TL;DR — The honest version
Privilio is an end-to-end encrypted contact manager. Your contacts, notes, and vault are encrypted on your device with a key derived from a passphrase only you know, then synced across your devices. We store only ciphertext — we cannot read your contacts, and we never receive your passphrase. We don't sell your data and we don't advertise. We comply with valid Canadian legal orders, but all we could ever produce is encrypted bytes that are mathematically useless without your passphrase.
1. Who we are
Privilio is published by Adapting Services Limited, a company incorporated in Ontario, Canada. References to "Privilio", "we", "us", or "our" in this policy refer to Adapting Services Limited. Our principal address is in Ontario, Canada. You can reach us at privacy@privilio.ca.
2. What data we collect
The key point: we store only ciphertext. Your contacts, tags, notes, and vault are encrypted on your device with a key derived from your passphrase before they are sent to us. We never receive your passphrase or your unencrypted data, and we cannot decrypt what we store.
Account data
To sync your encrypted data across your devices, we store:
- Your email address or account identifier (used to sign in)
- Authentication data needed to verify it's you — we never store your passphrase in a form we can read
- Sync metadata such as record timestamps and device/sync identifiers
Your encrypted contacts
What we actually hold for sync is the encrypted ciphertext of your contacts, tags, and notes (including anything in your vault). This ciphertext is unreadable without your passphrase, which we never have. We cannot see names, companies, notes, or any other contact content.
Operational data
- IP addresses (retained briefly for security and abuse prevention, then deleted)
- Error logs (no contact content included)
We do not collect: your unencrypted contacts or notes, browsing behaviour, device fingerprints, advertising identifiers, location data, or analytics about how you use the app beyond what's stated here.
3. How we use your data
We use the limited data we hold only to:
- Authenticate you and sync your encrypted contacts across your devices
- Operate, secure, and maintain the service
- Respond to support and privacy requests
- Detect and prevent abuse
We do not use your data for advertising, profiling, or sale — and because your contacts are encrypted, we couldn't read them for those purposes even if we wanted to.
4. Data sharing
We don't sell, rent, or share your personal information with advertisers or data brokers. The only third parties involved are:
- Our hosting/infrastructure provider — stores your encrypted ciphertext and account data on our behalf (they cannot read it either)
- Apple App Store / Google Play — distribute the app and process any purchases under their own policies
- Legal authorities — only when required by valid Canadian legal process (see Section 7)
5. Data retention
- Encrypted contacts, notes & vault: Retained (as ciphertext) until you delete them or close your account.
- Account data: Retained until you delete your account.
- IP logs: Retained briefly for security, then automatically deleted.
When you delete your account, your encrypted data is permanently deleted within 30 days. You can also export your data to a JSON file at any time from Settings.
6. Your rights (Canadian and international)
Under PIPEDA (Canada's federal privacy law), applicable provincial laws, and the GDPR (for EEA residents), you have rights to access, correct, delete, and port your personal data. In Privilio's case these rights are largely satisfied by the app itself:
- Access & portability: export all your data to a JSON file from Settings
- Correction: edit any contact directly in the app
- Deletion: delete contacts individually, or wipe everything from the "Danger zone"
- Complaints: you may contact the Office of the Privacy Commissioner of Canada
To exercise any of these rights, contact us at privacy@privilio.ca. Note that because your contacts are end-to-end encrypted, we can act on your account and ciphertext but cannot read or alter the contents ourselves.
7. Law enforcement requests
The honest answer: We comply with valid court orders issued by Canadian courts. But because of our zero-knowledge design, the only data we could ever produce is your account identifier and your encrypted contacts — ciphertext that is mathematically unreadable without your passphrase, which we never receive. If you forget your passphrase, even you cannot recover your data. This is not a limitation — it is the point.
8. Security
Privilio's security comes from end-to-end encryption — we store only what we can't read. Specifically:
- Your contacts, notes, and vault are encrypted on your device with a key derived from your passphrase, before anything is synced
- Our servers store only ciphertext; your passphrase and encryption keys never reach us
- Vault contacts are additionally protected by a 4-digit PIN you set (changeable or removable in Settings)
- All data in transit is protected with TLS
- You can export a JSON backup and delete all your data at any time
Keeping your passphrase safe is essential — it is the only key to your data, and we cannot reset or recover it. If you discover a security vulnerability, please report it to security@privilio.ca — we respond within 48 hours.
9. Children
Privilio is not directed to children under 13 (or under 16 in the EEA). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact privacy@privilio.ca and we will delete it.
10. Changes to this policy
We may update this policy from time to time. We will post significant changes within the app or on this page at least 30 days before they take effect. Your continued use of Privilio after the effective date constitutes acceptance of the updated policy.
11. Contact
For privacy-related questions or requests:
- Email: privacy@privilio.ca
- General: hello@privilio.ca
- Security: security@privilio.ca
- Company: Adapting Services Limited, Ontario, Canada