Privacy Policy
AKARUP is an end-to-end encrypted messenger. This policy describes, without ambiguity, the data we process and the data our servers can never access.
Last updated: June 28, 2026
Data controller
AKARE SARL, a limited liability company with share capital of €4,180, registered with the Paris Trade and Companies Register under number 495 145 898, with its registered office at 12 rue Vivienne, 75002 Paris, France. VAT number FR76495145898. Legal representative: Pascal Pommier.
For any question regarding your data or to exercise your rights, a single point of contact: [email protected].
Our principle: the server is blind to content
AKARUP is built on post-quantum end-to-end encryption. The content of your communications is encrypted on your device before it is ever sent, and can only be decrypted on the recipients' devices. Our servers transport and store this content as encrypted envelopes that they are technically unable to read.
In practice, we never have plaintext access to: your messages, your shared images and files, the content of your storage space, your backups, or the profile information you encrypt (display name, avatar, biography). These are protected by the ML-KEM-768 (FIPS 203), ML-DSA-65 (FIPS 204), XChaCha20-Poly1305 and AES-256-GCM algorithms.
Data actually processed by our servers
A minimal amount of technical data is required to run the service. In the interest of transparency, here is the exact list:
Account data
Your email address (in plaintext, required to send you the 6-digit verification codes during sign-up and account recovery), your username, and a cryptographic hash of your password. We never store your password in plaintext.
Public keys
The public keys of your devices (identity keys and post-quantum ML-KEM-768 keys). These are public keys by nature: sharing them is the very foundation of encryption and reveals no secret.
Encrypted envelopes
Your messages, files and profile data, stored exclusively in encrypted form, unreadable by our servers.
Push notifications
If you enable notifications, a technical token provided by Apple's or Google's notification services is stored to alert you of new messages. This token is linked to opaque identifiers, and the notification never contains the message content.
Temporary security data
During sign-up or recovery, the 6-digit codes are stored only in hashed form (bcrypt), with a 15-minute expiry, then deleted. Your account recovery key is stored encrypted by a key derived from your recovery phrase: our servers cannot decrypt it.
Technical connection metadata
Like any online service, your IP address is processed by our host and network provider to route traffic. We minimize the retention of such metadata.
Hosting and data location
All data is hosted in France, with Scaleway. No data is transferred outside the European Union. Network distribution and transport security (TLS) are provided by Cloudflare, which processes the connection metadata (IP address) required for routing.
Sub-processors
We rely on a limited number of technical providers:
- •Scaleway (France): infrastructure and database hosting.
- •Cloudflare: network routing, protection and transport encryption (TLS).
- •Apple Push Notification service and Google Firebase Cloud Messaging: notification delivery, if you enable it.
Purposes and legal bases
Data is processed solely to provide the messaging service (performance of the contract), for account security (legitimate interest and legal obligation), and to send verification codes (performance of pre-contractual and contractual measures). We carry out no advertising profiling, sell no data, and display no advertising.
Retention period
Your account data is kept for as long as your account is active. Verification codes expire within 15 minutes. When you delete your account, your associated data is erased from our servers.
Your rights
Under the General Data Protection Regulation (GDPR), you have the rights of access, rectification, erasure, restriction, objection and portability regarding your data. The app lets you export your settings and delete your account directly. For any other request, write to [email protected].
You may also lodge a complaint with the French data protection authority (CNIL).
Changes
This policy may be updated to reflect changes to the service. The last update date appears at the top of this page.