Privacy Policy

Last updated: 2026‑07‑16

This Privacy Policy explains how Core51, Inc. (“Core51”, “we”, “us”) processes personal data in connection with the website and mobile applications (the “Service”).

1. Controller and contact

Controller: Core51, Inc. (Delaware, USA). Contact: info@core-51.com.

2. Data we process

  • Account data: email address, password hash, Core ID, profile fields you provide.
  • Service data: encrypted message and attachment content (ciphertext) and associated metadata (timestamps, IDs, hashes/signatures) necessary for delivery, integrity, and verification.
  • Technical and security data: IP address, device/browser identifiers, logs, and security events (for fraud prevention, abuse control, and service reliability).
  • Payments (if enabled): billing and payment records handled by payment processors; we may receive limited transaction identifiers and status.

3. End‑to‑end encryption

Core51 is designed so message and file contents are encrypted on user devices. We do not aim to store message plaintext. However, metadata and encrypted blobs may still be personal data.

4. Purposes and legal bases

  • Provide and maintain the Service (contract / legitimate interests).
  • Security and abuse prevention (legitimate interests; compliance where applicable).
  • Integrity and dispute support (legitimate interests), including features intended to support auditability and proof of business agreements.
  • Communications (account verification, service notices) (contract / legitimate interests).
  • Compliance (legal obligations where applicable).

5. Account deletion

You may request account deletion from the Service. When an account is deleted, we disable login, invalidate existing authentication tokens, remove push notification tokens, cancel active subscription and entitlement records, and remove or anonymize ordinary profile data such as name, company, job title, phone, location, gender, and personal avatar.

The deleted account is shown to other users as a deleted account with a generic deleted-account avatar. We do not continue to show the deleted user’s ordinary profile fields through contacts, search, chat lookup, or profile APIs. A user who deleted an account may register again with the same email address as a new account.

Core ID / Public ID. A Core ID that has been assigned to an account is not reissued to another account after deletion. This helps avoid confusion in historical conversations and audit records.

Chats and evidence records. Account deletion does not necessarily delete chat history. Encrypted message ciphertext, encrypted attachments, message metadata, key-envelope records, timestamps, hashes, signatures, public end-to-end encryption keys, and related integrity records may remain stored so that existing conversation participants can retain, export, decrypt, and verify their historical conversations. We do not store users’ private E2EE keys.

Email evidence. To support account integrity, fraud prevention, and dispute resolution without keeping a hidden copy of the account profile, we may retain a minimal identity evidence record containing the user ID, historical Core ID, email verification status, verification timestamp where applicable, public key fingerprints, and a keyed HMAC-SHA256 hash of the normalized email address. We do not store the plaintext email address in this evidence record. This record is not exposed through ordinary user-facing profile, contacts, or search APIs.

These retained records are used only as needed for service integrity, security, fraud prevention, legal compliance, audits, dispute resolution, and the establishment, exercise, or defense of legal claims, to the maximum extent permitted by law.

6. Sharing and processors

We use processors to operate the Service (e.g., hosting/VPS, email delivery, object storage, payment processing). We share only what is necessary to provide the Service and maintain security.

7. International transfers

Your data may be processed in countries outside your jurisdiction, including the United States. Where required, we use appropriate safeguards (e.g., contractual protections) and security measures.

8. Retention

We retain personal data as long as needed to provide the Service, support integrity and dispute resolution, comply with legal obligations, and enforce agreements. Retention periods depend on data type (account, security logs, payments, and service records). Encrypted content and integrity records may be retained after account deletion where needed for conversation history, export, verification, legal holds, fraud prevention, or the establishment, exercise, or defense of legal claims.

9. Your rights

Depending on your location, you may have rights to access, correct, delete, or obtain a copy of your personal data, and to object or restrict processing. To exercise rights, contact info@core-51.com.

10. Cookies

We may use essential cookies or local storage for authentication and site functionality. See Cookies for more details.

11. Security

We implement technical and organizational measures designed to protect data. No system is perfectly secure, especially during beta.

12. Children

The Service is not intended for children. We do not knowingly collect personal data from children under 13 (or a higher age where required by law).

13. Changes

We may update this Privacy Policy from time to time. The “Last updated” date indicates the latest revision.

14. Contact

Privacy questions: info@core-51.com.