Veil Privacy Policy
Effective date: 16 August 2026
Last updated: 27 September 2026
The short version
Veil is built so that we know as little about you as possible. We can't read your messages, we can't listen to your calls, and we don't know where you go. This policy explains exactly what we do and don't collect, in plain English, because you shouldn't need a law degree to understand what happens to your data.
If you only read one section, read "What we collect" and "What we never collect" below.
1. Who we are
Veil is made by Veil Technologies Ltd, a company registered in England and Wales.
- Company number: 17342128
- Registered office: 64 Kingsway, Coventry, CV2 4FE, United Kingdom
- ICO registration number: ZC206131 (registered 23 July 2026, expires 22 July 2027 — confirmed via the ICO's own Data Protection Registration Certificate and public-register entry, 2026-08-08)
- Contact for privacy questions: support@veilsuperapp.com
Veil Technologies Ltd is the "data controller" for the personal data described in this policy. That's the legal term for the organisation that decides how and why your data is used.
We have not appointed a formal Data Protection Officer because we are not legally required to have one at our current size and scale of processing. Privacy questions go directly to the team at the email above, and we will respond within one month as UK GDPR requires.
2. What we collect
We collect the minimum we need to make the app work. Here is the complete list.
Your account
- Nothing — no phone number, email address, or username. Your account is a randomly generated Veil ID, created entirely on your device using a cryptographically secure random generator. We never ask for, and have no way to link your account to, your real-world identity. Contacts find you by exchanging Veil IDs directly with you, not through any directory we hold.
- Your public encryption keys — these let other people send you messages only you can decrypt. Public keys are, by design, not secret.
- A hashed sign-in password and optional display name — your Veil ID is registered with us alongside a hashed password (we cannot read the password itself): a random one your device generates automatically, or one you choose yourself if you set up recovery so you can restore your account on another device. If you enter an optional display name, that is stored with your Veil ID too.
- Basic account records — when the account was created and when it last connected. We use this to run the service and to delete abandoned accounts (see "How long we keep data").
- Your saved contacts list — the Veil IDs of the people you add and the names you give them are stored on our server so they stay with your account. Pending contact requests pass through our server too, holding the two Veil IDs until the request is accepted, declined, or expires after 24 hours. We still never read your phone's address book.
Why we're allowed to: this is necessary to perform our contract with you — you can't have a messaging account without an account. (Legal basis: UK GDPR Article 6(1)(b), contract.)
Messaging
Your messages are end-to-end encrypted. That means they are scrambled on your device and can only be unscrambled on the recipient's device. We do not have the keys. We cannot read your messages, and neither can anyone who compromises our servers.
To deliver messages, our servers briefly handle:
- Encrypted message payloads in transit — held until delivered to the recipient's device. If a recipient is offline, the encrypted message stays queued on our server for as long as it takes to deliver it — verified directly against our live server's own configuration (2026-08-15): no fixed expiry is set, matching the messaging protocol's own default behaviour of retaining undelivered messages indefinitely rather than discarding them after a fixed window. The message is still always encrypted end-to-end while queued — we cannot read it regardless of how long it waits.
- Routing information — enough to know which account a message should be delivered to. Our own app code does not log who messaged whom, and we don't build a social graph from it. Being precise about the one place this isn't the whole story: the messaging server's own access logs do not record your source IP address. Those logs are hard-capped and auto-rotating, never kept indefinitely.
Why we're allowed to: necessary to perform our contract with you (Article 6(1)(b)).
Voice and video calls
Calls use WebRTC and are end-to-end encrypted. Where possible, calls connect directly between your device and the other person's device, and no call data touches our servers at all.
When a direct connection isn't possible (for example, because of restrictive network firewalls), calls are relayed through our TURN servers. Relayed call data is still encrypted — the relay server passes it along without being able to decrypt it — and is not recorded or stored.
To set up a call, our signalling servers momentarily process the IP addresses of both participants. This is technically unavoidable: devices can't connect to each other without knowing where to send data. We do not log call metadata (who called whom, when, or for how long) on our own signalling servers. When a call can't connect directly and has to relay through our TURN provider (Metered.ca) — the minority of calls where a direct connection isn't possible — they've confirmed directly that call media itself is never stored, logged, or inspected. For those relayed calls, they do retain some connection-level metadata (the relaying device's own IP address, transport type, session timing, and total data relayed) tied to our account, for as long as we have an account with them, and this isn't currently something we can turn off or configure. This is standard practice for TURN relay providers generally, not unique to Veil, and never includes the call's actual content or the other participant's IP address.
