Legal

Privacy Policy

Last updated: 27 July 2026

TRI1 is a private, end-to-end encrypted messaging, voice/video calling, and prepaid-credits application. Privacy is the product. This policy explains exactly what does and does not leave your device.

The Golden Rule

Your private keys, identity backup, and message/call content never leave your device. Only your public identity (a public key and the name/photo you choose) is shared, and only with contacts you add. We cannot read your messages or calls, and we cannot recover your private keys.

1. What we do NOT collect

2. What we DO process, and why

DataPurposeNotes
Public identity (public key, chosen name/photo)So contacts can find and verify you and route encrypted messages/callsShared only with contacts you add
Encrypted relay / offline mailboxDeliver messages & attachments when the recipient is offlineStored only as ciphertext we cannot read; deleted after delivery
NotificationsLet you know about incoming calls and new messages when the app is closedA friendly nudge that wakes your phone. Not tied to your identity, and it never carries your message content.
Prepaid credits / paymentsBuy & spend in-app creditsCard details are collected and processed by Stripe under Stripe's own policy; TRI1 stores only your balance and pay-request metadata, never full card numbers. Optional; may be absent in some builds.

3. Device permissions

You can revoke any permission in your device settings; the related feature is then disabled.

What we deliberately do not touch. TRI1 does not read your motion or body sensors (accelerometer, gyroscope, and the like), your location, your SMS, your call log, or your phone number. None of these are part of how the app works. If your operating system ever surfaces a prompt for one of them, and privacy-hardened systems such as GrapheneOS are especially good at surfacing them, it comes from a bundled platform service, not a TRI1 feature. You can safely deny it: nothing in TRI1 depends on it, and the app keeps working normally.

Third-party components, kept to the minimum. To ring an incoming call or notify you of a message while the app is closed, TRI1 uses your device's standard push service. Like nearly every app that does this, that platform library ships with helper sub-components bundled in; TRI1 invokes none of them, asks for no phone number, and ties no phone number to your identity. We carry no advertising or analytics-tracking SDKs, and we keep third-party code to the least required to deliver a message reliably. Because our release builds are signed with our own key and published with their checksums, anyone can verify the exact binary they installed and inspect what it contains.

4. Data retention & your rights

On your device: your identity, keys, and message history live in the app's local storage. Uninstalling deletes them (and, on Android, revokes your push token).

On our servers: undelivered encrypted mailbox items are removed once delivered, and notification tokens are removed when a device unregisters or a token becomes invalid.

Your rights (incl. GDPR): you have the right to access, rectify, restrict, port, and erase the limited metadata we hold, and to object to processing. To exercise any of these, including deletion of your public-identity record, push tokens, and pending mailbox items, contact us below. Because content is end-to-end encrypted and keys are device-only, we can only ever act on the metadata we hold; the rest is already beyond our reach by design.

5. Privacy & security compliance

TRI1's architecture is engineered on the core principles behind today's leading privacy and security frameworks. We are aligned with the following; these describe our privacy-and-security-by-design approach rather than a claim of formal certification (available on request where your use case requires it):

GDPR-aligned ISO/IEC 27001 principles NIST CSF & 800-53 CIS Controls

6. Children

TRI1 is not directed to children under 13 (or the minimum age in your country, e.g. 16 in parts of the EU). We do not knowingly collect data from children.

7. International transfers

Our servers may process the limited metadata above outside your country. All content remains end-to-end encrypted in transit and at rest on our servers.

8. Changes

We will update this page and the "Last updated" date when this policy changes.

9. Contact

Privacy questions, compliance/attestation requests, or data-deletion requests:
Email: [email protected]
Web app: app.tri1space.com

© 2026 TRI1 · Secure. Private. Yours.
Download  ·  Web App  ·  API  ·  Terms