Privacy Policy
Effective 3 October 2026 · Applies to the Sendant apps for Android (io.sendant) and iPhone, to the Sendant web client, and to the sendant.io website.
Sendant is a private, end-to-end encrypted messenger. The short version: your messages belong to you. They are encrypted on your device, your keys never leave it, and our infrastructure only ever handles content it cannot read. We don't ask for your phone number, and there are no analytics in the apps. Our website counts visits from server logs that never record your IP address.
1. Who we are
Sendant is operated by VectraSEO LLC ("VectraSEO", "we", "us"), which is the developer of record on the App Store and Google Play and the controller of the limited personal data described below. Sendant is built by Yoni Ryabinski (yoniryabinski.com).
| Controller | VectraSEO LLC |
| Postal address | VectraSEO, 243 E 5th Ave #A135, Anchorage, AK 99501, USA |
| Privacy contact | privacy@sendant.io |
| Telephone | (908) 628-9057 |
Email is the fastest way to reach a person, and every address on this page is read by a human rather than an automated system. See section 13 for the contact points we are required to publish for EU and EEA users.
2. Information we do not collect
- No phone number. Sendant does not require or collect a phone number to create an identity.
- No account, email, or password. Your identity is a cryptographic key generated and stored on your device.
- No advertising identifiers and no ads. Sendant contains no third-party advertising and no ad SDKs.
- No analytics in the apps and no behavioral tracking anywhere. The apps ship with no analytics SDK and no crash-reporting SDK of any kind. The website sets no cookies and loads no analytics or advertising scripts; the only traffic information it keeps is the IP-free request log described in section 4. We do not profile you, and we do not sell data, targeting, or behavioral analytics.
- No location data. Sendant never requests or receives your device location. On iPhone you may see a location permission string listed in the App Store privacy details: it exists only because a bundled camera library links against a location API, and Sendant does not call it. The app has no location permission on Android at all.
- No address book upload. Sendant does not request your device contacts or upload an address book.
3. Information that exists on your device
The following stays local to your device and is not transmitted to us in readable form:
- Your cryptographic identity and keys. On iPhone these are held in the iOS Keychain, and on Android in the Android Keystore — in both cases hardware-backed, marked non-syncable, and therefore excluded from iCloud and Google cloud backups. In the web client, keys are stored locally by your browser, which is a weaker store than either platform keychain; we say so plainly rather than imply otherwise, and stronger at-rest protection for the web client is on our roadmap.
- Your message history and attachments — stored locally on your device, encrypted at rest with a key held in the platform keychain.
- A profile name you optionally enter — a local label; you are not required to provide your real name.
Deleting your Sendant data, or uninstalling the app, removes these local databases from your device. Step-by-step instructions for iPhone, Android, and the browser are on our data deletion page.
Device permissions
Sendant requests only feature-specific permissions when needed: camera access to scan invite or verification QR codes, microphone/audio access for voice messages and calls, network access to send and receive encrypted messages, and notification permission so your device can show a local alert after it receives a content-free wake signal. These permissions are not used for advertising, profiling, or contact discovery.
Linked devices
You can link a browser to the identity on your phone, so the same conversations appear in both places. What that means for your data:
- Your root identity key never leaves your phone. The linked browser generates its own separate keypair and receives a certificate signed by your phone. It cannot link further devices, and it cannot revoke any.
- A linked browser is a second copy of your conversations, held in browser storage, which — as noted above — is a weaker store than the Keychain or Keystore. Link only browsers on devices you control.
- Linking adds a mailbox. Each linked device has its own mailbox slot, so a message sent to you is sealed separately for each of your active devices. Our infrastructure can see that an identity has more than one device; it still cannot read anything sealed to any of them.
- Recent history is copied at pairing — roughly the last 30 days — over an encrypted channel between your own devices. Nothing in that transfer is readable by us.
- Links expire and can be revoked. A linked browser unlinks itself after 30 days without connecting, and you can revoke it at any time from your phone. Revocation is broadcast to your contacts over encrypted channels rather than enforced by a server, so a contact whose app has not yet received the update may still reach a revoked browser until the certificate expires. We would rather state that limit than promise instant revocation we cannot deliver.
