Privacy Policy
Last Updated: October 2026
1. INTRODUCTION
PairCrypt is built with privacy-by-design principles to protect your communications. We believe that your private notes should remain truly private.
2. DATA MINIMIZATION & METADATA
PairCrypt prioritizes data minimization and does not collect names or contact details. To operate the service, PairCrypt processes limited technical metadata (pseudonymous device IDs that are generated specifically for each room, room IDs, and network metadata). PairCrypt uses Supabase as its infrastructure and relay provider. Encrypted message content is transmitted to the relay in encrypted form, and PairCrypt does not provide the relay provider with the decryption keys.
When Tor is disabled, PairCrypt processes hashed IP addresses at the application level for rate limiting, security, and abuse prevention. PairCrypt may also process limited technical metadata for service operation, synchronization, abuse prevention, rate limiting, security, and service reliability.
3. ZERO-KNOWLEDGE ENCRYPTION
All notes are encrypted locally on your device using end-to-end encryption (E2EE). PairCrypt does not possess the decryption keys required to decrypt your content and therefore cannot access your content in plaintext.
4. NETWORK & TOR
PairCrypt provides an optional embedded Tor network feature.
When Tor is enabled, PairCrypt's application network traffic, including applicable REST requests, WebSocket connections, synchronization traffic, and relay communications, is routed through the embedded Tor network rather than directly to PairCrypt's infrastructure.
PairCrypt uses a strict fail-closed approach when Tor is enabled. If Tor is not fully available or ready, PairCrypt's applicable network connections are refused locally rather than silently falling back to a direct connection.
Tor is optional. When Tor is disabled, PairCrypt may use the device's normal network connection.
PairCrypt's Tor feature applies to PairCrypt application network traffic. External web links or native platform payment screens opened outside PairCrypt run through native operating system components outside PairCrypt's embedded Tor routing.
PairCrypt's "New Circuit" feature requests a new Tor circuit and temporarily pauses applicable PairCrypt network traffic while the circuit is reconstructed. A new circuit may use different Tor relays and may result in a different public exit IP, but Tor does not guarantee that the public exit IP will always change.
Tor provides network-path privacy but does not guarantee complete anonymity against every possible observer or threat.
5. DATA RETENTION
Encrypted message payloads are retained only as necessary to facilitate delivery and synchronization and are generally deleted within 3 days after successful delivery. Retention may vary where necessary for legal obligations, dispute resolution, security, or service integrity.
Technical security metadata is retained for approximately 72 hours for abuse prevention. Retention may vary where necessary for legitimate security or legal requirements.
Subscription transaction records may be retained as necessary for accounting, fraud prevention, and reconciliation.
6. SUBSCRIPTIONS
Purchases are processed by Apple through the App Store or by Google through Google Play, depending on your platform. PairCrypt processes limited purchase and subscription information, including transaction identifiers or tokens where necessary, to verify your status using a privacy-preserving mechanism designed to minimize the link between your payment and your private communications.
Payment processing itself is handled by the applicable platform provider under its own terms and privacy practices.
7. DATA DELETION
You can delete locally stored data using the app's "Wipe" or "Power Wipe" features, which erase encrypted notes, keys, and local application data. You can also trigger "Power Wipe+" to delete local data and initiate deletion of associated server-side room and quota metadata. PairCrypt cannot recover encrypted content or encryption keys that have been permanently deleted from your device.
To request access to or deletion of server-side metadata, contact the email below.
8. COMPLIANCE & RIGHTS
PairCrypt seeks to comply with applicable privacy and data-protection laws. Users may contact PairCrypt to exercise applicable rights concerning access, correction, or deletion of their data.
9. CONTACT
For any privacy-related questions, please contact us at:
support@paircrypt.com