VantaChat

Privacy Policy

Effective Date: 25 March 2026  ·  Last Updated: 25 March 2026

End-to-End Encrypted
No Ads · No Tracking
No Phone Number Required
P2P Voice & Video Calls
Messages Deleted After Delivery

1 Introduction

VantaChat ("the App", "we", "us", or "our") is developed and operated by Finnovant. We are committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information.

By using VantaChat, you agree to the practices described in this policy. If you do not agree, please do not use the App.

2 Who We Are

Developer: Finnovant

Website: https://finnovant.com/

Privacy Contact: bbezuidenhout@finnovant.com

Jurisdiction: We operate globally. This policy applies to all users worldwide.

3 Minimum Age

VantaChat is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us and we will delete that information promptly.

Users in jurisdictions where the minimum age for digital consent is higher (e.g. 16 in certain EU member states) must meet their local minimum age requirement.

4 Information We Collect

4.1 Account Information

DataPurposeRequired?
UsernameUnique account identifierYes
Display NameShown to contactsYes
About / StatusOptional personal bioNo
Profile PictureShown to contactsNo
🚫

We do not collect your phone number, email address, date of birth, or payment information at any point.

4.2 Cryptographic Keys

When you create an account, the App generates an ECDH (Elliptic Curve Diffie-Hellman) key pair on your device using the secp256r1 curve. Your private key never leaves your device and is stored in the Android KeyStore (hardware-backed where available). Your public key is uploaded to our servers solely to allow contacts to send you encrypted messages.

A recovery hash derived from a BIP39 mnemonic seed phrase is stored on the server to support account recovery. The seed phrase itself is only ever shown to you and is never transmitted.

4.3 Messages & Media

All messages are end-to-end encrypted on your device before being sent. Direct messages use AES-256-GCM with keys derived via ECDH. Group messages use a shared AES-256 group key, distributed via individual ECDH-encrypted handshakes.

⏱️

Temporary relay only. Encrypted message payloads are stored on our relay server only until the recipient's device acknowledges delivery. Once delivered, the message is permanently deleted from our servers. We cannot read the content of any message at any time.

Media files (images, videos, documents) are uploaded encrypted to our secure storage and referenced within the encrypted message payload. Access to media requires the encryption key held only by the intended recipient.

Message metadata (delivery status, timestamps) may be processed to facilitate delivery.

4.4 Voice & Video Calls

📡

Calls are peer-to-peer (P2P). Both one-to-one and group voice and video calls are established directly between participants' devices using WebRTC. Audio and video streams do not pass through or touch any media server — they travel directly between devices. We cannot intercept, record, or store any call content.

Call signaling (connection setup such as SDP and ICE candidates) passes through our servers briefly to establish the direct connection. This signaling data is transient and not retained after the call is connected. A Google STUN server is used for NAT traversal to help devices find each other on the network.

4.5 Push Notifications

We use Firebase Cloud Messaging (FCM) by Google to deliver push notifications. Your FCM token is stored on our servers and updated automatically when it changes. Notification payloads do not include message content — only a generic indicator that a new event is waiting. Notifications are only delivered from users in your contact list.

4.6 Technical Data

We do not use analytics SDKs, advertising SDKs, or third-party crash-reporting services.

4.7 Data Stored Locally on Your Device Only

The following is stored on your device and is never accessible to us:

5 How We Use Your Data

We use the information described above only to:

🚫

We do not sell, rent, or trade your personal information. We do not use your data for advertising or profiling. Ever.

Legal Basis for Processing (GDPR)

Processing ActivityLegal Basis
Account creation and managementPerformance of contract
Message relay and deliveryPerformance of contract
Push notificationsConsent
Security and abuse preventionLegitimate interest
Legal complianceLegal obligation

6 Third-Party Services

ServiceProviderPurposeData Shared
Firebase Cloud MessagingGoogle LLCPush notificationsFCM token, notification metadata
S3-Compatible StorageStorageChainEncrypted media storageEncrypted media files, profile pictures
Google STUNGoogle LLCP2P call NAT traversalIP addresses during call setup only

We share only what is strictly necessary with each provider. We do not use advertising networks, analytics platforms, or third-party crash-reporting services.

7 Data Retention

Data TypeRetention Period
Encrypted message payloadsDeleted from our servers immediately upon confirmed delivery to the recipient's device
Account data (profile, public key)Until account deletion
Media filesUntil deleted by the user or upon account deletion
FCM tokensWhile account is active; deleted on account deletion
Call signaling dataTransient — discarded after call connection is established
Server access logsLimited period for security and abuse prevention only
Local device dataOn device until you clear app data or delete your account

8 Account Deletion

You can permanently delete your account at any time from Settings → Account → Delete Account.

Upon deletion:

⚠️

Account deletion is permanent and irreversible. Your account cannot be recovered after deletion, even using your seed phrase.

9 Security

Despite these measures, no system is 100% secure. We encourage you to use a strong PIN and keep your seed phrase in a safe place.

10 Your Rights

Depending on your location, you may have the following rights regarding your personal data:

RightHow to Exercise
Access — obtain a copy of your dataContact us by email
Correction — correct inaccurate dataUpdate in-app or contact us
Deletion — erase your account and dataSettings → Account → Delete Account, or contact us
Restriction / Objection — restrict or object to processingContact us by email
Withdraw Consent — withdraw where consent is the basisContact us by email

We will respond to all requests within 30 days.

EU/EEA Users (GDPR): You have the right to lodge a complaint with your local data protection supervisory authority.

California Users (CCPA): You have the right to know, delete, and opt-out of the sale of personal information. We do not sell personal information.

11 International Data Transfers

Finnovant operates globally. Your data may be processed and stored in countries outside your own, including countries that may not have the same data protection laws as your country of residence. Where required, we apply appropriate safeguards (such as standard contractual clauses) to protect your data during international transfers.

12 App Permissions

PermissionPurpose
RECORD_AUDIOMicrophone access for voice and group calls
CAMERACamera access for video calls
INTERNETRequired for all app functionality
ACCESS_NETWORK_STATECheck network connectivity
POST_NOTIFICATIONSDisplay push notifications
FOREGROUND_SERVICEMaintain active call in background
USE_FULL_SCREEN_INTENTShow incoming call screen
WAKE_LOCKKeep device awake during active calls
VIBRATEHaptic feedback for notifications
SYSTEM_ALERT_WINDOWDisplay call overlay UI

13 Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the App or via a notice on our website. The "Last Updated" date at the top of this policy reflects the most recent revision. Continued use of the App after changes constitutes acceptance of the updated policy.

14 Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please reach out:

✉️
Finnovant

Website: https://finnovant.com/

Email: bbezuidenhout@finnovant.com

We aim to respond within 30 days of receiving your request.