SekurMail

Privacy Policy

Last updated: July 26, 2026

This Privacy Policy explains what information SekurMail (Intellect Service Consulting Company, McKinney, Texas, USA — “we,” “us”) collects, how we use and share it, and your choices. It covers the SekurMail apps, websites, and services (the “Service”).

The short version: SekurMail is end-to-end encrypted and zero-knowledge for message content. We run the Service by relaying sealed (encrypted) data and a limited amount of routing information. We cannot read your messages, attachments, profile content, or calls, and we never receive your private keys. This policy explains, precisely, the metadata and account information we do handle, the few capabilities that qualify the “we can't read it” promise, and how long we keep things.

1. What we cannot see (the zero-knowledge core)

Your message, attachment, profile, and call-media content is encrypted on your device before it reaches us. Our servers store and relay only ciphertext and routing metadata. We do not have the keys to decrypt your content, and we never receive your private keys in any form we can open. (When you link a new device, an encrypted key bundle may briefly transit our servers — it is sealed so that only your devices can open it.) Sender identity is cryptographically verified when a message is opened.

Three capabilities qualify this — please read them:

  1. Recipient reporting. A person who receives your message can report it to us. Because they already hold the decrypted copy, their report discloses that message to us as evidence. (We still do not decrypt anything; the disclosure comes from the recipient.)
  2. Forced retention / legal hold. When SekurMail has enabled this control (it is off by default), a reported message is retained as evidence: it becomes exempt from recall, deletion, burn-after-read, and disappearing timers, may be retained indefinitely and disclosed to authorities, and survives deletion of your account.
  3. Leak-tracing watermarks. Your app embeds watermarks (on your device) in content you view or send so a leaked copy (for example, a screenshot) can be traced to the account and — for content you viewed — the device involved. Our servers keep watermark records (a token bound to the sender's account, and to the viewing account and device, per message); reading a watermark out of a leaked copy is a restricted, audited action by our security staff, and each such decode is logged.

Organizations as recipients (not surveillance): if you send a message to an organization, that organization's administrators can decrypt it as the recipient — the same way any recipient can read what you send them. This does not give any organization access to your other, member-to-member conversations, which remain end-to-end encrypted to their participants only.

2. Information we collect

2.1 Account and authentication data

2.2 Device and key material (public only)

2.3 Message routing metadata (not content)

2.4 Media

2.5 IP addresses and device signals

2.6 Notifications

2.7 Payments and business data

2.8 Support and signups

3. How we use information

We use the above to: operate and secure the Service (deliver messages, authenticate you, prevent abuse and fraud), provide features you request, process payments, comply with law and legal process, enforce our terms, and communicate with you about the Service. We do not sell your personal information, and we do not use the content of your messages for advertising or profiling — because we cannot read it.

Legal bases (EEA/UK): performance of our contract with you (providing the Service); our legitimate interests (security, abuse prevention, improving reliability); compliance with legal obligations; and consent where required (for example, marketing).

4. How long we keep information (retention)

DataRetention
One-time sign-in codes~10 minutes
Sign-in sessions~30 days
Step-up (sensitive-action) grants~5 minutes
Undelivered relayed messages~30 days backstop, then deleted
Messages sent to organizations~30 days
1:1 / group message history (server-held ciphertext)~30 days by default (configurable, up to ~1 year), or earlier if you delete it or a disappearing/burn/view-once setting applies. Copies on your own devices are yours and are not deleted by us
Disappearing messagesTimer starts when the message is read; deleted at expiry
Burn-after-readServer copy destroyed when the recipient reads it
View-once mediaDeleted once all recipients have fetched it
Encrypted media (attachment ciphertext)Follows the message it belongs to — deleted with the message, at its expiry, or when view-once is consumed
Media access log~180 days
Watermark forensic records~18 months
Security / audit log (incl. IP + user-agent)Retained indefinitely by design (forensic); survives account deletion
Reported-content evidence under legal holdRetained until an operator disposition; no fixed expiry; survives account deletion

Deletion is not total. When you delete your account we remove your account, identifiers, devices, messages, media access records, prekeys, push tokens, and related data. We deliberately retain, for security, legal, and integrity reasons: the security/audit log, leak-tracing watermark records, and any reported-content evidence placed under legal hold. See Sections 1–2.

5. How we share information

We share information only: (a) with service providers/processors listed in Section 6, acting on our instructions; (b) with an organization you send messages to, which decrypts those messages as the recipient (Section 1); (c) as required by law or valid legal process (see our Law Enforcement Guidelines) — noting we cannot produce content we cannot decrypt; (d) to report CSAM to NCMEC and cooperate with authorities as required; (e) in a merger, acquisition, or asset sale, subject to this policy; and (f) with your consent. We do not sell or rent your personal information.

6. Service providers / subprocessors

ProviderPurposeData it receives
StripePayments/billingCustomer id, card brand/last-4, amounts, email
ResendEmail sign-in codes + signup notices (SMTP)Recipient email + the code
TelnyxSMS sign-in codesRecipient phone number + the code
Amazon Web Services (AWS)Hosting; encrypted-media storage (S3)Infrastructure; ciphertext media only
Apple (APNs), Google (FCM), Web Push (VAPID)Content-free push notificationsPush token/endpoint only
TURN/relay providerRelayed encrypted call media when peer-to-peer failsEncrypted media relay only

7. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, port, or restrict your personal information, to object to certain processing, and to not be discriminated against for exercising these rights (GDPR/UK-GDPR, CCPA/CPRA, and similar laws). To exercise them, contact privacy@sekurmail.com.

A note on encryption and your rights: because we cannot decrypt your message content, we cannot “produce” that content to you in readable form on request — you already hold it on your device. We can provide the account and metadata we hold. We honor deletion requests subject to the retained-data carve-outs in Section 4.

California: you may request the categories and specifics of personal information we collect, the purposes, and the parties we share it with, and you may request deletion. We do not sell or share personal information as those terms are defined by the CCPA/CPRA.

8. Cookies and local storage

Our website does not use advertising or analytics cookies or third-party trackers. The web app stores functional data in your browser (your encryption keys, an unlock cache, and your session) so it can work; this is not shared with us. See the Cookies & Local Storage Notice.

9. Security

We use end-to-end encryption, encryption at rest for sensitive server-side secrets, access controls, and audit logging. No system is perfectly secure. If we learn of a breach affecting your personal information, we will notify you and regulators as required by law.

10. Children

The Service is not directed to children under 13 (or under 16 in the EEA/UK), and we do not knowingly collect their personal information.

11. International users and transfers

We operate in the United States, and processing occurs in the U.S. and with our processors' locations. Where we transfer EEA/UK personal data internationally, we rely on appropriate safeguards (such as Standard Contractual Clauses).

12. Changes to this policy

We may update this policy and will post the new “Last updated” date; for material changes we will provide notice in the app or by email.

13. Contact

Privacy questions or requests: privacy@sekurmail.com. Data controller: SekurMail (Intellect Service Consulting Company), McKinney, Texas, USA.