Privacy Policy
Canary last updated: 4 August 2026 · Policy effective: 26 May 2026
Veilus Digital is a business operated by Curtis John Tunaley (ABN 90 372 665 693), registered in Western Australia, Australia. Contact: support@veilusdigital.co.
Veilus Digital uses industry-standard end-to-end encryption — the Signal Protocol, hybridised with NIST FIPS 203 post-quantum encryption (ML-KEM-768) — to provide private messaging services to users worldwide ("Services"). Your messages are encrypted on your device before they are ever transmitted, so they can never be shared or viewed by anyone but yourself and the intended recipients — not even by Veilus Digital.
Information you provide
Account Information. To create a Phantom Chat account, all you need is a username of your choice. No phone number, email address, or other personal information is required. Your chosen username is the only account identifier we hold, and we cannot access or read any of your message content.
Messages. Veilus Digital cannot decrypt or otherwise access the content of your messages. Because Phantom Chat is built on true end-to-end encryption, your message content is encrypted on your device before it is ever transmitted. We have no technical ability to read, store, or hand over your messages to any third party — including law enforcement. Your readable message history lives only on your own devices. Our servers never hold anything but encrypted ciphertext that we have no ability to read.
User Support. If you contact Veilus Digital support at support@veilusdigital.co, any information you voluntarily share with us is used only to respond to your enquiry and is not retained beyond that purpose.
Managing your information. You can manage your account information in Phantom Chat's application Settings. You may permanently delete your account and all associated data at any time using the in-app account-reset feature, which deletes your server-side data, wipes the encryption keys from your device's Keychain — making any residual encrypted data cryptographically unrecoverable — and performs a multi-pass (DoD 5220.22-M) overwrite of the app's stored files.
What we store on our servers
When you use Phantom Chat, our servers hold only the following items, all of which are either chosen by you or unreadable to us:
- Your chosen username (shared with someone only when you connect via an invite code or QR code).
- A profile blob holding optional profile settings you choose.
- Encrypted message ciphertext, held only so we can deliver it to the recipient's device(s). It is end-to-end encrypted and unreadable by us at all times, and is removed when a disappearing-message timer expires or when you delete your account.
- Your push notification token (an opaque identifier issued by Apple — it is not, and cannot be reversed into, a phone number).
- Your subscription status (active / trial / expired — for billing only).
- Diagnostic timestamps (small server-timestamped entries tagged "diag", written to your account namespace and used to detect latency problems or connection failures). These contain no message content, no behavioural data, and are not used for analytics or profiling. They are retained only long enough to investigate service issues.
We do not store: phone numbers, email addresses, real names, contact lists, location data, IP addresses — we do not store them; any transient connection logs are held by our infrastructure providers (Google, Apple) under their own retention policies, device fingerprints, advertising identifiers, or any tracking identifiers.
Subprocessors and Third-Party Services
To provide Phantom Chat, we use the following subprocessors. None of them have access to your message content; they only handle encrypted blobs and account-level identifiers:
- Google Firebase (Google LLC) — encrypted data storage, encrypted message routing, and push notification delivery. Firebase only stores ciphertext that we cannot decrypt.
- Apple Inc. — app distribution via the App Store, subscription billing via In-App Purchase, and the push notification gateway (Apple Push Notification service / APNs).
We do not use any analytics, advertising, or tracking subprocessors. If we ever add or change subprocessors that touch user data, we will update this Privacy Policy and notify users in accordance with the Material Changes clause below.
Information we may share
Because Phantom Chat is designed with end-to-end encryption at its core, Veilus Digital has no access to the content of your messages and therefore has no message content to share with anyone. In the very limited circumstances described below, we may be required to act on account-level information (such as your username and subscription status) only:
- To comply with a valid legal obligation or enforceable governmental request under Australian law.
- To enforce these Terms, including investigating potential violations.
- To detect, prevent, or address fraud, security vulnerabilities, or technical issues affecting the integrity of our Services.
- To protect the rights, property, or safety of Veilus Digital, our users, or the public as required or permitted by law.
In all such cases, any information we could provide is limited strictly to account-level data. We cannot and will not provide message content — it is technically impossible for us to do so.
Transparency Statement (Warrant Canary)
Last updated: 4 August 2026.
As of the date above, Veilus Digital has received:
- Zero (0) government requests for user data.
- Zero (0) gag orders or non-disclosure directives.
- Zero (0) National Security Letters or equivalent secret subpoenas.
We update this statement at least once every calendar quarter. If this section is ever removed, replaced with a date older than three months, or stops being updated, you should assume something has changed that we may not be legally able to disclose.
Even with end-to-end encryption, this commitment matters: account-level metadata (such as your username and subscription status) is the only thing we could in principle be compelled to disclose, and we will publish honest, current information about whether any such compulsion has occurred. We will not falsify, backdate, or pad this statement under any circumstance.
Updates
We will update this Privacy Policy as needed so that it is current, accurate, and as clear as possible.
Material Changes. When we make material changes to this Privacy Policy, we will notify you via an in-app banner at least 14 days before the change takes effect. Continued use of the Services after that date constitutes acceptance of the updated Privacy Policy. Non-material clarifications, typographical corrections, and updates to contact details may be made without advance notice.
Contact Us
If you have questions about our Privacy Policy please contact us at support@veilusdigital.co.
Effective as of 26 May 2026