4. Information that passes through our infrastructure
To deliver messages when your contact is offline, Sendant uses a store-and-forward "mailbox" and relay infrastructure. What that infrastructure sees:
| Data | What we can see | Retention |
|---|---|---|
| Message & attachment content | Opaque ciphertext only. Messages are end-to-end encrypted; we cannot read, search, or decrypt them. | Held only until delivered, and auto-expires (currently up to 30 days), then deleted. |
| Delivery/routing data | The minimum needed to route an encrypted envelope to its mailbox. Sealed-sender techniques minimize sender metadata. | Transient; not used for profiling or advertising. |
| Network connection data | Standard connection metadata (e.g. IP address) inherent to any internet service, used to operate and protect the service. | Not used to build a profile of you. |
| Push token | A Firebase Cloud Messaging device token tied to your mobile device so the mailbox can send content-free wake pushes. The web client has no push and receives nothing of the kind. | Kept while notifications are enabled for that device, then replaced or removed when the token rotates or notifications are disabled. |
All communication with our infrastructure is encrypted in transit (TLS), and the app does not permit cleartext network traffic: on Android this is enforced by a network security configuration that denies cleartext outside of developer loopback addresses, and on iPhone by App Transport Security, which the app does not disable.
Push notifications. Sendant uses Firebase Cloud Messaging (FCM) to wake the app when you have mail. On iPhone, FCM delivers through Apple Push Notification service (APNs), so Apple as well as Google is in that path; on Android it is Google alone. These push messages are data-only and contain no message content — just a signal to fetch; the app then retrieves and decrypts your messages locally. Google, and on iPhone Apple, can see that your device received a wake signal and when, but not who messaged you or what they said. The web client does not use push at all.
Visits to the sendant.io website
When you load a page on sendant.io, our content delivery network (Amazon CloudFront) writes a request log. We have configured it to leave out your IP address and any cookies. Each entry holds only: the time, the page address (including any query string), the response status, the referring page, your browser's user-agent string, the country the request came from (derived by the network, not stored as an IP), and whether it was served from cache.
- Why: to keep the site working and to understand, in aggregate, which pages people read and how they find us (for example, from a search engine, a link, or an AI assistant).
- How long: the request log is deleted automatically after 30 days.
- What we derive from it: once a day we reduce the log to daily totals per
page — referring site (domain only), campaign tags (
utm_source,utm_medium,utm_campaign), country, response status, and a broad visitor type such as “browser: Safari” or “search crawler”. Any combination seen fewer than three times is merged into “other”. Every other query parameter, the full user-agent string, and the full referring address are discarded. These totals cannot be tied to you. - Where the totals go: to VectraSEO, our own search-visibility service, operated by VectraSEO LLC, the same company that runs Sendant. Only the aggregated totals are sent; the request log itself stays in our cloud account.
This applies to the website only. Nothing in the Sendant apps or the web client reports usage to us or to VectraSEO.
5. Diagnostics
Sendant does not collect crash or diagnostic telemetry, and the apps currently ship with no analytics or crash-reporting SDKs. If we ever add optional diagnostics, they will be off by default, scrubbed of message content before anything is sent, and used only to fix bugs and improve reliability — never for advertising or profiling.
6. How we use information, and our legal bases
We use the limited data above only to: deliver your encrypted messages, operate and secure the service, respond to abuse reports, and meet legal obligations. We do not sell your data, we do not share it for cross-context behavioral advertising, and we do not share message content with third parties — we cannot, because it is encrypted.
If the GDPR or UK GDPR applies to you, these are the legal bases we rely on:
| Purpose | Data | Legal basis |
|---|---|---|
| Delivering your messages | Encrypted envelopes, routing data | Performance of a contract (Art. 6(1)(b)) |
| Waking your device for new mail | Push token | Performance of a contract (Art. 6(1)(b)) |
| Keeping the service up and defending it from abuse | Connection metadata, abuse reports | Legitimate interests (Art. 6(1)(f)) — operating a safe, available service |
| Understanding how people find and use the website | IP-free website request logs, then aggregated daily totals | Legitimate interests (Art. 6(1)(f)) — knowing which pages are read and where visitors come from, with no IP address or cookie recorded |
| Acting on a report you send us | Whatever you choose to include in the report | Consent (Art. 6(1)(a)) — the message attachment is opt-in and never sent without it |
| Responding to valid legal process | The limited data we hold | Legal obligation (Art. 6(1)(c)) |
We do not use your data for automated decision-making that produces legal or similarly significant effects about you.
