Version 4 · effective October 3, 2026
VOIDEX is built to see as little about you as possible. Your direct messages and one-to-one calls are end-to-end encrypted, so we store only ciphertext we cannot read. This policy explains the limited data we do handle to run the Platform.
Account information: the details needed to create and secure your account, such as your username, a hashed password, your public encryption keys, and an encrypted, recovery-sealed backup of your keys that only you can unlock.
Content you make public: posts, comments, media, reactions, and profile details you choose to publish in Space, Orbits, or on public profiles. This content is public by design.
Technical and usage data needed to operate and secure the service: for example, connection and device information, log and diagnostic data, and abuse-prevention signals. We keep this to the minimum needed to run and protect the Platform.
We cannot read your direct messages or hear your calls. They are encrypted end-to-end and we store only ciphertext. We do not have a key to your private conversations, and we cannot hand over content we cannot decrypt. Private message and call media are uploaded as encrypted blobs and are not scanned by us on the server.
VOID EXPLORER lets you search and open web pages from inside VOIDEX. Your searches are not logged and are never linked to your account - we do not keep a record that says a particular person searched a particular thing, so we cannot tell that it was you who looked something up. To actually run a search or open a page, our server has to process that request in the moment (it is the one that talks to the web, so the sites you visit see VOIDEX and never see you), but that request is handled transiently and is not written to a log tied to your identity.
Your VOID EXPLORER history is stored end-to-end encrypted on your device - we hold only ciphertext we cannot read, and you can delete any item or clear it entirely at any time. Popular results may be cached to make everyone's searches faster, and that shared cache is anonymous: it never records who asked.
When you ask PULSE a question, the question and PULSE's answer may be kept so PULSE - and the wider VIRTUE AI it is part of - can learn and give better answers. What is kept is never linked to you: no account, no device, no IP address and no time of day, only the date, and email addresses, phone numbers, @usernames and links are removed from the question before it is stored. Follow-up questions in a conversation are never kept. Do not put personal details in a question you would not want kept in this anonymous form.
We use the limited data above to operate, maintain, secure, and improve the Platform; to provide support and fix bugs; to prevent fraud, abuse, and security threats; to moderate public content in response to reports; and to comply with the law. We do not sell your personal data, and we do not run third-party advertising that profiles you.
We share data only with service providers who help us run the Platform (such as infrastructure hosting), bound to protect it; when required by law or valid legal process; or to protect the rights, safety, and security of users, the public, or VOIDEX. Even under legal process, we cannot produce the content of end-to-end encrypted messages or calls, because we cannot decrypt them.
We use encryption in transit and at rest, end-to-end encryption for messages and calls, hashed passwords, and access controls. No system is perfectly secure, but security is central to how VOIDEX is built. If we ever become aware of a breach affecting you, we will act in accordance with applicable law.
You can access and edit your profile, control what you make public, and delete your content. You can delete your account, which removes your account data from active systems (subject to limited retention required by law, security, or backups). Depending on where you live, you may have additional rights - such as to access, correct, export, or erase your personal data, or to object to certain processing - and you can exercise them by contacting us.
We keep data only as long as needed to provide the Platform and for legitimate legal, security, and operational reasons. Public content remains until you or we remove it. Deleting content or your account removes it from active systems, though residual copies may persist briefly in backups.
We use only the minimal cookies and browser/local storage needed to keep you signed in and to remember your preferences (such as your last view or filters). We do not use them for cross-site advertising or profiling.
VOIDEX is not intended for anyone under 16. If you believe someone under 16 has provided us personal data, contact us and we will take appropriate steps.
We may update this policy; material changes update the version and effective date. Questions or privacy requests: support@voidex.us.
The controller of your personal data is CNOTA Management FZCO, Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, United Arab Emirates. Our representative in the European Economic Area under Article 27 of the GDPR is VIRTUE AS. You can contact either of us at support@voidex.us about anything in this policy.
To provide the account and the Platform you signed up for (contract): your account details, the public content you post, delivering your encrypted messages and calls, and subscriptions.
Our legitimate interests in keeping VOIDEX safe and working: security, abuse and fraud prevention, moderation of public content, fixing bugs, and improving PULSE with anonymous questions and answers that are not linked to you. You can object to processing based on legitimate interests by contacting us.
Your consent, which you can withdraw at any time in Settings or your device settings: push notifications, sharing your live location in a private channel, and access to your camera, microphone and photos when you choose to use them.
Legal obligations: answering valid legal requests and keeping records the law requires.
Our servers are hosted by Hetzner Online in data centres in the European Union (Finland and Germany), and media is stored in Hetzner object storage in the EU. Push notifications are delivered through Google Firebase Cloud Messaging and Apple Push Notification service; a push says who wrote to you, never what they wrote. Account emails, such as password resets, are sent through Resend. Subscriptions are processed by the app store you subscribe with. Where a provider processes data outside the European Economic Area, we rely on the safeguards the law requires, such as the European Commission's Standard Contractual Clauses.
How long we keep things: your account data for as long as your account exists; server logs for a short period while they are rotated out; encrypted backups for up to 12 months, after which they are deleted; anonymous PULSE learning data without a time limit, since it is not linked to anyone.
If you live in the European Economic Area or the United Kingdom, you can complain to the data protection authority in your country if you believe we handle your data unlawfully. We would appreciate the chance to fix it first, so please write to us as well.