Scope
This policy covers SealSend - Secure Messaging, its delivery infrastructure and this website. The mobile-app descriptions below apply to the current external-mail architecture, including Android version 1.0.6. SealSend does not sell personal data or use mobile-app data for advertising.
Local Wallets and App Security
You create or import a local wallet identity, not a centrally hosted email/password account. Recovery phrases, private encryption keys and PIN protection are handled on your device. Biometric authentication is performed by the operating system; SealSend does not receive fingerprint images or biometric templates.
Contacts, readable message history and wallet profiles are stored locally using the app's protected storage. Creating a wallet does not register your phone number or email address with SealSend. Keep each wallet's recovery phrase private and backed up.
Email Addresses and External Apps
The current mobile app does not connect to your mailbox, request Gmail OAuth access, read your inbox or store a mailbox password. It encrypts a message and selected attachments locally, then opens your chosen email or chat application when you ask it to share the resulting file.
For email delivery, the recipient email address and a generic subject and delivery instructions are passed to the external email app. A share-sheet fallback also copies those delivery instructions, including the recipient address, to the device clipboard. The mail application and provider process normal delivery metadata under their own policies. This optional handoff is disclosed as email-address sharing for app functionality in our Google Play Data safety information.
An optional reply-to address entered in SealSend is protected inside the encrypted package and becomes visible to the intended recipient after decryption. SealSend does not send readable recipient or reply-to email addresses to its chat relay or maintain a server-side email-address directory.
Build 18 contains an optional phone-number-or-email invitation field that is not used to send invitations or stored with the new contact. Entering a phone number there does not transmit it to SealSend. Choosing a recipient in WhatsApp, SMS or another external app is handled by that app.
Legacy versions used Gmail authorization. Updating performs best-effort revocation and removes legacy local Gmail account/cache data. You can also revoke old access in your Google Account settings. The browser extension has a separate browser-based interaction model; the current mobile app does not require that extension.
Encrypted Chat and Delivery Metadata
Direct and group communication uses encrypted message content. SealSend's relay receives encrypted envelopes plus public wallet identifiers, public keys or signatures needed for authentication, sender/recipient routing information, delivery identifiers and timestamps. The relay can see this metadata even though it does not have the private keys needed to read message content.
Queued offline messages are configured to expire after seven days; delivery acknowledgements can remove them earlier. Expiration is processed by the service's cleanup cycle. Local and recipient copies may remain until deleted on those devices.
Network services receive IP addresses and connection/request information for delivery, authentication, rate limiting and abuse prevention. Operational logs are subject to hosting-service log rotation and security needs; they are not a promise of immediate deletion when the app is removed. We do not intentionally log plaintext messages, recovery phrases, PINs or private keys.
ION and TON Wallet Features
Wallet features send public wallet addresses and relevant signed requests to ION or TON network infrastructure and RPC providers, including ION's API and Toncenter. These services can observe queried addresses, network identifiers and requests for public wallet status, balances and transaction history.
When you authorize activation or a transfer, signed transaction data is broadcast to the selected network. Transactions, addresses and amounts recorded on a public blockchain are public and cannot be erased by SealSend. We disclose wallet identifiers and other financial information needed for these functions; recovery phrases and private keys are not sent to these providers.
Attachments, Camera and Temporary Files
Chat media is encrypted locally before upload through the SealSend relay to Pinata/IPFS. The relay and storage provider process ciphertext and upload metadata. IPFS content may persist in third-party caches or pins, so deleting a local message or removing a pin cannot guarantee deletion of every encrypted copy.
Secure-email files are normally handed directly to the external mail or chat app. Optional hosted secure-email links and package uploads are disabled in the build 18 release configuration.
Camera access is used on demand for wallet QR scanning; SealSend does not upload camera frames from this scanner. Microphone and file/media access are used when you choose the corresponding attachment functions. Received files are decrypted locally. App-private temporary files are cleaned on a best-effort basis, including removal of entries older than 24 hours when cleanup runs. Files you export or share are controlled by the receiving app and your device.
Security and Third Parties
App network services use HTTPS or WSS. Message and attachment content additionally uses end-to-end encryption. Encryption does not hide public wallet identifiers, IP addresses, message timing or ordinary email delivery metadata, and cannot prevent a recipient from copying decrypted content.
Hosting/network providers, the chat relay, Pinata/IPFS, blockchain RPC providers and user-selected email/chat apps participate in the relevant workflows. Their retention and handling practices also apply to data they receive. Transfers requested by you are for communication or wallet functionality, not advertising or sale of your information.
Your Controls and Retention Limits
You can decline optional sharing, cancel an external composer, revoke camera or microphone permissions in device settings, delete local messages, or use Settings > Delete Wallet to remove local wallet data. Back up recovery phrases before deleting a wallet or uninstalling.
Deleting local data does not delete public blockchain records, messages already received by other people, copies in external email/chat services, or encrypted content replicated on IPFS. Contact the relevant service for its deletion controls. SealSend does not currently provide a self-service mechanism that erases all off-device data associated with a wallet.
Website and Privacy Questions
This website's hosting and network services process standard request information, including IP address and requested URL, to serve and protect the site. These website requests are separate from the mobile app's encrypted message contents.
For privacy questions, use the developer contact listed under App support on the official SealSend Google Play listing. Do not send a recovery phrase, private key or PIN with a support request.
Changes
We update this page when data handling changes. The date above identifies the current policy; store declarations must be updated before enabling additional collection or sharing features.