Effective August 1, 2026
Privacy starts with collecting less.
What remains on your devices, what infrastructure processes to deliver the service, and which external services appear only when you choose them.
Standard identities
A standard QEYET identity does not require a phone number, legal name, or email address. You may choose a display name, and contacts may assign their own local name or note to you.
Messages and local content
Readable message history, drafts, call logs, contact notes, cached media, and account state are stored on authorized devices. QEYET routing nodes receive encrypted envelopes, not the conversation keys required to read their contents.
Deleting local data removes the selected information from that device. Six recovery words restore identity material; they do not recreate messages deleted from every authorized device and backup.
Routing and operational data
Delivering an internet service necessarily exposes some metadata. QEYET nodes and network providers may process source network addresses, connection timing, approximate encrypted packet size, mailbox routing identifiers, delivery attempts, rate-limit state, and abuse signals.
QEYET clients also send privacy-limited operational telemetry containing the application version, a heartbeat, an observation time, and aggregate event counters such as delivery, retry, file-transfer, and call outcomes. This telemetry is used for system health and does not include message bodies, attachment contents, recovery words, or conversation keys.
Voice, video, and direct files
WebRTC connects participants for calls and direct file transfer. Depending on network conditions, participants, internet providers, and relay services may observe network addresses and timing. File bytes are not retained for offline download by QEYET's message queue; a pending transfer waits for both endpoints.
Push notifications
If you enable notifications, the browser or operating system creates a push subscription that QEYET nodes use to wake the installed experience. Apple, Google, Microsoft, browser vendors, and their delivery networks may process push-routing metadata under their own terms. Notification previews can be disabled in QEYET.
Backups and Google Drive
Backups occur only when you initiate them. Local exports remain under your control. If you configure and use Google Drive backup, Google processes authorization and file storage under your Google account and privacy terms. QEYET does not receive your Google password.
Optional AI assistants (Hermes & Grok)
AI assistants are optional. QeyeT Mail does not send your messages to an AI model by default. You must explicitly connect a bridge and allow AI data sharing in the app before any assistant chat content leaves your device for that purpose.
What may be shared when you use an AI chat: the text (and optional session title) you send in that AI conversation, plus routing identifiers and a display name needed to pair your device with the bridge. Recovery words, device PIN/passcode, and the rest of your mailbox are not sent for AI processing unless you paste them yourself.
Who receives that data:
- Hermes — a Hermes agent bridge that you run or host. That bridge may call models or tools you configure. Those third parties process data under their own terms and privacy policies.
- Grok / Grok Build — a bridge that you run or host. Prompts may be sent to xAI (or other providers the bridge is configured to use) under those providers’ terms and privacy policies.
- QeyeT infrastructure — transports encrypted envelopes between your authorized device and your bridge. QeyeT routing nodes do not hold the keys to read AI chat content.
Permission: Before connecting Hermes or Grok, the app explains what may be sent and to whom, and requires your active consent (checkbox). You can revoke that permission later in Settings → AI assistants. Disconnecting a bridge stops further pairing traffic to that bridge.
Only allowing AI features in a Terms of Service or Privacy Policy is not how QeyeT enables them — consent is obtained in the product before use.
Enterprise accounts
Enterprise administrators can process usernames, display names, membership status, directory visibility, spaces, enrollment events, client versions, and aggregate operational health for their tenant. They can reissue organizational access but cannot use that authority alone to decrypt an employee's local message vault.
Retention
Local content remains until you delete it, the browser removes site data, or a configured disappearing-message rule expires it. Encrypted queued envelopes are retained only within configured delivery and storage limits. Operational logs, abuse controls, aggregate metrics, push subscriptions, and enterprise administration records may be retained as needed to operate, secure, and troubleshoot the network.
Your choices
- Use a standard identity without providing a phone number or email address.
- Disable notifications and notification previews.
- Delete local messages, call logs, cached media, or all local application data.
- Export an encrypted backup manually.
- Disconnect linked devices and Hermes or Grok bridges.
- Revoke AI assistant data sharing in Settings (or never enable it).
- Ask an enterprise administrator to suspend or remove organizational membership.
Security and limitations
No security design eliminates compromised devices, malicious browser extensions, traffic analysis, software defects, or user disclosure of recovery material. Review the QEYET security architecture for current protections and assurance status.
Contact
Privacy questions can be sent to admin@qeyet.com. Do not send recovery words, private keys, or confidential message content by email.
Changes
This notice may change as QEYET adds providers, applications, or commercial services. Material changes will be reflected by a new effective date on this page.