Privacy Policy
Last updated: July 17, 2026
PicSecure is currently in development. The app has not yet launched publicly, and today we only collect the email address you provide to join our early-access waitlist. This policy also describes how your data will be handled once PicSecure launches, so you know what to expect.
1. Who we are
PicSecure ("PicSecure", "we", "us") is a secure communication platform built around end-to-end encryption and a zero-knowledge architecture. This policy explains what information we collect, why, and the controls you have over it. If you have questions, contact us at hello.team@picsecure.in.
2. Information we collect today (pre-launch)
While PicSecure is in early access, the only information we collect is:
- Waitlist email address — so we can notify you when PicSecure launches.
- Basic usage analytics for this website (e.g. which pages are viewed), used only in aggregate to understand interest in the product.
3. Cookies & tracking technologies
This website uses a small number of cookies and similar technologies:
- Essential cookies — required for the site to function (e.g. remembering your cookie preference). These can't be turned off.
- Analytics cookies — help us understand aggregate traffic patterns (e.g. which pages are viewed), using privacy-respecting analytics that don't build cross-site advertising profiles of you.
We don't use third-party advertising cookies, and we don't sell or share cookie data with ad networks. Once the app itself launches, it will not use browser cookies at all — the concepts above apply to this website only.
4. Information PicSecure will process once launched
Once the app is live, the categories of information involved fall into two groups:
4.1 What we can see
- Account information — such as your display name, phone number or email used to register, and profile photo.
- Device and diagnostic information — device type, operating system, app version, and crash/error logs, used to keep the app working reliably.
- Metadata required to deliver messages — such as when a message was sent and to which device, in the same way any messaging app needs to route your messages. This does not include message content.
4.2 What we cannot see
PicSecure encrypts chats, calls, and media end-to-end. Encryption keys are generated and stored on your device — never uploaded to our servers. This means we cannot read the content of your messages, calls, or files, and cannot decrypt your Media Vault contents — even if compelled by legal process, since we have no technical ability to hand over content we don't possess.
5. Our encryption architecture, layer by layer
Rather than a single layer of protection, PicSecure wraps your data in four independent layers. If one is ever challenged, the others still hold:
- Transport layer — TLS 1.3 protects data while it's in transit between your device and our servers, the same standard used by major banks.
- Session layer — X3DH key exchange establishes a shared secret between you and the person you're messaging without ever transmitting it, and the Double Ratchet algorithm rotates encryption keys with every message, so that even if one key were ever exposed, past and future messages stay protected.
- Storage layer — chats and files kept on your device sit in an encrypted local database (AES-256-GCM), keyed to your device rather than a password we hold.
- Device layer — your private key is generated and sealed inside hardware-backed storage (Secure Enclave on iOS, Android Keystore on Android) — it cannot be exported, copied, or read by any app, including ours.
6. Message & data deletion
When you delete a message or file, that deletion is real and permanent:
- Gone from your device — deleted content is removed from local encrypted storage immediately, not just hidden from view.
- Gone from delivery infrastructure — because messages are end-to-end encrypted, we only ever hold them transiently to route delivery. Once a message is delivered (or after a short time-to-live if it can't be delivered), it's purged from our systems — there's no long-term database copy for us to separately delete.
- No backups of message content — since we never had readable access to your messages or files, we have no archive or backup containing their content to worry about.
- “Delete for everyone” requests a matching deletion on the recipient's device as well; as with any messaging app, we can't force a device that's offline or has been screenshotted to un-see content, but the message itself is removed from both ends' storage.
In short: deleting something in PicSecure doesn't just hide it from you — it removes it from your device, from the recipient's device (for "delete for everyone"), and from any transient server-side storage or database used to route it. There's nothing left over for us to hold.
7. Privacy details for every PicSecure feature
Here's exactly what each part of the app involves, in plain language:
7.1 Secure Chats
Messages are end-to-end encrypted before they leave your device. We route encrypted message packets so they reach the right recipient, but we cannot read their contents. We keep only the metadata described in Section 4.1 (timing and routing) to make delivery work.
