privacy & support
privacy, data & funds
Your funds and private conversations belong to you. Glyphteck Corp cannot access or control your funds and cannot decrypt private messages between user-controlled accounts. veyl is built so those limits come from the architecture, not merely from policy.
your funds are never ours
Glyphteck Corp never receives your vault password, decrypted seed, or wallet private signing keys. It cannot access, spend, freeze, transfer, reverse, recover, or otherwise control your funds. Glyphteck Corp does not and will not take custody of user funds through veyl, and funds shown through veyl are not held for you by Glyphteck Corp.
Wallet actions are initiated from your locally unlocked vault. The wallet client communicates with Spark, Bitcoin, and related network infrastructure, which may process network or payment information under their own terms. Public blockchain records are permanent and are not controlled by Glyphteck Corp.
private messages stay private
Messages and attachments exchanged between user-controlled accounts are encrypted on the sending client. Glyphteck Corp relays and stores ciphertext but does not possess the private keys needed to decrypt the conversation. Glyphteck Corp does not operate a master key, key escrow, or message backdoor and will keep veyl unavailable in any jurisdiction that requires one.
Glyphteck Corp can receive message content only when a participant deliberately shares it, such as by submitting a report, attaching evidence, or contacting support. A message deliberately sent to a Glyphteck-operated bot or account is readable by that recipient, just as a message sent to any other recipient is; it is not accessible to the relay as part of an unrelated private conversation.
what we can see
To operate veyl, Glyphteck Corp processes an account identifier; your username, avatar, public wallet and chat keys, and presence state; passkey public credential records; notification and device records; settings and policy acknowledgements; and service identifiers used for authentication, delivery, sync, and abuse prevention.
The service also processes limited operational information such as sender and recipient account identifiers when routing a notification, timestamps, opaque chat or message identifiers, retention deadlines, upload sizes, network request information, and short-lived hashed security or rate-limit signals.
Glyphteck Corp stores an encrypted vault backup, encrypted message bodies, encrypted chat state, and encrypted attachment bytes. Possessing those encrypted records does not give Glyphteck Corp the secrets required to read them.
Camera, photo, and notification access is controlled through your device. Biometric unlock is handled locally by the device operating system; Glyphteck Corp does not receive your Face ID data or raw biometric template.
what you choose to share
Reports, report notes and evidence, support requests, feedback, and bug reports may contain readable information because you choose what to submit. Glyphteck Corp uses that information only to respond, investigate, enforce the community rules in the Terms, protect the service, or comply with law.
Do not send your vault password, seed, private keys, or other recovery material to Glyphteck Corp. Support does not need them and cannot safely use them to recover your wallet.
how long data remains
Account, public profile, passkey, push, settings, and encrypted vault records remain while your account exists. Temporary authentication challenges normally expire within minutes, and operational security counters expire automatically after their short enforcement windows.
the default is after-seen deletion. in direct chats and groups of up to 32 members, an unsaved message disappears from your device’s chat view when you leave after everyone in that message’s original membership group has seen it. an open chat can keep it visible until you leave. removing hosted ciphertext is a separate step.
the optional 24-hour setting starts its timer when a client leaves after those reads and can commit cleanup with no other observed chat connections. it does not start at sending or the first receipt. once stored, the deadline is not extended by later reads or reopening the chat.
new unsaved messages under the after-seen or 24-hour setting have a 21-day deadline from creation, even if unopened. that deadline takes precedence if the 24-hour timer would end later. groups over 32 members do not use read-based expiry; notes also use the 21-day deadline under the default setting.
saving is shared: any current participant can save eligible messages for everyone, giving them no automatic expiry. any current participant can also unsave or delete messages they can access, or delete the chat for everyone. unsaving sets a fresh 21-day deadline that read-based expiry can shorten. forwarded and view-once attachments cannot be saved.
saving or unsaving an original attachment changes its hosted file expiry together with the message. automatic after-seen or 24-hour message expiry does not shorten the independent file deadline: unsaved encrypted files may remain for up to 21 days from upload, or from unsaving. forwards reuse the original file; deleting the original attachment or its chat makes uncached forwards unavailable.
official clients hide expired messages, but open chats, offline clients, or uncertain chat activity can defer shortening the stored deadline until the 21-day limit. database cleanup removes message ciphertext asynchronously, so it can remain fetchable after expiry. expired or deleted media receives no new download grants; existing grants can last up to 15 minutes unless the file is removed sooner. workers remove active file bytes asynchronously, and opaque deletion records can remain.
deletion from active systems is separate from provider retention. production media storage retains deleted ciphertext for seven days through provider soft deletion. the production message database reports a one-hour version-retention window. these windows do not establish a physical-erasure deadline for every provider backup or log.
Reports, evidence, feedback, bugs, and support communications remain only while needed to review and act on them, unless the associated account is deleted sooner or law requires a limited record to be retained.
account deletion
Account deletion starts immediately. Data associated with the account is normally removed from active systems during the request; remaining active-system cleanup may take up to 48 hours.
account deletion removes account, profile, credential, encrypted vault, and encrypted owner records, and deletes notes and direct chats. it leaves group chats for remaining participants: their retained history, including saved messages, is not erased just because one participant deletes their account. a group is deleted when its last participant leaves.
