Privacy Policy — P2P Zero-Trust Chat

Privacy Policy

Last updated: June 2026

This Privacy Policy describes how P2P Zero-Trust Chat (“the Extension”, “we”, “our”) handles information when you use our Chrome extension.

Summary

Data stored on your device

The Extension stores the following locally in your Chrome browser profile (chrome.storage.local and related APIs):

DataPurpose
Private & public key pairsEncryption and message signatures
Saved chat rooms & message historyDisplay your conversations (decrypted locally)
Verified peers (SAS)Remember trusted contacts
UI settings (language, notifications, layout)Your preferences
Unread countersBadge on extension icon

This data remains on your device until you remove the Extension or clear extension data. We cannot access it remotely.

Data on signal.vlk.by (signaling server)

Our signaling service helps two browsers discover each other and exchange WebRTC setup data. It is not a messenger.

DataRetentionPurpose
Public keys~2 minutesHandshake
Room membership hashes~5 minutesPeer discovery
WebRTC offers / answers / ICE~5 minutesEstablish P2P
Magic invite sessions~30 minutesShort invite codes

Not stored on the server: chat message text, private keys, accounts, passwords, or permanent chat history.

vlk.by (optional)

If you choose to shorten a long URL in the chat composer, only that URL is sent to vlk.by. Chat content is not transmitted through this service.

Permissions

Children

The Extension is not directed at children under 13. We do not knowingly collect personal information from children.

Changes

We may update this policy. The “Last updated” date will change accordingly. Continued use after changes constitutes acceptance.

Contact

Questions about privacy: support@vlk.by or our support form.