Privacy Policy
Last updated: 2026‑04‑23
This Privacy Policy explains how Core51, Inc. (“Core51”, “we”, “us”) processes personal data when you use the Core51 website and mobile applications (the “Service”). It is written to be clear, but it is also intended to be complete and suitable for serious business use.
Key points
- End‑to‑end encryption: message and file contents are encrypted on devices. We are not designed to store message plaintext.
- We still process metadata: identifiers, timestamps, routing/delivery data, cryptographic hashes/signatures, and security logs are needed to run a secure messenger.
- Business‑grade integrity: the Service may maintain tamper‑evident records (e.g., hash chains / audit events) to support reliability and verification.
- Your controls: you can request access, deletion, and other rights (see “Your rights”).
1. Controller and contact
Controller: Core51, Inc. (Delaware, USA). Legal address: 251 Little Falls Drive, Delaware 19808, USA. Phone: +1 302 5205090. Email: info@core-51.com.
2. Scope
This Privacy Policy applies to personal data processed through the Service, including the website, mobile apps, support interactions, and security operations. If we provide separate enterprise agreements, they may include additional privacy terms for that relationship.
3. Definitions
- Personal data means information relating to an identified or identifiable person.
- Content means user‑generated message text, files, and attachments.
- Metadata means data about communications (e.g., timestamps, IDs, cryptographic hashes, delivery and integrity signals) that is not the plaintext content itself.
4. Data we process
We aim to minimize data collection, but a secure messenger still requires certain categories of information.
- Account and profile data: email address, password hash, internal account identifiers, public identifiers (e.g., “Core ID / Public ID”), and profile fields you choose to provide.
- Authentication data: session tokens and related security attributes used to protect accounts.
- Encrypted service data (ciphertext): encrypted message payloads and encrypted attachments stored to deliver the Service.
- Cryptographic and integrity data: message IDs, conversation IDs, created timestamps, cryptographic hashes, signatures, key‑envelope records (e.g., per‑recipient key wrapping), and audit/integrity events used to verify or troubleshoot delivery and tamper‑evidence.
- Delivery and device data: push notification tokens (e.g., Firebase Cloud Messaging), device/platform type, and app version signals (where available).
- Support and communications: emails or messages you send to support and our responses.
- Payments (if enabled): billing status and limited transaction identifiers from payment processors. We do not intend to store full card data ourselves.
- Security logs: IP address, approximate location derived from IP (coarse), request logs, abuse signals, and incident records.
5. End‑to‑end encryption and what we can (and cannot) see
Core51 is designed so that message and file contents are encrypted on user devices before they reach our servers. As a result:
- We are not designed to access message plaintext or attachment plaintext in normal operation.
- We may store ciphertext and metadata necessary to route and deliver messages and to support integrity and verification features.
- Users may be able to export and verify records using integrity tools; such exports may include cryptographic audit fields.
Important: Metadata can still be personal data, and encryption does not eliminate all privacy risks. We therefore apply security and access controls to both content ciphertext and metadata.
Device integrity: End‑to‑end encryption depends on the security of your devices and how you use the Service. We are not responsible for privacy or confidentiality issues caused by (i) malware or unauthorized access on your device, (ii) you sharing, backing up, exporting, or otherwise disclosing chat data, or (iii) you losing control of private keys or account credentials. If you choose to export conversations or store keys insecurely, that may expose otherwise encrypted content.
6. Purposes of processing
- Provide and operate the Service: account creation, login, message routing, delivery, and synchronization.
- Security and abuse prevention: protect accounts, prevent spam/fraud, detect attacks, and enforce policies.
- Integrity and verification: maintain and verify tamper‑evident service records and support dispute/investigation workflows (e.g., delivery state, audit events, hash‑chain checks).
- Support and communications: respond to requests, provide service notices, and contact you about account/security issues.
- Compliance: comply with applicable laws, lawful requests, and enforceable obligations.
- Improve reliability: debugging, incident response, performance monitoring, and scaling (with a preference for privacy‑preserving approaches).
7. Legal bases (GDPR / similar laws)
Where GDPR applies, we rely on one or more of the following legal bases depending on the context:
- Contract (Art. 6(1)(b)): to provide the Service you request.
- Legitimate interests (Art. 6(1)(f)): to secure the Service, prevent abuse, ensure integrity, and improve reliability, balanced against your rights.
