Signet

Privacy Policy

Last updated 10 July 2026 · Operator: the signets.social relay operator (contact in-app)

Draft — not legal advice. This describes what the software actually does, written from the code so it is honest (the project's #1 rule). A lawyer must review and adapt it for your jurisdiction before any public launch. Where the implementation has a known gap, it is stated plainly rather than hidden.

Summary

Signet is an end-to-end encrypted messenger. The content of your messages, calls, and attachments is encrypted on your device and can only be read by you and the people you talk to. The relay server cannot read message content. We collect no analytics, run no ads, and use no tracking SDKs. We keep the minimum metadata needed to deliver messages, and delete it on a short schedule.

What is end-to-end encrypted (the server never sees the plaintext)

What the relay server necessarily processes (metadata)

To route and deliver messages the server handles:

We do not collect: your contacts list (it stays on your device), message content, location, advertising identifiers, or behavioral analytics.

Push notifications (be aware)

The app prefers a persistent encrypted connection (no Google services) for delivery. The build may also include Google's Firebase Cloud Messaging library as an optional wake path; in the current build the FCM project is a placeholder and FCM is effectively inert. If a real FCM project is configured in a future build, a wake “ping” (carrying no message content) may transit Google's servers to wake the app. This will be disclosed and made opt-out at that time.

Retention & deletion

Your controls

Security verification

You can verify a contact's identity out-of-band via a safety number (derived on-device from both identity keys) or a QR scan. A changed safety number is flagged and clears any prior “verified” mark.

Government / legal requests

The operator can only provide what the server holds: account identifiers and limited routing metadata within its retention window. The operator cannot provide message, call, or attachment content because it is end-to-end encrypted and the server never has the keys. (Jurisdiction-specific transparency commitments to be added after legal review.)

Children

Not directed to children under the age required by your jurisdiction (commonly 13/16). (Adjust after legal review.)

Contact the operator

Signet has no support email: the relay does not run a mail server, and a published address would only invite spam to a project run by one person. Reach the operator inside the app instead — add the contact @signet and send a message. It travels end-to-end encrypted like any other, so a privacy question is not itself leaked to reach us.

If @signet is not yet resolvable in your build, the operator account is being provisioned; the handle on this page is the one to use once it is.

Changes

Material changes will be announced in-app and/or on the download page with an updated “last updated” date.

Signet · a no-Google, end-to-end encrypted messenger · signets.social