Privacy Policy

Effective date: July 14, 2026 · NoPeek, a product of SignOut LLC

This Privacy Policy explains how SignOut LLC, a Montana limited liability company ("we", "us"), processes personal information in connection with NoPeek — chat APIs that are end-to-end encrypted by default. It covers our customers (developers and companies, "Customers") and, where we act as a processor, the end users of Customer applications ("End Users").

1. The short version

Message content in end-to-end encrypted channels is encrypted on End-User devices before it reaches us. We cannot read it. Not for analytics, not for advertising, not on request. What we necessarily process in readable form is routing metadata. We sell no personal information to anyone.

2. What we can and cannot see

We can see (metadata)We cannot see (E2EE content)
Account details: org name, billing email, password hashMessage text ██████████
User/channel/device identifiers and membershipAttachments and files ████████
Timestamps, sequence numbers, MLS epochsReactions in encrypted channels ███
Delivery/read markers, typing signals, presenceLink previews and GIFs █████
Public key material (never private keys)Encrypted history backups ██████
IP addresses and request logs (security/audit)Recovery codes / backup keys ████

Channel types a Customer explicitly opts out of encryption are an exception: content in those channels is processed server-side on the Customer's instruction and is marked as such in the product.

3. Information we collect

From Customers: registration data (name, billing email, password hash), API key hashes, billing records (processed by Stripe — we do not store full card numbers), dashboard activity, and support communications. From End Users (as processor for the Customer): the identifiers and metadata listed above, ciphertext blobs, public keys, push notification tokens, and IP/technical logs. Automatically: service telemetry (request counts, latency, errors) tied to accounts, not content.

4. How we use information

To provide and secure the Service (routing, delivery, abuse prevention, audit logging); to bill and manage accounts; to provide support; to meet legal obligations; and to improve reliability using aggregate, content-free telemetry. We do not use Customer Data to train machine-learning models, we do not profile End Users, and we do not serve advertising.

5. Sharing

We share information only with: (a) subprocessors that operate the Service — a cloud infrastructure provider (compute and storage), a managed database provider, and a payment processor (Stripe) — each bound by contract to process it only for us; (b) authorities when legally compelled, in which case encrypted content can only be produced as ciphertext because we hold no keys, and we will notify the affected Customer unless legally prohibited; and (c) a successor entity in a merger or acquisition, subject to this policy. We never sell personal information.

6. Moderation reports

If an End User reports a message, the reporter's device may voluntarily attach the decrypted content of that message, which the reporter could already read. Disclosed report content is visible to the Customer's moderators and to us solely for handling that report.

7. Security

All traffic is encrypted in transit (TLS); stored data is encrypted at rest; content in E2EE channels is additionally end-to-end encrypted with keys held only on End-User devices. API secrets and passwords are stored as salted hashes. Access to production systems is role-restricted and logged in an append-only audit trail. We maintain a breach-notification process; suspected incidents can be reported to support@getsignout.com.

8. HIPAA

For Customers with an executed Business Associate Agreement, we act as a Business Associate. Our architecture minimizes PHI exposure: message content is ciphertext to us. Customers remain responsible for minimizing PHI in metadata fields they control (nicknames, channel names, custom metadata).

9. The NoPeek Messenger app

NoPeek Messenger is our own end-user application (iOS, Android, and web) built on the NoPeek platform. When you use NoPeek Messenger, SignOut LLC is the controller of your personal information. Everything in this policy applies; this section adds the app-specific details.

What we collect. Account information: your name, email address, and a password (credentials are managed by a dedicated identity provider; we never see your plaintext password), plus profile details you choose to add (photo, title, status). Organization membership: which orgs and group chats you belong to. Messages and attachments: end-to-end encrypted on your device — we store and route only ciphertext and the routing metadata described in Section 2. Push notification tokens: APNs (Apple) and FCM (Google) device tokens, and — for incoming calls on iOS — a separate VoIP push token, all used solely to deliver notifications and ring calls. App usage analytics: the app includes Google Firebase Analytics, which collects usage events (such as app opens and screen views) and device information on our behalf; analytics never includes message content, and we do not use it for advertising or cross-app tracking. We do not currently bundle a third-party crash-reporting SDK; crash reports you share via Apple or Google are governed by their settings and policies.

