Draft – subject to legal review
Privacy policy
This policy explains which personal data we process when you use 2ecure Messenger – the apps, the web app chat.2ecure.com, the account page account.2ecure.com and this website –, why we do so and what rights you have.
It fulfils the duty to inform under Art. 19 of the Swiss Federal Act on Data Protection (FADP). This English version is provided for convenience; the German version is binding.
Summary
- The 2ecure server is located in Switzerland. 2ecure is not connected to other servers; your data stays on the 2ecure server.
- All chats and calls are end-to-end encrypted by default. We cannot read the content of encrypted messages.
- No ads, no analytics or tracking. We do not sell data.
- Push notifications run through Apple and Google (USA) and contain no message content.
- You can delete your account yourself at any time.
1. Controller
The controller responsible for processing your personal data is:
Thomas Halvorsen
[street and number to follow], 8001 Zürich
Switzerland
For privacy questions and to exercise your rights, write to support@2ecure.com.
2. What data we process
Account
- Email address: for confirmation codes at registration, for resetting your password and for messages about your account.
- Username and user ID, for example
@anna:2ecure.com. - Password: stored only as a non-reversible hash.
- Display name and profile picture, if you set them. They are visible to other people on 2ecure.
- Invitation and consent: which invitation code was used for your account, and when you accepted the terms of use.
- Settings that your account stores on the server, for example notification rules.
Messages and content
- End-to-end encrypted content (messages, pictures, files, voice messages, calls): the server stores and transmits it only in encrypted form. We cannot read it. On 2ecure, encryption is turned on by default for all rooms.
- Content of unencrypted rooms: if a room exceptionally has no end-to-end encryption, its content is readable on the server.
- Metadata: who is a member of which rooms, when messages are sent and read, and the names, topics and pictures of rooms. The server needs this information to deliver messages; it is not end-to-end encrypted.
- Key storage: if you use it, the server stores a backup of your keys that is encrypted with your recovery key. We cannot decrypt it.
Devices, sessions and IP addresses
- For each signed-in device: device name, session identifier, the device’s public keys and the time of last activity.
- IP addresses and technical access information, for example app version or browser. We delete this information after 28 days.
Push notifications
If you allow notifications in the app, the server stores a push token for your device issued by Apple or Google. How notifications are delivered is described under Recipients.
Calls
For calls, the 2ecure call server in Switzerland processes the participants’ IP addresses and connection data for the duration of the call. Calls are end-to-end encrypted and are not recorded.
Reports and contact
- If you report content or people, we store the report: the reported message or person, the room, your reason, the time and your user ID. For encrypted messages, we only learn what you describe or show us yourself.
- If you email us, we process your email address and the content of your message.
Website, web app and account page
- When you visit this website, the server processes technically necessary information (IP address, time, page requested, browser) to deliver the page and keep it secure. This website sets no cookies.
- The web app and the account page use only technically necessary cookies and your browser’s local storage, so that you stay signed in and your keys are stored on your device.
3. Why we process data
- to provide the service: running your account, delivering messages, connecting calls and sending notifications;
- to protect your account and prevent abuse, for example with confirmation codes;
- to review reports and enforce the terms of use;
- to answer your requests;
- to keep the service secure and available, for example with backups;
- to comply with legal obligations.
We do not process your data for advertising, do not build profiles about you and do not sell data.
4. Recipients
We pass personal data only to the following recipients, and only as far as needed for the purpose concerned.
- Email delivery: mail server mail.2econd.net, operated by the operator, Switzerland. Sends confirmation codes and emails about your account on our behalf. Receives your email address and the content of these emails.
- Backups: provider for off-site encrypted backups (to be chosen before the official launch), Switzerland. Stores backups of the server at another location. Backups are encrypted before they leave our server; the provider cannot read them.
- Apple Push Notification service (Apple Inc., USA) for the iPhone app and Firebase Cloud Messaging (Google LLC, USA) for the Android app. They deliver notifications to your device. They receive your device’s push token, identifiers of the room and the message, and the number of unread messages – no message content. The app then fetches the message from the 2ecure server itself.
- Only during the pilot phase: Element’s push service (matrix.org). If you temporarily use the app “Element X” by Element Creations Ltd (United Kingdom) instead of 2ecure Messenger, your notifications run through the push gateway that Element operates for that app at matrix.org, and from there through Apple or Google. The same information as above is transmitted, no message content. The app “Element X” itself is covered by Element’s privacy policy. With 2ecure Messenger, this route no longer applies.
- Authorities: we disclose data only where we are legally obliged to, for example under the Swiss Federal Act on the Surveillance of Post and Telecommunications (SPTA/BÜPF). We cannot disclose the content of end-to-end encrypted messages because we cannot read it.
5. Where data is processed
- Hosting in Switzerland: we run the 2ecure server ourselves, on our own infrastructure in Switzerland.
- No federation: 2ecure is not connected to other servers of the Matrix network. Your account and message data is therefore not transferred to other servers. Should this change, we will update this policy beforehand and inform you.
- No link previews by the server: the 2ecure server does not fetch links shared in chats.
- No tracking: neither the 2ecure apps nor the web app nor this website contain analytics, tracking or advertising. Error reports are not sent to third parties automatically.
6. Disclosure abroad
Apple and Google process push data in the USA. Both are certified under the Swiss-U.S. Data Privacy Framework; since 15 September 2024, the Swiss Federal Council recognises an adequate level of data protection for companies certified in this way. Element Creations Ltd (pilot phase only) is based in the United Kingdom, which in the Federal Council’s assessment also ensures adequate data protection. All other data stays in Switzerland; backups leave our server only in encrypted form.
7. How long we keep data
| Data | Retention |
|---|---|
| Account data (email address, display name, profile picture, settings) | until your account is deleted |
| Username | kept permanently as blocked, so that it is never given to anyone else |
| Messages and files | until they are deleted, or until your account is fully erased on request |
| Deleted messages | content is permanently removed from the server after one day at the latest |
| Uploaded files after an account deletion | 30 days at most |
| IP addresses and access information | 28 days |
| List of signed-in devices | until you sign out of the device or delete your account |
| Push tokens | until you sign out, turn off notifications or delete your account |
| Reports and emails to us | as long as needed to handle them, usually no longer than 12 months after completion |
| Backups | rotating, overwritten after 12 months at the latest |
If we ever have to restore a backup, we re-apply all deletions made since it was created. Details on account deletion are on the Delete account page.
8. Data security
We protect your data with technical and organisational measures, in particular end-to-end encryption, encrypted connections, encrypted backups, server access limited to the operator and regular security updates. If a data security breach nevertheless occurs that poses a high risk to you, we report it to the FDPIC and inform you as required by law.
9. Your rights
- Access to the personal data we process about you;
- Correction of inaccurate data – you can also change your display name, profile picture and email address yourself;
- Deletion – you can delete your account yourself at any time;
- Handover or transfer of your data in a common electronic format;
- Objection to certain processing.
Write to support@2ecure.com, preferably from your account’s email address. We may ask you to confirm your identity and usually reply within 30 days.
You can also lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC/EDÖB): www.edoeb.admin.ch.
10. Minimum age
2ecure is intended for people aged 16 and over.
11. Changes
We update this privacy policy when the service or the law changes. The version published on this page applies. We inform you about significant changes in advance in the app or by email.