Why we're allowed to: necessary to perform our contract with you (Article 6(1)(b)).
Maps and navigation
Route calculation and turn-by-turn guidance run on your device once a route is fetched — we don't compute your navigation on our servers. Our own servers never receive or store your location, routes, searches, or destinations — verified directly: no coordinate ever appears anywhere in our backend code or storage.
That's a narrower claim than "your location never leaves your device," and we want to be precise about the difference. Three things happen directly between your device and named third parties, not through us:
- Map tiles and route directions go directly to Stadia Maps, a mapping data provider — necessarily including your device's IP address and the coordinates of what you're viewing or the start/end points of a route you're planning.
- Weather personalisation on your Home screen sends your device's coordinates directly to OpenStreetMap's Nominatim service (to resolve your city) and Open-Meteo (for the forecast itself).
We chose this design specifically so that Veil's own infrastructure has nothing to compromise, subpoena, or leak on this data — but it does mean these two named providers see raw coordinates directly, on the open internet, exactly like they would for any app using their services. If that distinction matters to you, it's worth knowing plainly rather than assumed away.
Why we're allowed to: necessary to perform our contract with you (Article 6(1)(b)).
AI Assistant
When you use Veil's AI Assistant, your message — along with a small amount of context that lets the assistant answer helpfully, described below — is sent to Anthropic, the company behind the Claude model that generates the response, via a Veil-operated relay. Your Veil ID itself is never included, and Anthropic has no way to link separate conversations back to the same person from that alone — but the context described below does travel with your message each time, so this is not full message-content isolation.
Separately from what Anthropic sees, Veil's own infrastructure saves your conversation transcript, tied to your Veil ID, so the assistant can remember context across sessions instead of starting fresh every time — a deliberate trade-off between continuity and full statelessness. You can permanently delete this at any time ("New session"), and it's capped and auto-deleted regardless (the most recent 60 messages, expiring after 90 days). The assistant may also remember a small set of durable facts about you across sessions (your name, a stated preference) — individually visible and deletable, same 90-day expiry, and included in the context sent to Anthropic on later turns so it can actually use what it remembers.
If you've already granted Veil location access elsewhere in the app, the assistant can use your device's current resolved weather (a temperature, condition, and city-level label only — never your exact coordinates) to answer questions about it, and it can read your existing Tasks and Calendar events (including event locations) to answer questions like "what have I got tomorrow" — this weather, task, and calendar context, along with short previews of any Notes you've attached to something, is included in what's sent to Anthropic for that turn so the assistant can actually use it. It can propose creating a Task, a Calendar event, or a Note, or attaching one to something you already have — but it never saves anything without your explicit confirmation first.
Notes you ask the assistant to create are the one exception to server-side storage above — they're kept only on your device, never uploaded, a deliberately stronger privacy tier than the conversation transcript itself.
Why we're allowed to: necessary to perform our contract with you — providing the AI Assistant feature you've chosen to use (Article 6(1)(b)).
Veil Mail
Veil Mail is the mailbox built into the Veil app. It is the same service described in the Veil SuperMail privacy policy at veilsupermail.com/privacy.
- Your mailbox. A Veil mailbox address at veilsupermail.com is created for you automatically and is linked to your Veil ID. We store the mailbox account and the sign-in credentials needed to give you access to it.
- Your public encryption key. Registered so other Veil users can encrypt mail to you. Public keys are, by design, not secret.
- Your messages. Mail you send and receive is stored on our own mail server (self-hosted Stalwart mail software, on a Vultr server in London). We do not use a third-party mailbox provider.
- Message details the server needs to deliver mail. The sender, recipients, subject and date of a message are visible to our mail server so it can deliver and file it; encryption protects the message body, not these details.
How your mail is protected:
- Between Veil users: the message is encrypted on the sender's device before it leaves it, so our servers hold only the encrypted body.
- Mail arriving from outside Veil: our mail server receives it in ordinary readable form for the moment it takes to deliver it. If you have a registered encryption key, it is encrypted on arrival, before it is stored. If no key is registered for the recipient, it is stored without that encryption — we do not describe inbound outside mail as universally encrypted.
- Mail sent to people outside Veil travels over the ordinary email network. It is protected in transit by TLS where the other provider supports it, but it is not end-to-end encrypted by default.
Why we're allowed to: necessary to provide the mailbox you have chosen to use (Article 6(1)(b)).