7.2 Secure Calls
Voice and video calls are wrapped in the same layered encryption described in Section 5 and, wherever possible, connect peer-to-peer directly between devices rather than routing media through our servers. Call audio and video are never recorded, stored, or accessible to us — encrypted in transit and gone the moment the call ends.
7.3 Media Vault
Photos, videos, documents, and audio you store in your Media Vault are encrypted on-device before any sync occurs. We store only encrypted blobs we cannot open — the decryption key never leaves your device.
7.4 Secure Sharing
Shared file links carry their own time-based access controls that you set (for example, a link that expires after 24 hours). We enforce the expiry you choose, but we cannot see the shared file's contents, only that a link exists and when it expires.
7.5 Quiet Hours
Quiet Hours mutes notifications for a chat or the whole app on the schedule you set. Messages continue to arrive and stay fully encrypted while muted — this feature only affects notification delivery on your device, and involves no additional data collection.
7.6 Voice Commands
Voice input is processed to carry out the action you request (e.g. ending a call, opening a chat). Voice audio is processed to execute your command and is not stored or used for any other purpose.
7.7 Guardian (Danger, Medical, Travel, Customize modes)
Guardian is off by default and only ever activated by you. When you start a Guardian session, it shares a specific set of data with only the trusted contacts you select for that session — never with us beyond what's needed to relay it, and never continuously in the background. Exactly which fields are shared depends on the mode:
- Live location — your device's GPS coordinates (latitude/longitude), updated periodically while the session is active;
- Speed & direction — derived from consecutive GPS readings, used in Danger and Travel modes;
- Battery & network status — your device's battery percentage and connectivity state, so contacts know if you might lose signal;
- Device identifiers — the device name and a device identifier used only to know which of your devices is sharing, not for tracking across apps;
- Medical information — only in Medical mode, and only the fields you've chosen to enter (e.g. conditions, allergies, medications);
- Emergency message & trusted contacts — the message and the specific contacts you selected to receive it;
- Route start & end points — only in Travel mode, the journey's origin and destination as you've set them.
All of this goes directly to the contacts you chose for that session — we relay it but do not analyze, profile, or retain it beyond what's needed for delivery, and sharing stops the instant you end the session.
7.8 Family Space (Parental Mode)
Family Space is a mutual-follow circle, not one-directional monitoring — every connection requires both sides to accept. Within it, family members can see each other's online status and, if both sides enable it, location — always visible to the person being "watched," never covert. One-tap calling within Family Space uses the same end-to-end encrypted calling as the rest of the app.
8. How we use information
We use the limited information described above to:
- Operate, maintain, and improve PicSecure;
- Notify waitlist members about launch and major updates;
- Provide customer support;
- Detect, prevent, and address technical issues or abuse of the service;
- Comply with legal obligations.
We do not sell your personal information, and we do not use message content for advertising — we cannot, since we can't read it.
9. Data sharing
We do not share your personal information with third parties for their own marketing purposes. We may share limited information with:
- Service providers who help us operate the app (e.g. cloud infrastructure, email delivery for the waitlist), bound by confidentiality obligations;
- Law enforcement, only when required by valid legal process, and limited to the metadata described in Section 4.1 — we have nothing further to disclose;
- Contacts you explicitly choose to share information with via Guardian or Family Space.
10. Data retention
Waitlist email addresses are kept until launch (or until you ask us to remove them) plus a reasonable period afterward for launch communications. Once the app is live, account and metadata are retained only as long as your account is active, or as required by law.
11. Your rights and choices
Wherever you are, you can:
- Ask us to remove your email from the waitlist at any time by emailing hello.team@picsecure.in;
- Request a copy of the information we hold about you;
- Request deletion of your account and associated data once the app has launched — see our Delete Account page;
- Control what Guardian and Family Space share, and with whom, directly within the app.
