Privacy Policy — ConfiMsg

Last updated: April 20, 2026

1. Overview

ConfiMsg ("the App", "we", "our") is a zero-knowledge encrypted messaging service. This Privacy Policy explains how we handle information when you use our Android application and website at confimsg.com.

2. Information We Do NOT Collect

We do not collect, store, or process:

3. How Encryption Works

All messages are encrypted on your device using AES-256-GCM before being transmitted. The decryption key is generated locally and embedded only in the URL fragment (the part after "#"). URL fragments are never sent to our servers by any browser or HTTP client. This means we have no technical capability to read your messages — ever.

4. What We Store on Our Servers

Our servers store only:

This data is permanently deleted after the message is opened once, or after a set expiration period (default: 7 days).

5. Device Identifier

We collect an anonymous device identifier solely to enforce rate limits and prevent abuse. This identifier is not linked to your identity, messages, or any personal information, and is not shared with third parties.

6. Permissions

The App requests the following Android permissions:

7. Third-Party Services

We do not use any third-party analytics, advertising SDKs, or tracking services. The App does not contain ads.

8. Data Retention

Encrypted messages are automatically deleted from our servers after they are opened once (self-destruct), or after 7 days if not opened. We do not retain any personal data.

9. Children's Privacy

The App is not directed at children under 13. We do not knowingly collect any information from children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted at https://confimsg.com/static/html/privacy.html. Continued use of the App after changes constitutes acceptance of the updated policy.

11. Contact

If you have any questions about this Privacy Policy, contact us at: privacy@confimsg.com