SekurMailThis Privacy Policy explains what information SekurMail (Intellect Service Consulting Company, McKinney, Texas, USA — “we,” “us”) collects, how we use and share it, and your choices. It covers the SekurMail apps, websites, and services (the “Service”).
Your message, attachment, profile, and call-media content is encrypted on your device before it reaches us. Our servers store and relay only ciphertext and routing metadata. We do not have the keys to decrypt your content, and we never receive your private keys in any form we can open. (When you link a new device, an encrypted key bundle may briefly transit our servers — it is sealed so that only your devices can open it.) Sender identity is cryptographically verified when a message is opened.
Three capabilities qualify this — please read them:
Organizations as recipients (not surveillance): if you send a message to an organization, that organization's administrators can decrypt it as the recipient — the same way any recipient can read what you send them. This does not give any organization access to your other, member-to-member conversations, which remain end-to-end encrypted to their participants only.
We use the above to: operate and secure the Service (deliver messages, authenticate you, prevent abuse and fraud), provide features you request, process payments, comply with law and legal process, enforce our terms, and communicate with you about the Service. We do not sell your personal information, and we do not use the content of your messages for advertising or profiling — because we cannot read it.
Legal bases (EEA/UK): performance of our contract with you (providing the Service); our legitimate interests (security, abuse prevention, improving reliability); compliance with legal obligations; and consent where required (for example, marketing).
| Data | Retention |
|---|---|
| One-time sign-in codes | ~10 minutes |
| Sign-in sessions | ~30 days |
| Step-up (sensitive-action) grants | ~5 minutes |
| Undelivered relayed messages | ~30 days backstop, then deleted |
| Messages sent to organizations | ~30 days |
| 1:1 / group message history (server-held ciphertext) | ~30 days by default (configurable, up to ~1 year), or earlier if you delete it or a disappearing/burn/view-once setting applies. Copies on your own devices are yours and are not deleted by us |
| Disappearing messages | Timer starts when the message is read; deleted at expiry |
| Burn-after-read | Server copy destroyed when the recipient reads it |
| View-once media | Deleted once all recipients have fetched it |
| Encrypted media (attachment ciphertext) | Follows the message it belongs to — deleted with the message, at its expiry, or when view-once is consumed |
| Media access log | ~180 days |
| Watermark forensic records | ~18 months |
| Security / audit log (incl. IP + user-agent) | Retained indefinitely by design (forensic); survives account deletion |
| Reported-content evidence under legal hold | Retained until an operator disposition; no fixed expiry; survives account deletion |
Deletion is not total. When you delete your account we remove your account, identifiers, devices, messages, media access records, prekeys, push tokens, and related data. We deliberately retain, for security, legal, and integrity reasons: the security/audit log, leak-tracing watermark records, and any reported-content evidence placed under legal hold. See Sections 1–2.
We share information only: (a) with service providers/processors listed in Section 6, acting on our instructions; (b) with an organization you send messages to, which decrypts those messages as the recipient (Section 1); (c) as required by law or valid legal process (see our Law Enforcement Guidelines) — noting we cannot produce content we cannot decrypt; (d) to report CSAM to NCMEC and cooperate with authorities as required; (e) in a merger, acquisition, or asset sale, subject to this policy; and (f) with your consent. We do not sell or rent your personal information.
| Provider | Purpose | Data it receives |
|---|---|---|
| Stripe | Payments/billing | Customer id, card brand/last-4, amounts, email |
| Resend | Email sign-in codes + signup notices (SMTP) | Recipient email + the code |
| Telnyx | SMS sign-in codes | Recipient phone number + the code |
| Amazon Web Services (AWS) | Hosting; encrypted-media storage (S3) | Infrastructure; ciphertext media only |
| Apple (APNs), Google (FCM), Web Push (VAPID) | Content-free push notifications | Push token/endpoint only |
| TURN/relay provider | Relayed encrypted call media when peer-to-peer fails | Encrypted media relay only |
Depending on where you live, you may have rights to access, correct, delete, port, or restrict your personal information, to object to certain processing, and to not be discriminated against for exercising these rights (GDPR/UK-GDPR, CCPA/CPRA, and similar laws). To exercise them, contact privacy@sekurmail.com.
A note on encryption and your rights: because we cannot decrypt your message content, we cannot “produce” that content to you in readable form on request — you already hold it on your device. We can provide the account and metadata we hold. We honor deletion requests subject to the retained-data carve-outs in Section 4.
California: you may request the categories and specifics of personal information we collect, the purposes, and the parties we share it with, and you may request deletion. We do not sell or share personal information as those terms are defined by the CCPA/CPRA.
Our website does not use advertising or analytics cookies or third-party trackers. The web app stores functional data in your browser (your encryption keys, an unlock cache, and your session) so it can work; this is not shared with us. See the Cookies & Local Storage Notice.
We use end-to-end encryption, encryption at rest for sensitive server-side secrets, access controls, and audit logging. No system is perfectly secure. If we learn of a breach affecting your personal information, we will notify you and regulators as required by law.
The Service is not directed to children under 13 (or under 16 in the EEA/UK), and we do not knowingly collect their personal information.
We operate in the United States, and processing occurs in the U.S. and with our processors' locations. Where we transfer EEA/UK personal data internationally, we rely on appropriate safeguards (such as Standard Contractual Clauses).
We may update this policy and will post the new “Last updated” date; for material changes we will provide notice in the app or by email.
Privacy questions or requests: privacy@sekurmail.com. Data controller: SekurMail (Intellect Service Consulting Company), McKinney, Texas, USA.