Enzypher
Privacy Policy
Last updated: June 18, 2026
This policy explains how Enzypher collects, uses, stores, and shares information, including information received when users authenticate with Google.
1. What Enzypher is
Enzypher is a private messaging application available at https://enzypher.app. The app lets users create profiles, connect with friends, create direct or group conversations, send messages and media, and switch conversations between encrypted-looking and authorized-readable interface states.
True end-to-end encryption and true local-only authorization are planned security upgrades. The current product should be treated as a privacy-focused messaging experience with encryption/decryption states, access controls, and server-side protections, not as a finalized zero-knowledge or audited E2EE system.
2. Account and profile data we collect
We collect account data needed to create and operate your Enzypher account, including your email address, display name, username, profile image, authentication identifiers, and profile setup fields such as public key and local authorization-related credentials.
We also store relationship and messaging data needed for the product to work, including friend requests, conversation membership, group roles, message status, unread counts, timestamps, last seen/presence information, dialog previews, uploaded media references, and settings.
3. Google Sign-In data
If you sign up or sign in with Google, Enzypher uses Google OAuth only for authentication and account setup. We may receive your Google account identifier, email address, name, profile image, and authentication tokens/session information required to sign you in through our authentication provider.
We do not request access to Gmail, Google Drive, Google Calendar, Google Contacts, or other sensitive Google account content. We use the minimum Google permissions needed for sign-in.
We use Google user data to authenticate you, create or locate your Enzypher account, help prefill profile setup where available, secure your session, and route incomplete profiles to the finish-setup flow.
4. How we use data
We use your data to provide messaging, authentication, profile setup, friend discovery, group membership, message delivery/read status, conversation recovery, media display, account settings, security controls, and support.
We may use operational data to debug, protect, and improve Enzypher. We do not sell your Google user data, message content, profile data, or friend/conversation data.
5. Storage, processors, and sharing
Enzypher uses service providers such as Supabase for authentication, database, storage, and realtime infrastructure, and hosting/CDN providers for application delivery. These providers process data only as needed to operate Enzypher.
We may share data when required by law, to protect users or the service, to prevent abuse, or as part of a business transfer. We do not share Google user data with third parties for advertising, surveillance, or unrelated analytics.
6. Messages, media, and privacy states
Messages and media may be stored with related metadata such as sender, conversation, timestamps, delivery/read state, reply references, and media URLs. Some user-facing text and names may appear encrypted or decrypted depending on app mode and authorization state.
Because the product is still evolving toward true E2EE, do not use Enzypher as the only place to send emergency, legally privileged, medical, financial, or other information that requires audited security guarantees.
7. Cookies and sessions
We use cookies, local storage, and authentication session mechanisms to keep you signed in, protect requests, remember app state, and support realtime functionality. Third-party authentication providers such as Google and infrastructure providers may set their own security cookies during authentication or asset delivery.
8. Your choices and rights
You can update your profile and settings inside Enzypher. You may also contact us to request access, correction, deletion, or export of account information, subject to technical, legal, and abuse-prevention limits.
If you used Google Sign-In, you can revoke Enzypher's access from your Google Account permissions page. Revoking Google access may prevent Google-based sign-in until you reconnect.
9. Security
We use access controls, authentication, row-level database protections, HTTPS, and infrastructure security features to protect the service. No online service can guarantee perfect security, and the current encryption model is not yet a final audited E2EE release.
10. Children
Enzypher is not directed to children under 13. If you believe a child has provided personal information to Enzypher, contact us so we can review and remove it where appropriate.
11. Changes
We may update this Privacy Policy as Enzypher changes. If we materially change how we use Google user data or other personal information, we will update this page and, where appropriate, ask for consent before using data in a new way.
12. Contact
Questions, privacy requests, and Google OAuth concerns can be sent to support@enzypher.app.
