Cove Privacy Policy

Updated: July 20, 2026

1. Overview

Cove is an end-to-end encrypted messenger. Our baseline: your conversations belong to you. Private keys are generated and stored only on your devices, and ordinary messages are relayed as ciphertext that we cannot read. We collect the minimum data needed to run the service, and we do not sell data or show ads.

2. What we collect and store

DataPurposeRetention
Stable identifier from Sign in with AppleIdentifies your account; your Contact ID is derived from itLife of account
Nickname, avatar, and gender (optional, user-set)Shown to other users; stored in plaintextLife of account
Cove contact, message-request, and block relationshipsManages your Cove social graph; Cove does not read the system address bookLife of account
Contact ID lookup historyUser search, abuse prevention, and troubleshootingShort-term rolling
Device public-key directory (identity keys and prekeys)Lets contacts establish end-to-end encrypted sessions with youLife of account/device
Encrypted private account state (opaque ciphertext: which chats you pin or mute, contact aliases, disappearing-message preferences, view-once consumption)Syncs your own private settings between your devices. The key lives only on your devices, so Cove stores this as ciphertext it cannot readLife of account; removed with the account
In-transit encrypted messages (ciphertext)Offline deliveryDeleted about 1 hour after confirmed delivery
Encrypted attachments (ciphertext)Photo, video, voice, and file transferAbout 30 days
Push tokens (APNs / VoIP)Message and call notificationsLife of device
Push-notification metadataMay include the sender's self-published nickname; call wake-up also includes an internal sender ID and short-lived call ID. Private contact aliases are never sent to AppleHandled by Apple under its policies
Online status and last-seen timeShows your friends whether you are online (a live realtime connection counts as online); visible only to mutual friends who are not blockedLife of account
Message evidence you disclose when filing a reportAbuse handling (the only case where moderators can decrypt what you chose to disclose)Up to 90 days
Communication metadata (sender, recipient, time, size) and request logs (incl. IP)Routing, anti-abuse rate limiting, troubleshootingShort-term rolling
Aggregated, anonymized usage countersOperationsAggregates kept long-term

3. What we do not collect

We do not and cannot collect plaintext messages or attachments. We do not read your system address book or collect your phone number, email address, or location. We use no advertising identifiers and no third-party tracking SDKs. Friend aliases live in encrypted local storage, your encrypted backup, and end-to-end encrypted device sync; legacy server-side aliases are deleted after encrypted migration. Push notifications contain no message plaintext, but Apple can observe the routing fields listed in Section 2. We do not run ads and never sell data.

4. How encryption protects your content

Message content, attachments, and private account state are encrypted on your device before they reach us, using X3DH-style key agreement with a double-ratchet protocol. Each linked device has its own encryption identity, and you can verify contacts by comparing safety numbers in the app. What our servers can see is routing metadata (sender, recipient, time, size), the device public-key directory, group membership, and the public profile fields you choose to set — not the content of your conversations.

5. Voice and video calls

Calls are one-to-one and end-to-end encrypted: voice calls, with video calling where available. Call media flows peer-to-peer when possible (the other party can learn your network address); otherwise our relay forwards the encrypted stream. We do not record calls and cannot decrypt them.

6. Backups

Backups are optional and always encrypted on your device before they leave it. A backup is an encrypted file you export, store, and manage yourself — Cove keeps no server-side copy of your chat history. Every backup is protected by a passphrase or recovery code, and Cove never receives the passphrase, recovery code, or decryption key — if you lose both, no one, including Cove, can open the backup.

7. Service providers and sharing

Service providers process only what is needed to deliver a feature: Apple (APNs) delivers push notifications; hosting and object-storage providers process server data and ciphertext. We do not sell data and do not share it for third-party advertising.

8. Legal requests

If we receive a valid legal request, we can produce only the data listed in Section 2. Ordinary message content remains ciphertext that we cannot decrypt; the only content we could ever produce is report evidence a user voluntarily disclosed, within its 90-day retention window.

9. Your rights and controls

You control your data from within the app: you can export your chat history as an encrypted backup file and delete your account under Me → Account → Delete Account. Account deletion removes the account, devices, push tokens, queued ciphertext, and attachments, and wipes the current device's chat history and encryption identity. Reports already submitted, and their minimum identity snapshots, may remain for the retention period in Section 2 so that deleting an account cannot destroy abuse evidence. Deletion is irreversible. For any other privacy request, contact us at the address in Section 12.

10. Children

The service is not directed at children under 13 (or the higher minimum age required in your jurisdiction), and we do not knowingly collect personal data from them.

11. Changes to this policy

Updates are published on this page with a new effective date. For material changes, we will make the update reasonably visible, and the change history follows the effective date shown above.

12. Contact

Questions about privacy or this policy: [email protected]