Veil Messaging Privacy Policy
Effective date: 27 September 2026
Last updated: 27 September 2026
This policy covers the Veil Messaging app only. Veil's other products have their own policies. It is written from what the Veil Messaging app and its servers actually do today, and it says plainly where something is not yet verified.
The short version
Your messages are end-to-end encrypted: they are scrambled on your device and can only be unscrambled on the recipient's device. We cannot read them. To run the service we hold a random Veil ID for you, your saved contacts list, the encrypted messages waiting to be delivered, and the few records listed below. You can delete your account in the app at any time.
1. Who we are
Veil Messaging is made by Veil Technologies Ltd, a company registered in England and Wales.
- Company number: 17342128
- Registered office: 64 Kingsway, Coventry, CV2 4FE, United Kingdom
- ICO registration number: ZC206131
- Contact for privacy questions: support@veilsuperapp.com
Veil Technologies Ltd is the "data controller" for the personal data described in this policy.
2. What Veil Messaging collects
Your account
- No sign-up details. There is no email address, phone number or username. On first use the app creates a random Veil ID on your device. Veil does not require you to provide your real-world identity. A Veil ID is generated randomly and is not, by itself, a real-world identifier.
- A hashed sign-in password. Your Veil ID is registered with us alongside a random password your device generates automatically. We store only a hash of it and cannot read the password itself.
- Your public encryption keys. These let other people send you messages only you can decrypt. Public keys are, by design, not secret. Your private keys stay on your device.
- Basic account records: when the account was created and when it last connected.
- Any display name you set in the app is stored only on your device.
Your contacts
- Your saved contacts list is stored on our server so it stays with your account: the Veil IDs of the people you add, and the names you give them.
- Contact requests pass through our server: a pending request holds the sender's and recipient's Veil IDs until it is accepted or declined, or expires after 24 hours.
- We never ask for access to your phone's address book and have no way to read it. People find each other only by exchanging Veil IDs directly.
Your messages
- Encrypted message payloads. Messages are delivered through Veil's own messaging server (Matrix, hosted on Vultr in London). The server holds each message only in encrypted form. If the recipient is offline, the encrypted message stays queued until it can be delivered; there is currently no fixed expiry.
- Routing information: enough to know which account a message is for, and when it was sent. Our own code does not log who messaged whom, and the messaging server's access logs do not record your IP address. Those logs are size-capped and rotate automatically.
- Blocking. If you block someone, the fact that you have blocked that Veil ID is stored with your messaging account so their messages are not delivered to you.
- Notifications. The app currently shows new-message alerts only while it is open, and an alert never contains message content. It does not use push notifications today; if that changes, this policy will be updated first.
Reports
If you report someone, we receive your Veil ID, the Veil ID you reported, the category you chose and any note you write. Reports go to our moderation inbox by email. The app keeps no copy of decrypted messages, so no message content is attached.
Why we're allowed to: necessary to provide the messaging service you have chosen to use (UK GDPR Article 6(1)(b), contract). Handling reports is also in our legitimate interest in keeping the service safe (Article 6(1)(f)).
3. What we never do
- We do not and cannot read your messages.
- We do not use advertising, ad trackers or third-party analytics SDKs in Veil Messaging.
- We do not sell, rent or trade personal data.
- We do not build profiles of you or make automated decisions about you.
- We do not ask for access to your contacts, photos, location or microphone.
4. Who we share data with
- Infrastructure providers. Our messaging server runs on Vultr (London) and our account and contacts service runs on Cloudflare. They host the data described above on our behalf. Vultr's data processing addendum with Veil Technologies Ltd was signed on 18 August 2026, and Cloudflare's standing data processing addendum applies to our use of its platform.
- Apple. The app is distributed through Apple's TestFlight and App Store, under Apple's own privacy terms.
Nobody else. If we receive a legally binding order from a court or authority with jurisdiction over us, we can only hand over what we actually hold: the records listed in section 2, and messages only in their encrypted form.
5. How long we keep data
- Encrypted messages: held until delivered; undelivered messages stay queued, still encrypted, with no fixed expiry.
- Account, contacts and blocking records: kept while your account exists. When you delete your account in the app, these records are removed from our live service as part of the deletion. Copies can remain in our backups for up to 30 days (see Backups below).
- Backups: our messaging server has automated snapshots and a nightly database backup kept for 30 days, so data from a deleted account can persist in a backup for up to that window before it is gone from every copy.
6. Deleting your account
In the app, go to Settings and choose Delete account. This deletes your Veil ID, your contacts list and your messaging account. It is account-wide and cannot be undone. If any part of the deletion does not complete, contact support@veilsuperapp.com and we will finish it.
7. Your rights
Under UK GDPR you have the right to access, correct or delete your data, to restrict or object to processing, and to data portability. To exercise any of these, email support@veilsuperapp.com. We will respond within one month and will not charge you. Because we hold no name or email address for you, we may ask you to confirm your Veil ID from within the app. You may also complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113).
8. Children
Veil Messaging is not intended for children under 16.
9. Changes to this policy
If we change this policy we will update the date at the top and, for meaningful changes, tell you in the app before they take effect.
10. Contact
Questions, concerns, requests: support@veilsuperapp.com
Post: Veil Technologies Ltd, 64 Kingsway, Coventry, CV2 4FE, United Kingdom