Privacy policy
Effective 4 August 2026. Plain language first.
Launch notice: ENDL3SS is still in development. The operator's legal name, postal address, final subprocessors, exact retention periods, and supervisory authority must be published before public registration opens.
Who controls your data
ENDL3SS determines why and how account and service data is processed. Privacy requests can be sent to privacy@endl3ss.lol.
Data we process
- Account data such as username, password hash, settings, public keys, and registered devices.
- Encrypted message envelopes, delivery state, and optional encrypted backups.
- Short-lived security data such as IP address, request time, login failures, rate limits, and protocol errors.
- Information you choose to include in an abuse or support report.
Why we process it
We process data to create and secure accounts, route encrypted messages, prevent abuse, maintain the service, respond to requests, and meet legal obligations. The final legal basis for each processing activity will be documented before launch.
What we do not intend to collect
We do not intend to store plaintext messages, private encryption keys, recovery phrases, permanent live file transfers, advertising profiles, or server-side plaintext message indexes.
Sharing and transfers
Data may be handled by infrastructure and security providers acting for ENDL3SS. A current subprocessor list and information about transfers outside the European Economic Area will be published before launch.
Retention
Data is kept only for a documented operational, security, contractual, or legal purpose. Exact periods for account records, ciphertext, logs, reports, and backups will be published before launch.
Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or object to processing. You may also withdraw consent and complain to a competent data protection authority. We may verify your identity before fulfilling a request.
Security
We use access controls, encryption, separation of duties, logging limits, and incident procedures. No system is risk free. Current design limitations are described on the security page.
Changes
Material changes will be dated and communicated through the service when appropriate.