Contacts. Contact matching is on-device. When you tap “Import from contacts”, the app reads the names, email addresses, and phone numbers you allow it to access and matches them locally on your device against the member directory the app has already synced for your organizations. Your address book is not uploaded to our servers, is not stored by the app, and is discarded when you close the import screen. No contact data leaves your device.

Photos and media. Photos and files you attach are encrypted on your device before upload. Saving received media to your device gallery happens only when you tap Save, and on iOS uses write-only “add to photo library” access — the app can add that one item and cannot browse your library. Organization administrators may disable gallery saving for their organization.

Calls. Voice and video calls are peer-to-peer WebRTC, encrypted end-to-end (DTLS-SRTP). We do not record calls and have no technical ability to listen to them; we operate no call relay servers at all — call media travels directly between devices, and on networks where a direct connection is impossible the call fails with a clear message rather than routing through a middleman. We process call signaling metadata (who called whom, when, and for how long) to ring and connect calls. On iOS, incoming calls use Apple’s CallKit so they ring like phone calls; the entry that then appears in your iPhone’s Recents list is created and stored by iOS on your device — we do not receive your device call history. NoPeek calls are not a replacement for your telephone and cannot reach emergency services (911/112).

On-device storage. To open chats instantly, the app keeps a local cache of recent decrypted messages and media in the app’s private storage on your device, protected by your device’s encryption and, if you enable it, the app’s biometric lock. This cache exists only on your device — decrypted content is never sent back to us.

Account recovery. If you enable recovery, your message keys are backed up as an encrypted blob that can only be unwrapped with a key derived from your password. We store the blob; we cannot decrypt it. If you lose your devices and your password, encrypted history is unrecoverable — by design.

Deleting your account. You can delete your NoPeek Messenger account from Settings inside the app, by submitting your account email on our account deletion page, or by emailing support@getsignout.com from your account email. Deletion removes your account record, profile, devices, push tokens, recovery blob, and your messages per the retention rules in Section 10, subject to short backup roll-off and legal holds.

10. Retention and deletion

Customer account data is retained for the life of the account plus limited periods for legal/tax obligations. Message envelopes (including ciphertext) are retained under the Customer's configuration and deleted when the Customer deletes messages, channels, users, apps, or the account (recalled messages have content erased immediately; a tombstone identifier remains for client sync). Backups roll off within 35 days. End Users can exercise deletion via the Customer, which controls their data. NoPeek Messenger users can delete their account as described in Section 9.

11. Your rights

Depending on your jurisdiction (e.g., GDPR, CCPA/CPRA), you may have rights to access, correct, delete, port, or restrict processing of your personal information, and to non-discrimination for exercising them. Customers can exercise these via the dashboard or by contacting us. End Users should contact the operator of the application they use; we support Customers in fulfilling these requests. NoPeek Messenger users can exercise these rights directly with us at support@getsignout.com (our GDPR and CCPA/CPRA contact point). We honor verifiable requests within the timelines required by law, and we do not discriminate against you for exercising them. Note that for end-to-end encrypted content, access and portability requests can only be satisfied from your own devices — we hold ciphertext we cannot read.

12. International transfers

The Service is operated from the United States. Where we receive personal information from other jurisdictions, we rely on appropriate safeguards, including standard contractual clauses where applicable.

13. Children

The Service — including NoPeek Messenger — is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Customers may not use the Service to collect personal information from children except in compliance with applicable law (including COPPA) within their own applications. If you believe a child under 13 has created a NoPeek Messenger account, contact us and we will delete it.

14. Changes

We will post updates here and notify Customers of material changes via the dashboard or email at least 14 days before they take effect.

15. Contact

SignOut LLC · Montana, USA · support@getsignout.com