7. Sharing, international transfers, and legal requests
Because message content is end-to-end encrypted and only transient ciphertext passes through our infrastructure, we have no plaintext messages to disclose. If compelled by valid legal process, we can only provide the limited data we actually hold, which by design excludes the content of your conversations.
We use a small number of service providers to run Sendant: cloud hosting for the mailbox, relay, and website; and Google (with Apple, on iPhone) for content-free wake notifications. They act on our instructions and receive no message content. Aggregated website visit totals (section 4) go to our own VectraSEO service; they identify no one.
International transfers. VectraSEO LLC is in the United States, and our infrastructure is operated from the United States. If you use Sendant from the EEA, the UK, or Switzerland, the limited personal data described in section 4 is transferred to the United States. Where a transfer mechanism is required, we rely on the European Commission's Standard Contractual Clauses, together with the fact that the material we handle is end-to-end encrypted ciphertext we cannot read — which is the strongest supplementary measure available.
8. Your choices and rights
Depending on where you live, you may have some or all of the rights below. We honour them for every user, wherever you are, to the extent we can act on them:
- Access and portability — a copy of the personal data we hold about you. In practice this is close to nothing, because we hold no account and no readable content.
- Correction — correction of inaccurate personal data.
- Deletion — deleting your Sendant data on your device removes it; undelivered envelopes on the mailbox auto-expire. For anything else, email privacy@sendant.io. See the data deletion page for per-platform steps.
- Objection and restriction — you may object to processing based on our legitimate interests, or ask us to restrict it.
- Withdrawal of consent — where we rely on consent, you may withdraw it at any time, without affecting what we did before you withdrew it.
- No sale, no sharing, no targeted advertising — there is nothing to opt out of, because we do none of them. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we have not done so in the preceding twelve months, including for consumers we know to be under 16.
- No discrimination — we will not treat you differently for exercising any of these rights.
To exercise a right, email privacy@sendant.io. We answer within 30 days, and will tell you if we need longer. Because Sendant has no account, we may be unable to connect a request to any particular data — if we cannot verify that data relates to you, we will say so rather than hand it to someone else. You may use an authorised agent, and we may ask that agent for proof of authority.
If you are in the EEA or the UK you may also complain to your local supervisory authority; in the UK that is the Information Commissioner's Office. We would rather you came to us first.
9. Children
Sendant is rated 18+ and is intended solely for adults. It is not directed to children, we do not knowingly permit anyone under 18 to use it, and we do not knowingly collect personal information from anyone under 18. If we learn that a user is under 18 we will terminate their access. If you believe a child is using Sendant, email privacy@sendant.io.
10. How long we keep things
Undelivered encrypted envelopes expire automatically, currently after at most 30 days, and are deleted sooner once delivered. Push tokens are kept while notifications are enabled for that device. Connection metadata is transient and operational. Website request logs are deleted after 30 days; the aggregated daily totals derived from them identify no one and may be kept. Abuse reports and the correspondence around them are kept only as long as needed to act on them and to defend against repeat abuse. Everything else lives on your device, where you control it.
11. Security
Messages are end-to-end encrypted with X3DH key agreement and the Double Ratchet, local storage is encrypted at rest under a key held in the platform keychain, and you can compare a safety number with a contact to verify that no one is in the middle. No service can guarantee perfect security. If you find a vulnerability, please tell us at privacy@sendant.io; see our security page for details.
12. Changes
If we change this policy we will update the effective date above and, for material changes, surface a notice in the app or on this page.
13. Contact points for EU and EEA users
Under the EU Digital Services Act we publish a single point of contact for both users and authorities. There is only one, and it reaches a person:
| Point of contact for recipients of the service (Art. 12) | hello@sendant.io — read by a person, not solely by automated tools. You may write to us in English. |
| Point of contact for authorities (Art. 11) | privacy@sendant.io, or by post to VectraSEO, 243 E 5th Ave #A135, Anchorage, AK 99501, USA. Communications in English. |
| Trader | VectraSEO LLC, at the address above, telephone (908) 628-9057. |
Our content rules, the controls you have, and what happens when you report someone are set out in plain language in sections 4, 6 and 19 of the Terms of Use.
Questions about your privacy? Email privacy@sendant.io.