Privacy Policy

Effective 20 September 2026. Last updated 20 September 2026.

This policy explains what personal data Covert Signals LLC (“Covert Signals”, “we”, “us”) collects, why, and for how long. It covers covertsignals.com, Covert.IM, and every other service we host for you (together, the “Services”). It forms part of our Terms of Service.


Our approach

We are a privacy and security provider. That is only credible if our own data practices match, so:

1. Who we are

Covert Signals LLC is the controller of the personal data described here. Contact us at .

2. Account data

To give you an Account we store: your username, your email address, your display name, the groups and entitlements that decide what you can access, and the second-factor authentication methods you enroll. You give us this data; without it we cannot create an Account. We hold it in our own single sign-on system on infrastructure we control.

3. Connection and security logs

We keep no permanent logs of your IP address.

Our servers see your IP address while you are connected, because that is how the internet works. We retain it only as follows:

We also keep operational logs (request paths, response codes, timings, and error traces) to keep the Services running and secure. We configure these to exclude message content and to exclude or truncate identifiers wherever the system still functions without them.

4. Covert.IM service data

Message content in end-to-end encrypted conversations is encrypted on your device. We hold ciphertext that we cannot decrypt, and we cannot produce it in readable form for you, for ourselves, or for any authority. Our backups contain the same ciphertext and are equally unreadable to us.

We are candid that encryption protects content, not metadata. To route messages and run the service, our homeserver necessarily holds:

Metadata is still personal data. We minimize its retention (Section 7) and protect it under the same legal-process rules as everything else (Section 9).

5. Billing data

For paid Services we store your billing contact, billing address, purchase orders, invoices, and payment records. We keep these for as long as tax and accounting law requires, currently seven years. We do not store full payment card numbers.

6. Cookies

The public website sets no cookies. Signed-in services set a small number of strictly necessary cookies: a session cookie that keeps you signed in, a CSRF token, and a cookie that remembers your sign-in preference. These are first-party, are not used for tracking, and expire when your session ends or shortly after. There is no consent banner because there is nothing to consent to.

7. Retention

DataKept for
Account dataWhile your Account is open, then deleted within 90 days
Ephemeral rate-limit recordsUp to 24 hours
Per-device last-seen IP and time7 days, then purged automatically
Sign-in and security events30 days
IP addresses during an abuse investigationUp to 30 days, or until the investigation closes
IP addresses after a confirmed Terms breachAs long as necessary to prevent recurrence
Operational and error logs30 days
Encrypted message content and mediaUntil you or your room’s policy deletes it
Database backups14 days, then destroyed
Billing records7 years, as tax law requires

Deleted data may persist in encrypted backups until those backups expire on the schedule above.

8. Who we share it with

We do not sell or rent personal data, and we disclose it to no one for advertising. We use a small number of subprocessors:

SubprocessorPurposeData it handlesLocation
GlobalTeleHost Corp. (GTHost)Bare-metal server hostingEncrypted disks only; see belowUnited States
AhaSend B.V.Transactional email deliveryYour email address and the contents of notification emails we send youNetherlands (EU)

We keep this list current and will update it before adding a subprocessor that handles personal data.

Our servers are fully disk-encrypted and GTHost does not hold the key. We provision every machine with full-disk encryption and the decryption key is held by us alone. GTHost supplies hardware, power, and network. It cannot read the contents of our disks, and a legal demand served on GTHost for our stored data would produce ciphertext. We are candid about the limit of this protection: while a server is running, its key is in memory, so an adversary with physical access to a live machine is a residual risk that disk encryption alone does not eliminate. This is one reason we also encrypt Covert.IM content end to end and keep everything else to a minimum. A demand can only reach data that exists.

10. Your rights

Whatever jurisdiction you are in, you may ask us to:

Write to . We respond within 30 days and do not charge for reasonable requests. We will not discriminate against you for exercising a right.

United States residents. If you live in California, Colorado, Connecticut, Virginia, or another state with a comprehensive privacy law, the rights above are the rights that law gives you, and we extend them to everyone rather than gate them by state. We do not sell personal information or share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA, and we have not done so in the preceding twelve months. We do not process sensitive personal information for the purpose of inferring characteristics. You may use an authorized agent, and you may appeal a refused request by replying to our decision.

Outside the United States. If you are in the EEA or the UK, we process your data to perform our contract with you (Account and Services), to meet legal obligations (billing records), and for our legitimate interests in keeping the Services secure and free of abuse. You have the rights above under the GDPR or UK GDPR, including the right to complain to your supervisory authority. Our servers are in the United States and our email subprocessor is in the Netherlands. For transfers to the United States we rely on the Standard Contractual Clauses, together with full-disk encryption, end-to-end encryption, and data minimization.

11. Security

We operate the Services on infrastructure we control, with full-disk encryption on every server under keys only we hold, end-to-end encryption for Covert.IM conversations, encryption in transit everywhere, single sign-on with mandatory multi-factor authentication, and least-privilege administrative access. No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant authorities within the deadlines the law sets.

12. Children

The Services are not for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal data, write to and we will delete it.

13. Changes

We may update this policy. For a material change we will give at least 30 days’ notice by email or in the Services before it takes effect. The effective date at the top always reflects the current version.

14. Contact

Write to for anything covered by this policy: privacy questions and rights requests, vulnerability reports and security incidents, abuse reports, and legal notices and demands. Mark the subject line with the reason so we can route it quickly.