Decove Privacy Terms EULA Support

Privacy Policy

Last updated: 7 September 2026

Decove is a private, end-to-end-encrypted social network. This policy explains what data the service processes, why, and what happens to it. It is written to be read, and it is deliberately specific: because of how Decove is built, we can tell you not only what we do with your data, but what we are unable to do with it.

1. Who is responsible

The data controller is Edoardo Sorrenti, Viale dell'Arte 46, 00144 Roma, Italy (“we”, “us”). For anything in this policy, including exercising your rights: privacy@decove.app.

2. The short version

The content you share on Decove — posts, comments, direct messages, photos, voice recordings — is end-to-end encrypted. We cannot read it. That is not a policy we promise to follow; it is a property of the system: the keys needed to decrypt your content exist only on your and your friends’ devices and are never sent to us. What our servers store is ciphertext.

End-to-end encryption protects content, not context. Like any service that delivers messages, we necessarily see some routing information: who your friends are, who a post was addressed to, and when things happen. This policy lists all of it — the table below is complete.

We show no ads, run no analytics or tracking SDKs, set no cookies, and sell nothing about you to anyone. We do count how much the service is used — totals with nobody’s name in them, listed in section 3 and gathered by our own servers from the requests they already answer, never by anything running on your phone. The app never contacts third-party servers except the three processors listed in section 5, and even its fonts are bundled rather than fetched.

3. What we process, why, and for how long

DataWhat we actually holdPurpose & legal basisKept until
Phone number A keyed one-way code (HMAC) of your number, used to recognise it at sign-in. Your raw number is processed transiently when we send you a login code, and is disclosed to our SMS provider for delivery. Sign-in and account identity — performance of our contract with you (Art. 6(1)(b) GDPR). Account deletion.
Login codes (OTP) A hash of the six-digit code, never the code itself. Sign-in security — contract. Minutes: codes expire after 10 minutes or on first use.
Display name and profile photo Stored readable on our servers — deliberately not end-to-end encrypted, so that friend requests and notifications can show who is asking. This is the one category of your profile we can see. Letting friends recognise you — contract. Both are optional. Account deletion, or until you change them.
Your content (posts, comments, direct messages, photos, voice) Ciphertext only. Encrypted on your device (XChaCha20-Poly1305, with keys agreed via X25519); we never receive a decryption key. Storing and delivering what you share — contract. Until you delete the item or the account. Deleting a post removes its ciphertext for every recipient.
Social metadata Your friend list, pending friend requests, the recipient list of each post (who was issued a wrapped key), who a post tags and who accepted a tag, and timestamps. This is the routing information delivery and notifications require, and we can see it. Declining a tag sends us nothing, so we hold no record of declines. Delivering content to the people you chose; preventing abuse — contract and our legitimate interest in running the service securely (Art. 6(1)(f)). Account deletion (friendships and requests in both directions are removed).
Contact discovery (optional) Your address book is read on your device only and never uploaded. Numbers are cryptographically blinded on the device; our server applies a secret key to the blinded values and cannot recover the numbers, nor learn which of your contacts matched. We store one uninvertible pseudonym of your own verified number so friends who already know it can find you. Finding friends who already use Decove — your consent (Art. 6(1)(a)), given via the contacts permission and withdrawable by revoking it. The pseudonym: account deletion. Blinded query values: processed transiently, not stored.
Push notification token The device token issued by Apple or Google, tied to your account, and whether that device asked for notifications that show no names. Waking your device when a message arrives — contract. Sign-out, account deletion, or when the platform reports it dead.
Device-transfer relays When you move your account to a new phone by QR, your account key crosses our server once as a sealed message only the new device can open. Device transfer — contract. Single use; expires within about two minutes regardless.
Operational logs Minimal server logs (request paths, timings, error events). IP addresses appear only in security events such as rate-limit triggers. Keeping the service running and abuse-resistant — legitimate interest. Short rotation; logs are not mined for anything else — the service statistics below are counted separately and never read back out of a log.
Service statistics Totals, and only totals. Daily counts of requests by route and outcome, and daily counts of how many accounts, friendships, posts and active users there are. None of these rows has a person in it: there is no account column, no IP address, and no record that any particular person did any particular thing. “How many people used Decove today” is answered from a mathematical sketch that holds counts rather than identities and is deleted within weeks, leaving only the number behind. We use no analytics service and nothing is collected from your phone to produce any of it. Knowing whether the service works and is being used — our legitimate interest in running it (Art. 6(1)(f)). Because these are aggregates about everyone rather than data about you, they are not linked to your account. Aggregate counts: about 13 months. The sketches behind the active-user figures: 35 days.

4. What we never have

For completeness, data we do not hold in readable form and cannot produce — for ourselves or anyone else, court order included, because we do not possess the keys: the content of any post, comment, message, photo, or voice recording; your address book; the names you give your circles (your private audiences); and the private keys of your account.

Where that line stops: we do store the recipient list of every post (section 3), so we can tell that a post went to some of your friends rather than to all of them, and which ones. Circles are private in the sense that we never learn what you call them — not in the sense that the people you share with are hidden from us.

A complete technical statement of what our servers can and cannot see is maintained in our engineering documentation and this policy tracks it.

5. Who else is involved

Three processors, no more:

Everything else runs on our own servers in the European Union. We use no analytics, advertising, or crash-reporting services — the usage totals in section 3 are counted by our own servers and shared with nobody.

6. Security

Content is encrypted on your device before it leaves and decrypted only on your friends’ devices, using audited primitives (libsodium: X25519 key agreement, XChaCha20-Poly1305 encryption). All traffic uses TLS. Phone numbers rest as keyed one-way codes, not raw numbers. The honest consequence of this design cuts both ways: a full breach of our servers would expose the metadata listed in section 3 — and could not expose your content, because the material needed to decrypt it is not there. No security is absolute; if a breach affects you, we will notify you and the supervisory authority as the law requires.

7. Your keys are yours — which has a consequence

Because we never hold your keys, we cannot recover your content for you. If you lose every signed-in device and every backup you made (recovery code, password manager entry, or a linked device), your content is permanently unreadable — by you, by us, by anyone. The app offers backup options under Profile → Backup; using at least one is strongly recommended.

8. Your rights

Under the GDPR you can ask us for access, rectification, erasure, restriction, portability of the data we hold about you, and you can object to processing based on legitimate interest. Write to privacy@decove.app; we answer within a month. Two Decove-specific notes:

You also have the right to complain to a supervisory authority — in Italy, the Garante per la Protezione dei Dati Personali (garanteprivacy.it), or the authority of your own country.

9. Children

Decove is not directed at children. You must be at least 14 to use it, or older where your country sets a higher age for consenting to data processing (16 in Germany and the Netherlands, 15 in France). We do not knowingly process children’s data; if you believe a child is using Decove, contact us and we will delete the account.

10. Changes

If we change this policy in any way that matters — a new processor, a new category of data, anything moving between encrypted and readable — we will say so in the app before the change takes effect, not after. The date at the top always reflects the current version.