Shopping and commerce
When you place an order through Veil Shopping, the delivery address and contact details you enter are used solely to fulfil that specific order — never saved to your Veil profile or reused for a future order without you typing it again. To actually deliver your order, we share what's necessary (your delivery address, and your order contents) with the supplier fulfilling that specific product — this is unavoidable for any physical delivery, by us or anyone else. Payment is processed via Stripe for card payments; VLT Token payments are handled entirely within Veil's own ledger and never leave our infrastructure.
Why we're allowed to: necessary to perform our contract with you — fulfilling the order you placed (Article 6(1)(b)).
VPN (invitation-only beta)
Our VPN is a real, live feature — four server locations (London, Amsterdam, Frankfurt, New York), genuine WireGuard encryption, physically verified: correct exit location and IP for every server, DNS requests confirmed routing through the tunnel with no leak to your normal network, and switching servers or networks confirmed working mid-connection.
- We do not record the websites you visit, the services you connect to, your DNS queries, or your traffic content in our VPN database. Your traffic is encrypted between your device and the VPN server, but the server has to decrypt it to pass it on to the internet, so as with any VPN it can technically see where your traffic is going while you are connected.
- Being precise about what we haven't yet verified: we have not audited our own VPN servers' connection-level logging (e.g. whether raw connection metadata is written to any system log) via direct inspection — a genuine, disclosed open item, not assumed clean.
- What the VPN does record. Veil's VPN links your Veil ID and device to the server region you connect through, and keeps: your device's public key (the private key stays on your device and is never sent to us), the internal tunnel address assigned to your device, when you were last connected, connection-health information (whether the tunnel is working, how recently it exchanged data, how long connecting took, and any error code), and the total data sent and received each month. When your device asks to connect, or is refused, our provisioning service writes the request's identifiers to its logs: your Veil ID, your device identifier, the server chosen (and any server that previously failed), and a random connection-request identifier.
- To operate the VPN we necessarily process your IP address for the duration of your connection, because that's how the internet works, and the server you connect through can see the network address your connection comes from while you are connected. We have not yet independently verified how long our server logs and infrastructure logs are retained — a genuine, disclosed open item.
- One further honest limitation: if the VPN tunnel itself were to fail while connected, your device currently falls back to your normal, unprotected connection rather than blocking traffic outright — a deliberate reliability choice made while multi-server switching was being hardened, not yet revisited now that switching is verified stable.
- We also keep aggregate, non-identifying capacity data (e.g. total bandwidth per server) to keep the service running.
Why we're allowed to: necessary to perform our contract with you (Article 6(1)(b)).
Crash reports and diagnostics
We do not collect crash reports or analytics automatically. (The one exception is the VPN's own connection-health information described in the VPN section above, which is sent only while you use the VPN.) If the app crashes, iOS may ask you whether to share a crash report with Apple and with us, under Apple's own consent flow. Anything you choose to send us is used only to fix bugs. Confirmed accurate against the app's own code: no crash-reporting or analytics SDK (Sentry, Crashlytics, Bugsnag, or similar) exists anywhere in this project.
Subscriptions
Veil itself is currently free to use — there's no subscription or premium tier, and we don't process any payment for using the app. (If you buy something through Veil Shopping, that's a separate transaction, covered under "Shopping and commerce" above — not a subscription to Veil itself.)
3. What we never collect
For clarity, here is what Veil does not do:
- We do not and cannot read your messages or listen to your calls.
- Our own servers never receive or store your location, routes, searches, or destinations — see "Maps and navigation" above for the precise, narrower distinction around map tiles and weather.
- We never ask for access to your contacts or address book, and have no mechanism to read or upload them even if we wanted to — confirmed directly: this app has no contact-discovery feature of any kind. Contacts are added by exchanging Veil IDs directly, person to person.
- We do not use advertising, ad trackers, or third-party analytics SDKs.
- We do not sell, rent, or trade personal data. Ever. To anyone.
- We do not build profiles of you or make automated decisions about you.
- We do not collect data "just in case it's useful later." If it's not on the list above, we don't collect it.
4. Who we share data with
We keep this list short on purpose.
- Infrastructure providers. Our servers run on Vultr (message routing, London) and Cloudflare (Workers, edge network). They host encrypted data and the operational data described above on our behalf, and may not use it for their own purposes. Cloudflare's own standing public Data Processing Addendum applies automatically to our use of their platform. Veil Technologies Ltd's data processing addendum with Vultr was signed on 18 August 2026.
