← Drdesh

Legal

Privacy Policy

Version 1.0 · Last updated 31 August 2026

Drdesh is a private messenger built so that we hold as little of your data as technically possible. This policy explains exactly what our servers store, what they can never see, whom we share data with (almost no one), and the rights you have. It is written to match how the service actually works — nothing here is aspirational.

The short version

What we store

To run the service, our servers keep this account data:

What we never store

What we can observe anyway (metadata honesty)

Running a delivery service means some metadata necessarily passes through us: the server knows when your device is online, which accounts exchange (encrypted) traffic and roughly how much, and the sizes and timing of encrypted media transfers. We minimize this — queue rows die on delivery, typing and presence signals are relayed and never stored, and presence is only visible to connections you have accepted — but we would rather tell you it exists than pretend otherwise.

Who can see what

Service providers

We use a small number of infrastructure providers, each of which sees only what its job requires:

We do not sell, rent, or share your data with anyone else. We have no advertising or data partnerships.

Abuse reports

End-to-end encryption means we cannot moderate content we cannot see. Instead, when you report a conversation, your own device forwards the offending messages (a bounded, recent selection — never your whole history, never media files themselves) to our moderation queue, together with the reported account's @username. Report evidence is retained while the report is being handled and for as long as needed to enforce bans, and is never used for anything except trust & safety. Because evidence is forwarded by one participant, moderators treat it as a claim to be assessed, not as a verified transcript.

Retention

When you delete your account

Settings → Account → Delete account permanently removes your account row, devices, key material, connections, group memberships, queued messages, push tokens, and profile photo. This is immediate and irreversible — we cannot restore a deleted account, and your message history (which only ever existed on your devices) is not ours to return.

One thing survives deletion, and we want to be plain about it: if an account was banned for abuse, we keep a one-way cryptographic hash of its email address so the ban stays effective. The hash cannot be reversed into your address and is used for nothing except preventing banned users from re-registering. Evidence attached to abuse reports may also be retained as described above.

Your rights

If you are in the EU/EEA or UK, the GDPR (and equivalents) grant you rights of access, rectification, erasure, restriction, portability, and objection. Drdesh is built so you can exercise the important ones yourself, instantly, in the app:

You also have the right to complain to your local data-protection authority. For anything you cannot do in-app, email us — we answer identity-verified requests within 30 days.

Children

Drdesh is not for children under 13 (or the higher minimum age your country sets for consenting to data processing — 16 in parts of the EU). We do not knowingly collect data from children below that age; if you believe a child is using Drdesh, contact us and we will delete the account.

Changes to this policy

If we change this policy in any meaningful way, we will notify you in the app before the change takes effect and keep prior versions available on request. The "Last updated" date above always reflects the current version.

Contact

Data controller: the Drdesh operator (full legal entity details will be listed here at launch).
Privacy contact: [email protected]