# Shroud — Privacy Policy

Shroud is an end-to-end encrypted messenger. This policy describes what the
Shroud server operators can and cannot see, and what the app stores on your
device. It matches the Google Play Data safety declarations for this app.

## Messages

All message content — texts, files, stickers, calls — is encrypted on your
device before it leaves it, using the Signal Protocol. The servers store and
forward ciphertext they cannot decrypt. We cannot read your messages, and
we cannot recover them if you lose your devices and your backup key.

## What the servers hold

- Your username, account UUID, device list and public keys (required for
  delivery and key exchange)
- Undelivered ciphertext queues, deleted on delivery
- If you buy a subscription or digital good: the purchase record and
  entitlement (server-verified, idempotent). Purchase data is never
  associated with message content or contacts.
- Membership rosters of groups you join (not message content)

## What stays on your device

Identity keys and conversation history live in an encrypted local vault,
locked by your passphrase. Backups are encrypted with a key derived from
your backup passphrase; the backup key shown at backup time is the only way
to restore after losing all devices.

## What we do NOT do

No ads, no tracking, no analytics on message content, no contact-graph
mining, no selling or sharing of data with third parties. We request no
permissions for contacts or location.

## Deletion

Deleting your account (in-app: Settings → Delete account) immediately removes
your devices, queued ciphertext, backups and group memberships from the
servers. Local vault data is deleted with the app.

## Contact

blockchainvainllc@gmail.com