LEGAL

Privacy Policy

Back to Main Site

Last updated: 16 June 2026

1. Introduction & Who We Are

DM NATIVE ("DM NATIVE", "we", "us", "our") provides an end-to-end encrypted messaging application available on iOS and Android. This Privacy Policy explains what information we process, why, and the choices and rights you have. For the purposes of the EU/UK GDPR we are the data controller for the limited account data described here. For any privacy question, or to exercise your rights, contact us at info@dmnative.com.

2. Our Privacy Model (the Short Version)

Messages, calls, and media are end-to-end encrypted using the Signal Protocol. The keys that protect them are generated and stored on your device, so our servers only relay ciphertext and cannot decrypt it. We do not read your messages, we do not sell your data, and we collect only the minimum information needed to run the service. Data is encrypted in transit (TLS 1.3) and end-to-end between devices.

3. Information You Provide

Required to create an account: a phone number or email address (stored only as a one-way hash for verification and contact discovery), a display name / username, and your public cryptographic keys. Optional: a profile photo, and — for contact discovery — your address-book contacts, which are matched using hashes and are never uploaded or stored in plaintext.

4. Information We Collect Automatically

Device & push: a device identifier and push token, used solely to deliver notifications. Diagnostics (Sentry): OFF by default. If you opt in (the same Settings → Privacy switch as analytics), crash and performance data — never message content — helps us keep the app stable. Both crash reporting and usage analytics are governed by that single consent, off until you enable them. Usage analytics (Mixpanel): covered by the same opt-in. If enabled, it records anonymised product-interaction events (for example, that a feature button was tapped) — never the content of a message. Operational metadata: the minimum routing/delivery data needed to move encrypted messages between devices.

5. Information We Do NOT Collect

We do not collect or have access to the content of your messages, calls, or media (all end-to-end encrypted), and we do not upload your contacts in plaintext. We cannot read, scan, or hand over content we do not hold.

6. How We Use Information & Legal Bases

We use your information to create and operate your account and deliver messages (legal basis: performance of our contract with you); to keep the service secure, reliable, and free from abuse (legitimate interests); to send notifications and run optional features you enable (your consent); and to comply with legal obligations. You can withdraw consent at any time.

7. AI & Optional Features

Writing-style suggestions run on your device; your message history is never uploaded to train them, and the feature is opt-in. AI features are OFF by default — reply suggestions, translation, AI voice notes and transcription do nothing until you turn them on in Settings → Privacy, and while off nothing is sent for AI processing. When you DO enable and use one, here is exactly what happens: when you invoke one, the specific text for that request leaves your device and is decrypted for processing on our own secure edge infrastructure (Cloudflare Workers AI) — it is not sent to Google, DeepL, or any other outside AI company. Our edge necessarily handles that text in readable form for the duration of that single request. It is processed transiently, not retained, and not used to train models or profile you. AI voice notes are synthesized from the text you type — at the network edge, with your device's built-in speech engine as fallback. No recording of your voice is ever made or uploaded.

8. Service Providers (Sub-processors)

We share the limited data above only with vetted providers who process it on our behalf: Cloudflare (edge infrastructure, encrypted media storage, and edge AI for optional translation/suggestions); Twilio (sending SMS verification codes); Resend (sending email verification codes); Google Firebase Cloud Messaging (push notifications); Mixpanel (in-app usage analytics, opt-in only); Sentry (crash diagnostics); Trustpilot (sending review invitations by email — if you register with an email address, it is shared so Trustpilot can invite you to review us; nothing else is shared). Optional translation and reply suggestions run on Cloudflare Workers AI — our own edge infrastructure, not a separate third-party AI company. When calls cannot connect peer-to-peer, encrypted call media may be relayed via a TURN server; the relay never has your keys. We do not sell your data to anyone.

Website analytics: our website (dmnative.com) uses Cloudflare Web Analytics, which is privacy-first and cookieless — it sets no cookies and collects no personal data, so there is nothing to opt out of because nothing personal is collected. We do not use Google Analytics, Google Tag Manager, advertising pixels, or any cross-site trackers.

9. International Transfers

Our infrastructure runs on Cloudflare's global edge network and our providers may process data in the United States and other regions. Where required, such transfers are protected by appropriate safeguards (for example, Standard Contractual Clauses).

10. Data Retention

Encrypted messages are stored only until delivered, then removed. If you delete your account, we apply a 30-day grace period, after which your profile data, account identifiers, and any models are permanently purged. Routing metadata (delivery records) is retained for a maximum of 90 days for spam prevention and legal compliance, then automatically deleted. Diagnostics and analytics are kept only as long as necessary for the purposes above.

11. Your Rights

Subject to applicable law (including the GDPR and the CCPA), you have the right to access, correct, delete, export (port), restrict, or object to the processing of your personal data, and to withdraw consent at any time. We do not sell or share your personal data for cross-context behavioural advertising. To exercise any right, email info@dmnative.com, or delete your account directly in the app under Settings → Delete Account. You also have the right to lodge a complaint with your local data-protection authority.

12. Security

We protect your data with end-to-end encryption (an implementation of the Signal Protocol's X3DH + Double Ratchet) and TLS 1.3 in transit. On your device, your data is protected by your phone's built-in encryption and DM NATIVE's app isolation, with your encryption keys held in your device's secure hardware. Because your keys never leave your device, we cannot read your messages. DM NATIVE uses X3DH + Double Ratchet today, with a post-quantum (PQXDH) migration on our roadmap. Nothing third-party runs, and nothing leaves your device for analytics, crash reporting or AI, until you turn it on. No system is perfectly secure, but we design to minimise what we hold so there is little to expose.

13. Children

DM NATIVE is rated 13+ and is not directed to children under 13 (or the higher minimum age of digital consent in your country). We do not knowingly collect data from children below that age; if you believe a child has provided us data, contact us and we will delete it.

14. Changes & Contact

We may update this policy; material changes will be reflected by the "last updated" date above and, where appropriate, notified in the app. Questions or requests: info@dmnative.com.