Privacy Policy
Last Updated: March 2026
1. What We Collect
Xent is designed with data minimization as a core principle. We collect only the minimum information necessary to provide our services:
- Encrypted identity (DID): Generated on your device, we store only the public identifier
- Relay metadata: Temporary routing information needed to deliver encrypted messages, deleted after delivery
- No phone numbers, no email addresses, no contact lists, no message content
2. What We Do NOT Collect
- Message content: All messages are end-to-end encrypted; we cannot read them
- Contact lists or social graphs
- Location data
- Device identifiers beyond what's needed for push notifications
- Financial data, wallet addresses, or transaction details
- Biometric data
3. Encryption & Data Processing
All communications are encrypted end-to-end on your device before transmission. Our servers process only encrypted blobs. We employ forward secrecy to ensure past sessions remain secure. Stealth mode and timed destruction provide physical-level data elimination.
4. Your Rights
- Right to access: Request a copy of your data (note: we hold minimal data)
- Right to deletion: Request deletion of your account and associated data
- Right to portability: Export your data in a standard format
- Right to withdraw consent: You may stop using the service at any time
To exercise these rights, contact us at privacy@xent.app.
5. Data Retention
We retain the minimum data necessary for service operation. Encrypted relay metadata is deleted within 24 hours of message delivery. Account data is deleted upon account termination. Stealth mode messages are physically destroyed on schedule.
6. Third Parties
We do not sell, trade, or share your personal information with third parties. We do not use third-party analytics that track individual users. Infrastructure providers process only encrypted data.