RypTyde is an invite-only, end-to-end encrypted messaging app published by Innercross. This policy explains exactly what the app collects, why, who it is shared with, how long it is kept, and how to delete it.
The short version: we cannot read your messages. They are encrypted on your device and we only ever hold the encrypted form. We do not use analytics, advertising, or tracking of any kind, and we never sell or share your data for marketing.
RypTyde is operated by Innercross ("we", "us"). For any privacy question, or to make a request about your data, contact us at info@innercross.com. We are the data controller for the information described below.
RypTyde has no public sign-up. An administrator issues an invite for a specific username, and you claim it by choosing a PIN. Because of that:
yourname@ntouch.app) on a domain that receives no mail. You are never asked for a real email address, and we hold none.| Data | Why we hold it |
|---|---|
| Username, display name, and an account number | To identify you to other members and let them start a conversation with you. |
| Profile photo, if you set one | Shown to other signed-in members. Stored in a private bucket that requires a valid session to read. Unlike messages, profile photos are not end-to-end encrypted. |
| Public encryption key | Published so others can encrypt messages to you. It is public by design and reveals nothing on its own. |
| Encrypted message content and attachments | Stored so your conversations sync and are delivered. We hold only ciphertext (see section 4). |
| Conversation membership, read state, and mute settings | To show which chats you are in, what is unread, and which you have silenced. |
| Security question and answer | Used to verify a PIN-reset request. The answer is stored only as a salted bcrypt hash. |
| Push notification token and an app session identifier | To deliver notifications to your device. The session identifier is generated by the app and is not a permanent hardware or advertising ID. |
| Moderation records | Reports you submit or that concern you, and a log of administrator actions such as kicks, bans, and PIN resets, kept so moderation decisions are accountable. |
| Invite record | Which invite code was used and when, so a code cannot be reused. |
Presence ("active now") and typing indicators are transmitted live between devices and are not retained as history. You can turn presence off in Settings.
Messages and attachments are encrypted on your device before they are sent, using X25519 key exchange with XSalsa20-Poly1305 authenticated encryption. Each message gets its own random key, which is then wrapped separately for every recipient. Our servers store only the encrypted result.
We cannot read your messages, and neither can anyone who obtains our database. We have no key that decrypts them.
Your private key is generated on your device and never leaves it in readable form. On iOS it is stored in the system Keychain. Because it is stored with standard Keychain protection rather than device-only protection, it can be included in your iCloud Keychain and in encrypted device backups. This is deliberate: it is what allows you to keep your message history when you replace your phone. It also means someone with full control of your Apple account could potentially reach it. If that is not an acceptable trade-off for you, disable iCloud Keychain on your device.
If you take a screenshot while viewing a conversation, RypTyde posts a notice into that conversation telling the other participants. This is a feature of the product, not a security guarantee — you should assume anything you send can be captured by other means.
We do not sell, rent, or trade personal data. We share it only with the service providers needed to run the app, each of which is bound by contract to protect it to a standard at least equivalent to this policy and to process it only on our instructions:
Because message content is end-to-end encrypted, these providers hold only ciphertext for your conversations. We may also disclose information if required by law, or where necessary to protect the safety of our users.
You can delete your account at any time, from inside the app: Settings → Delete my account. You will be asked to type your username to confirm. Deletion is immediate and cannot be undone.
When you delete your account we permanently erase your username, display name, profile photo, account identifier, PIN, security question and answer, push notification tokens, blocks and mutes, read state, and your personal copies of message keys. Your login is destroyed and every active session is ended. Your invite code is retired and cannot be used again.
One thing is deliberately retained: a single record holding your public encryption key. Messages you sent to other people can only be opened using it, so destroying it would make their copies of your past conversations permanently unreadable — it would delete their history as well as yours. That record carries no name, no photo, and no way to identify you; messages you sent appear to their recipients as coming from "Deleted user".
If you cannot access the app, email info@innercross.com and we will action the deletion for you.
Inside the app you can change your PIN and profile photo, turn your presence indicator off, mute conversations, and block other members. You can request a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it, by emailing info@innercross.com. Depending on where you live, you may have additional rights under laws such as the GDPR or the CCPA, including the right to object to processing and the right to lodge a complaint with your local data protection authority. We respond to requests within 30 days.
We process your data to provide the messaging service you asked for, to keep it secure, and to moderate it — in legal terms, to perform our contract with you and for our legitimate interest in running a safe service.
Message content is end-to-end encrypted. PINs and security answers are stored only as salted bcrypt hashes. Profile photos and attachments are held in private storage that requires an authenticated session. Access to sensitive records is restricted at the database level, and administrator actions are logged. No system is perfectly secure, but we design on the assumption that our own servers could be compromised — which is why we cannot read your messages.
RypTyde is not directed to children and is not intended for anyone under 13. Accounts are issued by invitation only. If you believe a child under 13 has been given an account, contact us and we will remove it.
Our service providers may process and store data in countries other than your own, including the United States. Where data is transferred out of the UK or European Economic Area, we rely on appropriate safeguards such as the European Commission's standard contractual clauses.
If we change this policy we will update the date at the top of this page, and for significant changes we will notify you inside the app. Continuing to use RypTyde after a change means you accept the updated policy.
Innercross
info@innercross.com