How it works Privacy Pricing FAQ Support
Download
PT EN DE FR ES
Legal

Privacy Policy

Last updated: 28 July 2026

Privacy is the reason CloakFort exists. This policy explains, in plain language, what data the CloakFort app ("the App", "we") processes, where it lives and what you can control. CloakFort is built by generictec, the data controller under the GDPR (Regulation (EU) 2016/679).

1. 30-second summary

  • Messages are end-to-end encrypted: the content is only ever readable on the two phones involved. We cannot read your messages.
  • What travels through our infrastructure is always encrypted: a text message travels as encrypted text; a photo or file travels hidden in the pixels of an image (steganography).
  • You need an account to use the App: it identifies you and publishes your public key. Your private key never leaves the device.
  • Messages are ephemeral: by default they disappear within 3 days, can still be recovered for about another week, and are then erased for good.
  • We use anonymous analytics to improve the App, which you can turn off. There are no ads and no third-party trackers.

2. Encryption and how a message travels

When you send something on CloakFort, the content is encrypted on your device and only for the recipient (X25519 → HKDF → AES-256-GCM). A text message then travels as encrypted content. A photo or a file travels hidden in the pixels of an image, using steganography. Either way, our servers store and deliver only encrypted content and have no way to get at the original. Decryption happens only on the recipient's device, inside the App. Outside CloakFort, the image is just a photo.

3. Account and keys

An account is required to use the App. When you create one:

  • We store your sign-in identifier (for example, an email, or the identifier from your Google/Apple provider) for authentication. We do not use OTP and do not verify phone numbers.
  • A key pair is generated. Your public key is published so other users can send to you; your private key is stored securely on the device (Keychain/Keystore) and is never transmitted. There is no escrow and no backdoor.
  • You can store basic profile data (for example, a display name).

Legal basis: performance of the service you requested (Art. 6(1)(b) GDPR). You can delete your account at any time, which removes your profile and public key from our systems.

4. Message metadata and retention

To deliver messages and show receipts, we process a minimal set of metadata: who sent and who receives (account identifiers), timestamps, delivery and read state (sent / received / read) and the expiry date. We never have access to the content, which is encrypted.

Messages are ephemeral. By default they are available for up to 3 days; then they enter a recovery window of about another week; and at most around 10 days they are permanently deleted - both the encrypted content and its metadata. An already-expired message can only be unlocked within the recovery window (see section 7). If you delete your account, we remove your account data; messages already in transit follow the same expiry cycle.

5. Anonymous analytics and diagnostics

To understand how the App is used and improve it, we may collect anonymized and aggregated usage statistics. We've configured this for privacy:

  • Events do not include the content of your messages or your keys.
  • Advertising signals are always disabled - the App never shares data for ads.
  • You can turn analytics off in the App's settings.

Legal basis: our legitimate interest in maintaining and improving the App (Art. 6(1)(f)), balanced by data minimization and the opt-out. We may also collect technical crash reports to fix bugs.

Separately from the App, this website (cloakfort.app) uses Google Analytics for aggregate visit statistics (page views, device type, approximate country). On your first visit we show a cookie banner: if you accept, Google Analytics stores statistics cookies; if you decline, we store no cookies and Google Analytics sends only aggregate, anonymous, cookieless measurements (so-called Consent Mode). You can change your choice at any time via the Cookies link in the footer of any page.

6. Cookies on this website

The CloakFort app does not use cookies. This website (cloakfort.app) uses a small number of cookies, only for visit statistics - never for advertising or to identify you personally.

  • Strictly necessary - keep the pages working and store no personal information.
  • Analytics (Google Analytics) - cookies such as _ga and _ga_<id> let us count visits in aggregate. They are stored only if you accept in the banner; if you decline, Google Analytics runs in cookieless mode. We've configured Google Analytics with advertising signals disabled.

We don't use advertising, social-media or cross-site tracking cookies. You can also block or delete cookies in your browser settings - the site keeps working normally.

7. Payments and subscriptions

The Premium plan and the one-off unlock of an expired message are processed by the App Store (Apple) or Google Play (Google). We never receive or store your card details. We only receive confirmation that your subscription or purchase is active, to unlock the matching features. The processing of your payment data is governed by Apple's and Google's privacy policies.

8. Device permissions

  • Photos / files - only when you choose an image or file to send, or save something you received. Processing happens on the device.
  • Contacts - if you allow it, we match your contact list against registered accounts to show you who you can send to. This matching is minimized; we don't use your contacts for advertising.
  • Notifications - to let you know when you receive a new message.
  • Biometrics - if you enable the biometric lock, authentication is handled by the operating system; we never access your biometric data.

9. Who we share data with

We don't sell your data and we don't share it for advertising. We only use processors strictly necessary to run the App: the infrastructure provider(s) hosting messages in transit (always encrypted), the push notification services (FCM / APNs), anonymous analytics, and the app stores (for payments). Each processes data under its own policies.

10. Your rights (GDPR)

You have the right of access, rectification, erasure, restriction, portability and objection regarding the data we process (account, metadata, anonymous analytics), as well as the right to withdraw consent. Because your message content is ephemeral and never accessible to us, most of the control sits directly with you, in the App. To exercise these rights, contact us at info@cloakfort.app. You also have the right to lodge a complaint with your competent supervisory authority (in Portugal, the CNPD).

11. Minimum age

CloakFort is intended for adults, 17+. It is not intended for children and does not knowingly collect data from minors. If we learn that an account was created by a child, we delete it.

12. Changes to this policy

We may update this policy to reflect improvements to the App or legal changes. We'll publish the revised version on this page, with the "Last updated" date at the top. Significant changes will be flagged in the App.

13. Contact

Data controller: generictec. For any privacy question, write to info@cloakfort.app.