Last Updated: July 16, 2026
InnerRing (“we,” “our,” or “us”) is a privacy-first 1:1 messaging app for close friends and family. This Privacy Policy applies to the InnerRing app and its public legal pages. It explains what data we process, why we process it, how long we keep it, and what choices you have.
InnerRing does not use phone numbers, email addresses for account identity, public user search, advertising, analytics, or cross-app tracking. Accounts are accessed with a recovery key.
Ordinary message contents are end-to-end encrypted, and we cannot read their plaintext from our backend. If you voluntarily submit a message report, the app sends a plaintext snapshot of that selected message to our backend for safety review. That reported snapshot is no longer protected from us by message end-to-end encryption, although it is protected in transit by HTTPS/TLS and handled as restricted safety-report data.
We do not receive or store your full payment card details. App Store purchases, billing, refunds, and payment processing are handled by Apple.
We use your information to:
We do not sell personal data. We do not use your data for advertising. We do not track your behavior across other apps or websites.
For users in the European Economic Area or United Kingdom, we rely on these legal bases under applicable data-protection law:
In more detail:
A safety report may incidentally contain sensitive information, including health, sexual-life, sexual-orientation, racial or ethnic, religious, political, or alleged criminal-offence information about the reporter, the reported person, or another individual.
Where UK law applies, we process special-category information only where an additional UK GDPR Article 9 condition applies, such as substantial public interest for preventing or detecting unlawful acts or safeguarding children and individuals at risk, legal claims, or vital interests. We process criminal-offence information only where authorized under UK GDPR Article 10 and the Data Protection Act 2018, including applicable Schedule 1 conditions. We use this information only where necessary and apply restricted access, defined retention, review procedures, and disclosure controls.
All network communication uses HTTPS/TLS. Local data is protected by iOS security features and the app’s encrypted database design.
We use trusted service providers to operate InnerRing. They process data only as needed to provide the app and related infrastructure.
These providers may process data in countries outside your country of residence. Where required, transfers are supported by an applicable adequacy decision, the EU Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, or another legally permitted safeguard. Contact us if you want information about the safeguard applicable to a particular provider. Provider backup and retention behavior is governed by their service terms and data-processing terms.
We share data only as needed to provide the service:
We do not routinely share plaintext message content because message contents are end-to-end encrypted and unavailable to us on the backend. If you submit a message report, the reported message content and report information you voluntarily provide may be reviewed and disclosed where legally required.
Depending on where you live, you may have rights to access, receive a portable copy of, correct, delete, restrict, or object to processing of your personal data. Where processing is based on consent, you may withdraw that consent at any time without affecting processing that was lawful before withdrawal.
Use the in-app controls while signed in for account access, export, correction, and deletion. You may contact us about another privacy right or make a formal privacy request by email. Because InnerRing does not use email addresses or phone numbers for account identity, we may need you to verify control of the account from within the signed-in app before we disclose, change, or delete account data. Email alone is not proof of account ownership. We will not ask for your recovery key.
When verification is required, we may email you a single-use code that remains valid for 24 hours. Entering the code while signed in links that email request to your InnerRing account. This verifies control of the pseudonymous account, not your legal identity. Incorrect attempts are rate limited, and a replacement code invalidates the previous code.
InnerRing is designed to support in-app data export while signed in. Server-side exports may include account data, device/session metadata, subscription identifiers and entitlement status, contact and conversation metadata, invite metadata, message metadata, reaction metadata, E2EE public-key metadata, and deletion request status.
Server-side exports do not include plaintext ordinary-message contents because we cannot decrypt them. Standard self-service exports include successful formal-request verification receipts but exclude their code hashes. They also exclude raw ciphertext, encryption headers, X3DH headers, encryption session IDs, App Attest keys, receipts, challenges, counters, replay-token records, and restricted safety-report context. Plaintext ordinary-message history may exist only on your device and in your encrypted iCloud backup if enabled. If you voluntarily submit a message report, its plaintext snapshot is restricted safety-report context and is not included in the ordinary self-service export.
The self-service export is not a decision that all excluded information falls outside a legal right of access. If you make a formal access request, we will assess the applicable law, the rights of other people, security risks, and any legal exemptions before deciding what additional information can be provided.
You can update your display name and select a different app-owned avatar background color in the app.
You can allow or disable push notifications in iOS Settings.
You can request account deletion in the app while signed in. Deletion requests are processed within 7 days. You may cancel your deletion request in the app before it is processed.
For security, deletion requests are not accepted by unauthenticated email. If you lose your recovery key and are signed out, we may be unable to verify ownership, recover, export, or delete the account.
You may object to processing based on our legitimate interests and may ask us to restrict processing in circumstances provided by law. Contact us using the email address in section 14. We will consider your request against our reasons for processing, legal obligations, safety needs, and the rights of other people.
Please contact us first if you have a privacy concern so we can try to resolve it. If you are in the United Kingdom, you also have the right to complain to the Information Commissioner’s Office. If you are in the EEA, you may complain to the data-protection authority where you live, work, or believe an infringement occurred.
Account, authentication, device-integrity, public-key, and core messaging metadata are contractually required to create an account and provide secure messaging. If you do not provide them, we cannot create or authenticate the account or provide the affected feature. Push notifications, optional iCloud backup, safety-report additional information, and support emails are optional, except that a short explanation is required when you select the “Other” safety-report category.
