Privacy Policy

Protection of your personal data

Introduction

OV Message is an encrypted messaging application designed to protect your communications. This privacy policy explains how your data is processed when you use the application.

Fundamental principle: OV Message operates without an intermediary server. Messages are transmitted exclusively via SMS through your mobile operator. No application data transits through or is stored at OV. There is no server on the publisher side capable of collecting or retaining your messages.

Data collected

OV Message does not collect any personal data.

No Data Transmitted

No personal information is sent externally

No Analytics

No tracking, analytics, or audience measurement system

No Advertising

No advertising, no trackers, no marketing tools

No Profiling

No user profile is created or maintained

Locally stored data

The only data that exists is stored locally on your device :

  • Your contacts and their information (name, phone number)
  • Your conversations (encrypted messages)
  • Your encryption keys
  • Your usage preferences (language, settings)

Role of the mobile operator

Messages are transmitted via SMS through your mobile operator. The message content is encrypted and unreadable by the operator.

However, as with any standard SMS, the metadata below is visible to your operator:

  • Sender's phone number
  • Recipient's phone number
  • Date and time of sending

Protected content: Even if an SMS is intercepted, the content of the message remains entirely unreadable without the encryption key shared between you and your correspondent.

Data storage

No remote backup is performed. Cloud backups (iCloud, Google) are disabled by the application.

Secure Hardware Storage

Your encryption keys are stored in your device's hardware-backed keystore (Android Keystore)

Local Encryption

If you set up a password, all your local data is encrypted (AES-256)

Key Management

Generation and management of encryption keys directly on your device

Verified Integrity

Each message is automatically checked to detect any alteration

Warning: If you uninstall the application or lose your device, your data is permanently lost. No remote recovery is possible.

Data sharing

OV Message does not share any data with third parties. No data is sold, rented or transmitted to advertisers, business partners or any other organization.

Required permissions

OV Message requests the following permissions, each for a specific reason:

SMS

To send and receive encrypted messages. This is the main feature of the application.

Contacts

Only if you choose to import contacts from your address book. This operation is local.

Notifications

To inform you of new incoming messages.

Camera

To scan key-sharing QR codes. No photo is stored or transmitted.

Storage

To export encryption keys to a physical medium. No file is sent outside.

On-demand permissions: All permissions are requested at the time they are needed. You may refuse any permission.

Data deletion

You keep total control over the deletion of your data:

Ephemeral Messages

Automatic deletion of messages after a chosen period (5 min to 1 month)

Manual Deletion

You can manually delete conversations at any time

Panic Mode

Instant and invisible destruction of all your data in the event of a threat

Uninstallation

Uninstalling the application deletes all your data

Security

Message encryption

Your messages are encrypted before being sent. Only you and your correspondent, who share the same key, can read the exchanged messages. Even if SMS messages are intercepted by a third party, the content remains unreadable without the key.

Unique Messages

Each message produces a different result, even with the same text

Anti-tampering

Each message is signed to detect any modification

Anti-replay

A message that has already been received is rejected if it is retransmitted (unique HMAC stored per contact)

Hardware Storage

Your keys are protected by your device's hardware vault

Conditional storage encryption: If you set up a login password, your local data (contacts, messages, preferences) is encrypted on your device. Without a password, local data is not encrypted.

User responsibility

The security of your communications depends on the proper management of your encryption keys. The exchange of keys between correspondents is carried out under your responsibility.

Recommendation: We recommend exchanging your keys in person via QR code. For remote pairing, use the integrated post-quantum hybrid system (ML-KEM-768 + X25519) and systematically verify the 8-character SAS code with your correspondent via a trusted voice or video channel: it is this channel that authenticates identity.

You are also responsible for:

  • The backup of your encryption keys (in case of device loss)
  • The choice of a password strong to protect local storage
  • The regular rotation of your encryption keys

Children

OV Message is not intended for children under 13. We do not knowingly collect any data relating to children.

Changes and Contact

Update of this policy

This policy may be updated occasionally. Any changes will be included in an application update. We encourage you to check this page regularly.

Last updated: February 2026

Contact us

For any questions regarding this privacy policy, you can contact us:

Email: contact@ovlabs.fr