Legal · Privacy
Privacy Policy.
What we collect, why, and the short version: your conversations are yours.
Last updated June 10, 2026
The short version
- End-to-end encryption for direct messages is planned and is not available in the current implementation.
- We don't sell data, run ads, or share content with third parties.
- Self-hosted instances send us nothing except an optional update check.
- You can export or delete your data at any time.
What we collect (hosted service)
| Data | Why |
|---|---|
| Account info (email, username) | Sign-in, recovery, and notifications you ask for. |
| Content you create | Stored and delivered by the configured application services. |
| Connection metadata (IP, device) | Security, abuse prevention, and session management. |
| Aggregate usage metrics | Capacity planning. Never tied to message content. |
What we don't do
We do not read your messages, scan attachments for advertising signals, build behavioral profiles, or train machine-learning models on customer content. Crash reports and diagnostics are opt-in.
Self-hosted instances
On your own instance, all data lives on your hardware. The only outbound request the software makes is a version check against our update server, and you can disable it with one environment variable. We receive no usage data, no account data, and no content from self-hosted deployments.
Retention and deletion
Hosted data is retained while your account is active. Deleting a message removes it for everyone; deleting your account removes your data within 30 days, with encrypted backups aging out within 90. Export is available from Settings at any time.
Your rights
Depending on where you live, you may have rights to access, correct, port, or erase your data (GDPR, CCPA, and similar). Write to privacy@corvus.app and we'll handle it — no forms, no dark patterns.