Legal · Privacy

Privacy Policy.

What we collect, why, and the short version: your conversations are yours.

Last updated June 10, 2026


The short version

  • End-to-end encryption for direct messages is planned and is not available in the current implementation.
  • We don't sell data, run ads, or share content with third parties.
  • Self-hosted instances send us nothing except an optional update check.
  • You can export or delete your data at any time.

What we collect (hosted service)

DataWhy
Account info (email, username)Sign-in, recovery, and notifications you ask for.
Content you createStored and delivered by the configured application services.
Connection metadata (IP, device)Security, abuse prevention, and session management.
Aggregate usage metricsCapacity planning. Never tied to message content.

What we don't do

We do not read your messages, scan attachments for advertising signals, build behavioral profiles, or train machine-learning models on customer content. Crash reports and diagnostics are opt-in.

Self-hosted instances

On your own instance, all data lives on your hardware. The only outbound request the software makes is a version check against our update server, and you can disable it with one environment variable. We receive no usage data, no account data, and no content from self-hosted deployments.

Retention and deletion

Hosted data is retained while your account is active. Deleting a message removes it for everyone; deleting your account removes your data within 30 days, with encrypted backups aging out within 90. Export is available from Settings at any time.

Your rights

Depending on where you live, you may have rights to access, correct, port, or erase your data (GDPR, CCPA, and similar). Write to privacy@corvus.app and we'll handle it — no forms, no dark patterns.