Limited information may remain where reasonably necessary for security, fraud prevention, legal compliance, dispute resolution, service integrity, backups, or the rights and records of other users and third-party networks. Retained information is removed or de-identified when it is no longer needed.
deletion cannot revoke plaintext or ciphertext already copied by a recipient, an agent or its model provider, content saved outside veyl, provider records retained under their rules, evidence deliberately submitted in reports or support requests, or payments published to a blockchain.
Account deletion can permanently destroy your ability to reach funds if you have not preserved your own recovery material or moved the funds first. Glyphteck Corp cannot restore deleted wallet secrets or recover the funds afterward.
sharing, providers & requests
Glyphteck Corp does not sell personal data, operate an advertising network, or disclose personal data for behavioral advertising or data brokerage. Limited service data is disclosed only to intended recipients, infrastructure providers needed to run veyl, wallet or network providers involved in an action you request, a successor to the business, or a party entitled to it by valid legal process.
Providers may include authentication, database, storage, hosting, abuse-protection, notification, Apple platform, Spark, and Bitcoin-network infrastructure. Their systems and retention practices are not controlled by Glyphteck Corp. Glyphteck Corp can disclose only information it actually possesses and cannot produce wallet secrets or decrypt private conversations it cannot access.
your controls
You may change your public profile and settings, manage device permissions, block another account, stop using veyl, or delete your account. You may contact Glyphteck Corp to ask about readable account data it holds, request correction, or raise a privacy concern. Glyphteck Corp cannot produce or recover encrypted or deleted material it cannot decrypt or no longer possesses.
age, availability & changes
veyl is for people age 13 and older and is not directed to children under 13. If Glyphteck Corp learns that an account belongs to a child under 13, it will delete the account and associated information. A teenager who cannot lawfully consent to the limited data handling described here may use veyl only after a parent or guardian provides any permission required by local law through a method Glyphteck Corp makes available.
veyl is offered only in jurisdictions Glyphteck Corp designates. It is not offered in the European Economic Area, the United Kingdom, or Switzerland. Service infrastructure may operate in other locations even when the user is in an available jurisdiction.
No system can be guaranteed perfectly secure or continuously available. Glyphteck Corp may update this notice as veyl changes and will post the revised effective date. Material changes will be presented through the service when appropriate.
support & legal requests
Support can help with the parts of veyl that Glyphteck Corp operates. It cannot bypass the privacy and self-custody boundaries built into the product.
what support can do
Support can address account access, public profiles, app behavior, service availability, account deletion, policy questions, reports, and legal or safety requests. Support can review only the service information Glyphteck Corp possesses and the evidence you choose to provide.
Glyphteck Corp may ask you to reproduce a technical problem using the current Official Client and may decline to troubleshoot behavior caused by a Modified or Unofficial Client. That technical-support boundary does not prevent you from submitting account, legal, privacy, or safety requests concerning services Glyphteck Corp operates.
what support cannot do
Support cannot access or move your funds, recover a seed or private key, reveal a vault password, reverse a payment, decrypt a private conversation between user-controlled accounts, or retrieve content that has been deleted or was never available to Glyphteck Corp.
TAKE IT DOWN Act & removal requests
Veyl accepts TAKE IT DOWN Act requests at contact@glyphteck.com. A depicted person or an authorized representative should email: their typed full name as an electronic signature; information reasonably sufficient for Veyl to locate the image or video, including relevant Veyl usernames and chat or message source identifiers when available; a brief good-faith statement that the depiction includes them and was published without their consent; and contact information for a reply. Do not send passwords, seeds, private keys, or wallet recovery material.
For a valid request concerning hosted content Veyl can locate, Glyphteck Corp will disable access as soon as possible and no later than 48 hours and will make reasonable efforts to identify and remove known identical copies. A participant should use the in-app report control when available because it supplies the exact opaque source identifiers and selected evidence needed to locate the hosted chat.
Ordinary private conversations are end-to-end encrypted, so Glyphteck Corp cannot search unreported plaintext or discover unknown encrypted copies. It may delete an exact reported chat and restrict an account from server chat access, but it cannot erase a copy another person already downloaded to a device.
account deletion help
Use Settings > Delete Account to request deletion. If the control fails, contact support from the account when possible. Deletion from active systems may take up to 48 hours as described in the data and funds section.
open-source notice
This product includes icons from the Lucide project.
ISC License. Copyright (c) for portions of Lucide are held by Cole Bemis 2013-2022 as part of Feather (MIT). Copyright (c) 2022-present Lucide Contributors.
Permission to use, copy, modify, and/or distribute this software for any purpose with or without fee is hereby granted, provided that the copyright notice and permission notice appear in all copies.
The software is provided as is and the author disclaims all warranties with regard to this software including all implied warranties of merchantability and fitness.
contact
Use the official Glyphteck contact below for veyl support, legal notices, safety requests, arbitration opt-outs, and account deletion assistance. Privacy questions, access or correction requests, and complaints may be addressed to Glyphteck Corp, Attention: Privacy Officer, through the same contact. Do not send passwords, seeds, private keys, or recovery material.