Legal
Privacy Policy
This policy explains what NovatisB&J OÜ (Estonia) collects when you use Novatis, why, and what you can do about it. Novatis is built so that we hold as little about you as possible — most importantly, we cannot read your messages or calls.
Encryption
What we cannot see
Your messages, photos, files and calls are end-to-end encrypted on your device. Our servers only ever hold ciphertext, and the keys stay with you and the people you talk to. We cannot read your conversations, and we cannot recover them for you if you lose your recovery key.
There is exactly one exception, and it is yours to trigger: when you report a message or a conversation, your app sends us that message and the few before it in readable form, so that a person on our safety team can review it. Nothing you have not reported is ever sent, and we cannot request it. The screen tells you this before you confirm the report.
If you use phone-contact discovery, your address-book numbers are sent to us over an encrypted connection, matched against verified members, and then discarded. They are never stored and never written to our logs.
Account data
What we do hold
To run an account for you we store:
- Your email address, display name, and — if you choose one — your public @handle.
- Your password, only ever as a slow one-way hash (argon2id). We never see the password itself.
- Your devices and sessions: a device label, the platform, and rotating session tokens, so you can stay signed in and revoke access.
- Two-factor data if you enable it: your authenticator secret and one-way hashes of your recovery codes.
- Your identity-verification status only — one of: not started, pending, approved, rejected, or resubmit.
- If you verify a phone number: a salted one-way hash of it, and the date. We do not store the number itself, so we cannot tell you or anyone else what it is.
- Your saved contacts, favourites, and anyone you have blocked.
- Any report you file with us: the reason you gave, where it happened, and the messages your app sent with the report — the reported message and the few before it, in readable form.
- An append-only security log of sensitive account events (sign-ins, password and device changes, verification changes, blocks, reports, deletions).
Processors
Identity verification
Identity verification is carried out by Sumsub, acting as our processor. Your identity document and selfie are submitted directly to them; we receive only the outcome and, if you complete phone verification, a one-way hash of your confirmed number.
Verification is optional today and nothing in the app requires it: you can register, message and call without it. Where a future feature does require it, we will tell you so before you start.
Delivery
Notifications
When push notifications are enabled, a notification is delivered through Apple (APNs) or Google (FCM). Because we cannot read your messages, the notification carries only an identifier — never message content, and never who wrote it.
Transactional email (verifying your address, resetting your password, confirming a new device) is sent through an email provider hosted in the European Union.
Hosting
Where your data lives
All of our infrastructure — application servers, homeserver and call relay — is hosted in the European Union. Our processors are Sumsub (identity verification), our EU email provider, and Apple/Google purely for delivering notifications.
Retention
How long we keep it
Account data is kept until you delete your account, which you can do yourself in the app.
One exception, stated plainly: entries in our security log are append-only and cannot be edited or removed, because their purpose is to be tamper-evident. After you delete your account those entries remain, but they reference an anonymised account record rather than your personal details.
GDPR
Your rights
Under the GDPR you can ask for a copy of your data, correct it, delete it, take it elsewhere, or object to how we use it. Account deletion and data export are available in the app — you do not need to ask us.
Where we rely on your consent — phone-contact discovery, being findable by phone, and the launch notification list — you can withdraw it at any time, and discovery and findability can be switched off in your profile.
You can also complain to your local data-protection authority.
Contact
Talk to us.
NovatisB&J OÜ, registry code 17518899, Tartu mnt 25, 10117 Tallinn, Estonia. Version 1.0, effective .