11.1 If you're in the European Economic Area, UK, or Switzerland (GDPR)
You additionally have the right to:
- Access — obtain a copy of the personal data we hold about you;
- Rectification — correct inaccurate or incomplete data;
- Erasure — request deletion of your data ("right to be forgotten");
- Restriction — limit how we process your data in certain circumstances;
- Portability — receive your data in a structured, machine-readable format;
- Objection — object to certain processing, including for legitimate-interest grounds;
- Lodge a complaint with your local data protection authority at any time.
To exercise any of these, email hello.team@picsecure.in. We'll respond within the timeframe required by applicable law.
11.2 If you're a California resident (CCPA/CPRA)
You additionally have the right to:
- Know what personal information we collect, use, and disclose;
- Delete personal information we hold about you, subject to certain exceptions;
- Correct inaccurate personal information;
- Opt out of the "sale" or "sharing" of personal information — we don't sell or share personal information as defined by the CCPA, so there's nothing to opt out of, but you can still submit a request for confirmation;
- Non-discrimination — we won't deny you service or charge you differently for exercising any of these rights.
To submit a CCPA/CPRA request, email hello.team@picsecure.in with "California Privacy Request" in the subject line. We may need to verify your identity before completing certain requests.
11.3 If you're in India (DPDP Act)
Where India's Digital Personal Data Protection Act, 2023, its implementing rules, or other applicable Indian data-protection law apply to our processing of your personal data, we process personal data for lawful purposes and provide notices and obtain consent where required by applicable law.
Subject to applicable law, you may have rights relating to your personal data, including the ability to:
- Request information about the personal data we process about you and how it is processed;
- Request correction, completion, or updating of inaccurate or incomplete personal data;
- Request erasure of personal data where applicable;
- Withdraw consent for processing based on your consent, subject to the consequences and limitations provided by applicable law;
- Raise a grievance regarding our handling of your personal data; and
- Exercise other rights available to you under applicable Indian data-protection law.
To submit a privacy request or grievance, email hello.team@picsecure.in with "India Privacy Request" in the subject line. We may need to verify your identity before processing certain requests. We'll provide or update additional grievance-redressal and data-protection contact information as PicSecure's legal entity and public-launch operations are finalized.
12. Children's privacy
PicSecure's Family Space is designed to help families stay connected safely, but PicSecure as a whole is not directed at children under 13, and we do not knowingly collect personal information from children under 13 without verified parental consent. If you believe a child has provided us information without appropriate consent, contact us and we will remove it.
Age thresholds and parental-consent requirements vary by country and region. Where applicable law requires parental or guardian consent for users above or below a different age threshold, PicSecure will apply the requirements of that jurisdiction before making the relevant services available.
13. Security practices
Beyond the encryption architecture in Section 5, we apply device authorization checks (every new device must be verified before it can access your account) and regular internal security reviews and dependency audits. No system is perfectly secure, but PicSecure is built so that even we hold as little as possible to protect.
14. International users
PicSecure may be used globally. Where we transfer information internationally, we take steps to ensure it remains protected consistent with this policy.
15. Changes to this policy
We'll update the "Last updated" date above whenever this policy changes, and for material changes we'll make a reasonable effort to notify waitlist members and, after launch, active users.
16. Contact us
Questions about this policy or your data can be sent to hello.team@picsecure.in.
Note: This policy is a working draft prepared ahead of PicSecure's launch and should be reviewed by a qualified privacy attorney — particularly regarding location data, health-adjacent information in Guardian's Medical mode, children's privacy laws (e.g. COPPA, GDPR-K, and India DPDP Act Section 9's verifiable parental consent and child-tracking restrictions — directly relevant given Guardian and Family Space's location features), and confirming the GDPR (Section 11.1), CCPA/CPRA (Section 11.2), and India DPDP (Section 11.3) language matches PicSecure's actual data flows, grievance-redressal setup, and chosen legal entity — before the app goes live.