Privacy Policy

Privacy for a permission-first messaging system

This page explains what VartaaX is designed to protect, what service data may be processed, and what the server should not be able to read.

Last updated: July 6, 2026

Encrypted content

Server cannot read encrypted messages. Messages and Vault content are encrypted client-side before they are sent to VartaaX services.

VartaaX does not intentionally store plaintext message content or plaintext Vault content. The backend is expected to store and route encrypted payloads only.

Service data

Some account, session, identity, permission, device, subscription, attachment, and operational metadata may be stored so the service can run, secure sessions, route messages, enforce permissions, and show account state.

Object storage may store encrypted blobs for media, attachments, or private records. Those blobs are intended to remain encrypted before storage.

Contact and support

If a contact form or email workflow is used, contact details and the message you send may be received or stored for the purpose of replying to your request.

The current public contact page uses a frontend-only mail link, so no public contact form submission is stored by the VartaaX backend from that page.

No legal overclaim

VartaaX is a working prototype/private-beta product. This policy does not claim a specific certification, audit status, or regulatory compliance program.