Collect:
Secria does not sell, mine, or use the content of your messages for advertising. Your messages are encrypted, including with post-quantum encryption where applicable, and stored message content is encrypted to your keys. Some operations necessarily process content—for example, delivering a message to an external (non-Secria) recipient, or scanning attachments for malware.
If You Share Logs:
In rare cases where you explicitly provide debug logs for support, those may include limited metadata or diagnostic data but never message content. This is entirely voluntary and used solely to resolve technical issues.
Why We Collect Diagnostic Data (When Shared):
Only to operate and troubleshoot the service effectively, in situations where you've chosen to involve us. We do not use message content for advertising or profiling, and we disclose information only when required by valid legal process.
Encryption:
We use strong encryption—including end-to-end encryption between Secria accounts and post-quantum encryption where applicable—to protect your communications from unauthorized access.
What We Collect:
Why We Collect It:
Note: Secria does not store your full payment information directly; we rely on trusted third-party payment processors that comply with industry standards (e.g., PCI DSS).
We use your information to:
Legal Compliance & Security:
If you are in the European Economic Area or the United Kingdom, we process your personal data under the following legal bases: performance of a contract (to provide the Services you sign up for), legitimate interests (to secure our platform, prevent abuse, and improve the Services), consent (where you have given it, such as for optional communications, which you may withdraw at any time), and compliance with legal obligations.
We may share your data with trusted third-party vendors (e.g., payment processors, cloud hosting) solely to help us operate our platform.
These vendors are contractually required to implement adequate safeguards and only process your data in accordance with our instructions.
We may disclose your data if required to comply with applicable laws, respond to a court order, or other legal process, or to protect our rights and property.
If we receive a law enforcement request for user data, we only disclose the minimal information necessary to comply, in keeping with our legal obligations.
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new entity. You will receive notice of any significant changes in ownership or data practices.
We do not sell your personal information to third parties.
We retain your personal information only as long as necessary to fulfill the purposes described in this Privacy Policy or to comply with legal obligations.
For inactive accounts (e.g., no login activity for 2+ years), your data may be deleted in accordance with our data retention and backup policies.
In certain regulated contexts (e.g., financial or legal requirements), we may keep relevant records longer, but only to meet those specific obligations.
We implement rigorous security measures to protect your information, including:
User Responsibility: While we strive for the highest level of security, no system is foolproof. We urge you to protect your account credentials and private keys and to use caution when sharing information online.
Depending on your location, you may have certain rights regarding your personal information:
To exercise these rights, please contact us at hq@secria.me.
If you are a California resident, you have the right to know what personal information we collect and how it is used, to request access to, deletion of, or correction of your personal information, and to not be discriminated against for exercising these rights. We do not sell or share your personal information as those terms are defined under California law, and we do not use it for cross-context behavioral advertising. The categories of personal information we collect are described in Section 1 (account, usage, content, and payment information). To exercise your rights, contact us at hq@secria.me; we verify requests using your account credentials.
If you are in the European Economic Area or the United Kingdom, in addition to the rights above you may lodge a complaint with your local data protection supervisory authority. Our legal bases for processing are described in Section 2, and safeguards for international data transfers are described in Section 9. For any request, contact us at hq@secria.me.
Our services are not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If we learn we have collected information from a child under 16, we will delete that information.
You can configure your browser to refuse cookies or notify you before accepting them. However, blocking cookies may limit certain features or functionality of our services.
Secria operates globally. Your data may be transferred to and processed in countries outside your own, which may have different data protection laws.
We ensure that appropriate safeguards (e.g., standard contractual clauses, encryption) are in place to protect your information during such transfers.
Secria VPN is part of your Secria account. It is built on a simple principle: your internet activity is none of our business. This section describes the data practices specific to Secria VPN.
No-Logs: We do not log your browsing activity, DNS queries, traffic content, or originating IP addresses. We cannot see what you do online while connected to Secria VPN.
Our VPN servers run in RAM only where possible. No traffic data is ever written to disk.
We collect only the minimum information needed to operate the VPN: your email address (for account authentication via Secria Mail), your subscription status (to determine access level), and your registered devices—including each device's public key, its VPN-assigned internal IP, and when it last connected—to enforce the device limit and secure your account. Aggregate server load metrics are used for load balancing and are not tied to any user. This connection metadata can show that a device connected, and to which server, but never what you did while connected: we do not log your browsing activity, DNS queries, or traffic, so we cannot link your account to your online activity.
Your traffic is encrypted between your device and our VPN server. We cannot inspect it.
If we receive a legal request for VPN user data, we can only provide what we have: your email address, subscription status, and limited connection metadata (your registered devices and when they last connected). We cannot provide browsing history, DNS queries, or traffic data, because we do not have it. We will notify affected users of legal requests unless prohibited by law.
We reserve the right to update or modify this Privacy Policy at any time.
Notice of Material Changes: If we make significant updates, we will notify you via in-platform alerts, email, or other prominent means.
The Effective Date at the top of this Policy indicates the most recent revision date.
If you have questions or concerns about this Privacy Policy or our data practices, please reach out to us at:
Secria Mail and Secria VPN are operated by Secria, Inc., a Delaware corporation, which is the controller of the personal data described in this Policy.
Secria, Inc.
8 The Green, Suite A
Dover, DE 19901
United States
By using Secria's services, you acknowledge that you have read and understood this Privacy Policy. Thank you for trusting Secria as your secure communication platform.