- Apple and Expo. Push notifications are delivered through Apple's Push Notification service via Expo's push relay (both see that a notification was sent and to which device — that's unavoidable for how push delivery works on iOS). Notification payloads never contain message content: a message notification says only "You have a new message". It also carries the sender's Veil ID in data the app uses to open the right conversation; this is not shown to you. The message text is never transmitted to Apple or Expo at any point. Verified working end-to-end 2026-07-19. Apple's and Expo's handling of push traffic is covered by their own respective privacy policies.
- Nobody else. We do not share data with advertisers, data brokers, analytics companies, or "partners."
Legal requests
If we receive a legally binding order from a court or authority with jurisdiction over us, we can only hand over what we actually have — which, as described above, does not include message content, call content, or location data. We review every request for legal validity, push back on overbroad ones, and disclose the minimum required.
5. International transfers
Our own message-routing and mail servers (Vultr) are located in London, UK. Our edge/Workers infrastructure (Cloudflare), our AI Assistant processor (Anthropic), and our email-delivery processor (Postmark) operate outside the UK/EEA. Cloudflare and Postmark's own standing Data Processing Addenda and Standard Contractual Clauses apply automatically to our use of their services. Anthropic's own Commercial Terms — which apply automatically to any use of their API, including ours — incorporate their standard data processing and international-transfer terms; we use their standard first-party API directly, not through a reseller or region-specific routing.
Note that when you message someone, your encrypted message travels to wherever they are — that's the nature of communication and isn't a "transfer" by us.
6. How long we keep data
- Encrypted messages in transit: deleted on delivery. If a recipient is offline, an undelivered message stays queued, still fully encrypted, for as long as it takes to deliver — there's currently no fixed expiry that discards it first.
- Call data: never stored.
- Account data: kept while your account is active. If you delete your account, it is removed from our live service as part of the deletion itself — confirmed in our own deletion code, not a scheduled or delayed process — except where we must keep specific records to comply with law. Copies can remain in our backups for up to the period described under Backups below.
- Inactive accounts: we don't currently delete accounts automatically for inactivity — an account stays as described above until you delete it yourself. If we add automatic inactive-account deletion in future, this section will describe the real policy before it takes effect, not after.
- Veil Mail: there is no automatic time-based expiry of mail; Trash is not permanent deletion and permanent deletion happens when you trigger it; nightly snapshots of the mail server are kept for 14 nights (about two weeks), so permanently deleted mail can persist in a snapshot for up to that long.
- Backups: we operate two backup layers on our messaging server — automated full-server snapshots, and a separate nightly database backup retained for a firm 30 days before automatic deletion. These exist to protect against data loss (a server failure, not a way to recover an account you've chosen to delete), but they mean a deleted account's data can genuinely persist in a backup for up to that window before it's fully gone from every copy we hold, not just from the live service immediately.
7. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you (fair warning: it isn't much).
- Correct inaccurate data.
- Delete your data ("right to erasure") — you can also just delete your account in the app, which does the same thing.
- Restrict or object to processing in certain circumstances.
- Data portability — receive your account data in a machine-readable format.
- Withdraw consent at any time, where we rely on consent (currently: nothing — we don't collect crash reports/analytics automatically, so there's no standing consent-based processing to withdraw from).
To exercise any of these, email support@veilsuperapp.com. We'll respond within one month and won't charge you. We may need to verify you control the account — since we don't hold a phone number or email address to check against, this usually means confirming your Veil ID directly from the app itself.
You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO) — ico.org.uk, or 0303 123 1113. We'd appreciate the chance to sort it out first, but that's your call.
8. Children
Veil is not intended for children under 16, and you must be at least 16 to create an account. We do not knowingly collect data from children under this age; if you believe a child is using Veil, contact us and we will delete the account.
9. Security
Beyond end-to-end encryption, we protect data with encryption in transit (TLS) and at rest, access controls on our systems, and by the simplest security measure of all: not collecting data in the first place. No system is perfectly secure, but a breach of our servers would expose dramatically less about you than a breach of a typical app, because the sensitive things were never there.
If a breach ever affects your personal data in a way that puts you at risk, we will notify you and the ICO as UK GDPR requires (within 72 hours to the ICO where applicable).
10. Changes to this policy
If we change this policy, we'll update the date at the top and, for meaningful changes, notify you in the app before they take effect. We will never quietly weaken this policy. This is our first published version; if we publish future versions, previous ones will remain available at this same URL's own version history.
11. Contact
Questions, concerns, requests: support@veilsuperapp.com Post: Veil Technologies Ltd, 64 Kingsway, Coventry, CV2 4FE, United Kingdom