Privacy Policy.

Private conversations should stay yours. Here's exactly what we collect, what we can't see, and the choices you have.

Last updated: July 20, 2026

1. The short version

The current iPhone client encrypts supported one-to-one and group messages, media, status updates, group system events, and encoded call frames on-device before UIMessage relays receive them. Account, profile, audience, delivery, call, and routing metadata remain visible to the service. We do not sell your data or show you ads.

Recipient public keys currently come from UIMessage's server directory without safety-number or transparency verification. An active compromise of that directory could substitute a key, so this design is not Signal-equivalent and does not yet provide Double Ratchet post-compromise security. Android is a UI preview and does not implement the iPhone protocol.

2. Information we collect

Account information: your phone number, which we use to create your account and help your contacts find you. You may optionally add a display name, profile photo, and an “about” line.

Contacts: if you grant permission, we use your address book to show you which of your contacts already use UIMessage. Contact matching is performed using transformed (hashed) identifiers wherever possible.

Technical and delivery data: limited metadata required to deliver messages and calls (such as device tokens for notifications, timestamps, and routing information). We minimize and retain this for only as long as needed to operate the service.

3. Content protection and its trust boundary

During normal operation, UIMessage's backend routes and stores ciphertext and has no content-decryption path for supported iPhone messages, media, statuses, system events, or encoded call frames. Private identity-key material is stored on the device; public identity keys are stored in the service directory.

The service directory is inside the current trust boundary. Because clients do not independently verify directory keys, a compromised directory could substitute a recipient key. UIMessage has not yet implemented X3DH, Double Ratchet, safety numbers, key transparency, or a complete multi-device identity model.

On iPhone, durable chat/status snapshots and status media use SQLCipher with a hardware-wrapped database key on supported physical devices. Some decrypted chat attachment and composer/export cache files remain outside SQLCipher under the operating system's file protection and are a known at-rest hardening gap.

4. How we use information

We use the limited information we collect to operate, maintain, and secure the service: registering your account, delivering messages and notifications, connecting calls, preventing abuse and spam, and improving reliability and performance.

We do not use your information for advertising, and we do not sell or rent it to third parties.

5. Sharing

We share information only with service providers who help us run UIMessage (for example, push-notification delivery), under contracts that require them to protect it, or when required by law. We will always seek to limit any disclosure to the minimum necessary.

6. Data retention

Encrypted content and delivery metadata are retained as needed to operate the service and apply configured expiry or deletion rules; delivery does not by itself promise immediate server deletion. Account and profile information is retained while needed to operate the account and to satisfy applicable security, legal, and deletion obligations.

7. Your choices

You can edit your profile, manage privacy settings (such as who can see your profile photo, last-seen, and status), and delete your account at any time from within the app. You can also revoke contacts, notifications, camera, and microphone permissions in your device settings.

8. Children

UIMessage is not directed to children under 13 (or the minimum age required in your country). We do not knowingly collect information from children below that age.

9. Changes

We may update this policy from time to time. When we make material changes, we'll update the date above and, where appropriate, notify you in the app.

10. Contact

UIMessage is built by Silicon Visions. If you have questions about this policy or your data, reach us at hello@uimessage.com.