InnerRing uses automated security, rate-limit, app-integrity, subscription-entitlement, and app-version checks. These checks can reject or temporarily limit account creation, session activation, verification-code attempts, invites, contacts, or messaging. They do not use advertising profiles or cross-app tracking. Safety-report outcomes and account safety restrictions are reviewed by a person rather than decided solely by an automated profile. Contact us if you believe an automated check was applied incorrectly.
We retain account, contact, encrypted message, message metadata, device, session, App Attest security, subscription entitlement, and E2EE public-key data while your account is active and the data is needed to provide the service.
Ordinary encrypted messages and related metadata are retained while the backend contact and conversation records remain. If a sender deletes a message for everyone, the current message ciphertext is cleared and the message is hidden from the chat view, but the backend message row and operational metadata remain. Message audit records containing earlier ciphertext are normally retained for 1 year and may be kept longer when linked to a safety report or legal hold.
Message events and reaction tombstones may be retained as needed for message sync, read/edit/delete state, Double Ratchet encryption correctness, abuse prevention, service reliability, and record keeping.
When your account deletion is processed, we delete or remove access to:
We anonymize your profile as “DELETED USER” and prevent future account access.
Because conversations involve two participants, encrypted historical messages and minimal conversation metadata may remain available to the other participant after your account deletion. We retain this limited data under our legitimate interests to preserve the other participant’s conversation history and the integrity of the messaging service.
We limit the privacy impact of this retention by deleting your authentication account, sessions, push tokens, app-linked device records, invite codes, E2EE prekeys, and public identity keys. Your profile is shown as “DELETED USER” with the default app-owned avatar color, your account cannot be accessed again, and message contents remain end-to-end encrypted on the backend.
App Attest security records are associated with an app installation and hashed device ID rather than directly with an InnerRing account. They may remain after account deletion where needed to verify device integrity, prevent replay, enforce rate limits, and investigate abuse.
The retained conversation data may include user IDs, contact relationship IDs, timestamps, encrypted message records, message events, and read/edit/delete/reaction metadata. This retained data is pseudonymous personal data, not fully anonymous data.
Safety reports, authority-escalated records, display-name audit records, message audit records, and related retention-held records may be retained after account deletion where needed for safety review, legal compliance, abuse prevention, service reliability, mandatory reporting, or record keeping.
We retain Apple-verified subscription entitlement records after account deletion as needed to verify purchases and refunds, handle billing disputes, prevent fraud, and maintain accounting and audit records. These records may include product ID, App Store transaction identifiers, subscription environment, entitlement status, expiry or revocation dates, and verification timestamps. The subscription record does not contain an InnerRing user ID, but Apple may retain its own transaction-to-account relationship under Apple’s policies.
We retain limited completed or cancelled deletion-request records, such as user ID, request time, status, and completion or cancellation time, for approximately 1 year for audit, security, and legal-defense purposes. Cleanup runs on a schedule, so deletion may occur shortly after the anniversary. Pending requests remain until completed or cancelled.
Unused formal-request verification records expire after 24 hours and are normally deleted 30 days after expiry. A replacement code overwrites and invalidates the previous code. Successful verification receipts, including the verification ID, account ID, and verification time, are retained for approximately 1 year to document request handling, manage complaints, and establish or defend legal claims. Cleanup runs on a schedule, so deletion may occur shortly after the retention period.
We retain display-name audit records for 1 year by default. If a safety report references a display-name audit record and the safety report has a longer retention period, we may retain the display-name audit record for the same period as that safety report.
Open safety reports are retained until reviewed and closed or placed under an applicable hold. Closed safety reports are retained for 1 year by default. Authority-escalated reports may be retained for longer where required by law, safeguarding obligations, competent-authority instructions, or internal safety retention policy. Message audit records and display-name audit records linked to safety reports may be retained for the same period as the related safety report.
Backend providers may retain deleted data temporarily in disaster-recovery backups according to their own retention practices. These backups are not used to restore deleted accounts as active accounts.
Optional iCloud backups are controlled by you through your Apple iCloud account. We cannot access or delete your iCloud backup for you.
We retain support, privacy, and safety-complaint correspondence only while needed to respond, document the outcome, meet legal or safeguarding obligations, resolve disputes, and establish or defend legal claims. Administrator notification emails and provider copies are also subject to the relevant email provider’s retention and backup practices.
During beta testing and TestFlight use, we may reset or delete test data to maintain the service. Do not use beta builds for critical or sensitive communications that you cannot afford to lose.
InnerRing is not intended for children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided personal data, contact us.
California residents may have rights under the California Consumer Privacy Act, including the right to know, delete, correct, and opt out of sale or sharing. We do not sell personal information.
We do not share personal information for cross-context behavioral advertising, and we do not use advertising, analytics, or cross-app tracking.
If you are in the EEA or UK, you may have GDPR or UK GDPR rights including access, rectification, erasure, restriction, portability, objection, and withdrawal of consent where processing is based on consent.
Use signed-in in-app controls where available. You may also contact us by email to make a formal request, but we may require verification through the signed-in app before taking an identity-sensitive action.
We may update this Privacy Policy from time to time. We will update the “Last Updated” date when changes are made. Material changes may also be communicated in the app.
If you have questions about this Privacy Policy, contact us at:
Email: innerring.app@gmail.com
For account deletion and the ordinary self-service export, use the in-app controls while signed in. You may use email for privacy questions, complaints, or formal rights requests, but email alone is not sufficient to verify account ownership.