- Legal obligation (Art. 6(1)(c)): where we must retain or disclose data under applicable law.
- Consent (Art. 6(1)(a)): when we ask you for it (for example, for certain optional communications). You may withdraw consent at any time, without affecting processing already performed.
8. Push notifications (FCM)
If you enable notifications, the Service may process push tokens (e.g., Firebase Cloud Messaging) to deliver message alerts. Push providers may receive technical information required to deliver the notification to your device. We aim to keep notification payloads minimal; notification content may be configurable and can depend on your device settings.
9. Sharing, processors, and sub‑processors
We share personal data only as necessary to operate the Service and maintain security. Typical categories of processors may include:
For transparency, we publish a non‑exhaustive list of key sub‑processors here: Sub‑processors.
- Hosting / VPS providers (compute and networking).
- Object storage / CDN for encrypted attachments and downloads.
- Email delivery providers for account emails and support.
- Push notification providers (e.g., Firebase Cloud Messaging) for device delivery.
- Payment processors if paid plans are enabled.
We require processors to implement appropriate security measures and to process data under our instructions, subject to applicable law.
10. International transfers
Core51 is a U.S. company and may process data in the United States and other countries. Where GDPR or similar laws apply, international transfers may be protected using appropriate safeguards such as Standard Contractual Clauses (SCCs) and, where appropriate, supplementary measures. We also apply security measures designed to protect data in transit and at rest.
11. Retention
We retain personal data only as long as needed for the purposes described above, including security, integrity, dispute support, and legal compliance. Examples:
- Account data: retained while your account is active and for a reasonable period thereafter for security and compliance.
- Encrypted message/attachment data: may be retained until deleted, subject to technical and legal constraints; other participants may retain copies.
- Security logs: retained for limited periods appropriate for investigating abuse and incidents.
- Payments: retained as required by financial and tax rules (where applicable).
Typical retention guidelines
These timeframes are general guidelines and may vary based on security needs, technical constraints, legal obligations, and ongoing disputes/investigations.
- Security logs: typically 30-180 days (longer if needed for incident response, abuse prevention, or legal holds).
- Support requests: typically 12-24 months (to track resolutions and prevent repeated abuse).
- Account data: retained while your account is active; after deletion/deactivation we may retain limited records for a reasonable period for security, fraud prevention, and compliance.
- Encrypted messages and attachments (ciphertext): may be retained until deleted or until accounts/chats are removed, subject to technical and legal constraints; other participants may retain their own copies.
- Integrity/audit records: may be retained to preserve tamper‑evidence and to support verification and dispute resolution, to the extent permitted by law.
- Payments (if enabled): retained as required by accounting/tax rules (often several years).
12. Account deactivation and deletion requests
You may be able to deactivate your account. Deactivation generally disables login and reduces visibility, but it may not remove encrypted service records shared with other users.
Deletion: where legally required and technically feasible, we will delete or anonymize certain personal data upon verified request, subject to legitimate retention needs (e.g., security, abuse prevention, legal obligations, and integrity records).
13. Cookies and local storage
We may use essential cookies and/or local storage for authentication, security, and core site features. See Cookie Notice for details.
14. Security
We implement technical and organizational measures designed to protect personal data, including access controls, encryption in transit, encrypted storage for content where applicable, and security monitoring. No system is perfectly secure, especially during beta, and you should use appropriate device security and strong passwords.
Security incidents: If we become aware of a personal data breach, we will assess it promptly and, where required by applicable law, notify affected users and/or relevant supervisory authorities without undue delay.
15. Your rights
Depending on your jurisdiction (including GDPR), you may have rights to request access, rectification, deletion, portability, and to object or restrict certain processing. You may also have the right to lodge a complaint with a supervisory authority.
To exercise rights, contact info@core-51.com. For security, we may need to verify your identity and may ask for additional information to process your request.
16. Children
The Service is not intended for children. We do not knowingly collect personal data from children under 13 (or a higher age where required by law).
17. Changes
We may update this Privacy Policy from time to time. The “Last updated” date indicates the latest revision.
18. Contact
Core51, Inc.
Legal address: 251 Little Falls Drive, Delaware 19808, USA.
Phone: +1 302 5205090.
Email: info@core-51.com.