🔒 CLASSIFIED DOCUMENT

PRIVACY POLICY

DeltaFox is engineered from the ground up with zero-knowledge architecture. End-to-end encryption ensures that only you and your recipients can access your communications.

LAST UPDATED: 2026-03-26 // CLASSIFICATION: PUBLIC
🏛

01 // Data Controller

Pursuant to Art. 13 and 14 of EU Regulation 2016/679 (GDPR), the Data Controller is:

DeltaFox is an independent project. No Data Protection Officer (DPO) is designated as the processing does not fall within the cases provided for by Art. 37 GDPR.

🛡

02 // Overview

DeltaFox is a self-hosted, end-to-end encrypted messaging platform. We are committed to protecting your privacy and ensuring your personal data remains under your exclusive control. This Privacy Policy is provided pursuant to Art. 13 of EU Regulation 2016/679 (GDPR) and Italian Legislative Decree 196/2003 (Privacy Code), as amended by Legislative Decree 101/2018.

👤

03 // Data We Collect

Account Information

Messages & Media

ALL MESSAGES ARE END-TO-END ENCRYPTED — WE CANNOT READ THEM

Technical Data

Data We Do NOT Collect

🚫 NO ANALYTICS // NO TRACKING // NO ADVERTISING // NO PROFILING

04 // Legal Basis (Art. 6 GDPR)

We process your personal data based on the following legal grounds:

🔐

05 // Encryption

DeltaFox uses the Signal Protocol for 1:1 messages and Sender Key protocol for groups:

X3DHDouble RatchetCurve25519NaCl SecretBoxEd25519DTLS-SRTPCertificate Pinning
🤖

06 // LILITH IA

Lilith IA
LILITH IA
DeltaFox's built-in AI assistant, powered by Anthropic Claude.
👁

07 // Data Usage

🚫 WE DO NOT SELL, SHARE, OR MONETIZE YOUR DATA

08 // Data Retention

We retain your data only for as long as strictly necessary:

🌐

09 // Third Parties & International Transfers

Some data is processed by third-party services. Where data is transferred outside the EU/EEA, it is protected by Standard Contractual Clauses (SCCs) approved by the European Commission, or by an EU adequacy decision:

📜

10 // Your Rights (Art. 15-22 GDPR)

Under GDPR, you have the following rights regarding your personal data:

To exercise your rights, contact us at:

info@deltafoxxx.it

We will respond within 30 days as required by Art. 12(3) GDPR.

🏛

11 // Right to Lodge a Complaint

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Italian Data Protection Authority:

🗑

12 // Deletion

Profile → Delete Account (irreversible)

🛡

13 // Security Measures (Art. 32 GDPR)

Pursuant to Art. 32 GDPR, we implement appropriate technical and organizational measures:

📱

14 // App Permissions

🤖

15 // Automated Decision-Making (Art. 22 GDPR)

DeltaFox does not use automated decision-making or profiling that produces legal effects or similarly significant effects on users. The only automated processes are rate limiting and progressive lockout on authentication endpoints, which are necessary security measures.

👶

16 // Children (Art. 8 GDPR)

DeltaFox is not intended for children under 16 years of age (in accordance with Art. 8 GDPR and Italian implementation setting the age at 14). We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will delete it immediately.

🔄

17 // Policy Updates

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date. For significant changes, we will notify users through the app. We encourage you to review this policy periodically.

📧

18 // Contact

For questions about this Privacy Policy or to exercise your data protection rights: