Legal
Privacy Policy
Aegis helps people confirm trusted devices during conversations while collecting only the information needed to operate and protect the service.
Effective August 7, 2026
Information Aegis handles
Account information
Your Sign in with Apple identifier and, if Apple provides them, your email address and name are processed through Firebase Authentication. Aegis also stores the display name you choose.
Device information
A device identifier and label, cryptographic public keys, platform, push-notification token, and registration timestamps are stored in Firebase. Private cryptographic keys remain on your device.
Trust and verification information
Aegis stores trusted-device relationships and verification request metadata, including participating account and device identifiers, encrypted challenge data, signatures, status, and timestamps. Plaintext verification words and numbers are not stored in Firebase or sent in push notifications.
On-device information
Your trust list, verification history, pending requests, and free-use count are stored on your device. Verification history does not contain the verification words.
Purchase information
Apple processes the Unlimited Access purchase. Aegis checks the verified StoreKit entitlement but does not send your purchase history or Apple Account details to Firebase.
How information is used
Information is used to authenticate you, register and protect device identities, deliver and complete requested verifications, prevent misuse, provide purchase access, troubleshoot failures, and maintain service security.
Aegis does not sell personal information and does not use it for third-party advertising or cross-app tracking.
Service providers
Apple provides Sign in with Apple, push notifications, and StoreKit purchases. Google Firebase provides authentication, database, cloud functions, push-delivery infrastructure, and App Check.
These providers process information under their own privacy policies and the service terms governing Aegis's use of their platforms. Aegis does not authorize them to use Aegis account data for third-party advertising.
Retention and deletion
Account and backend data are kept while your Aegis account is active. You can use Settings → Delete My Account to delete your Firebase authentication account, registered device data, trusted-contact references, verification requests, and local identity data.
Service-provider security logs and backups may remain for limited periods under their standard retention practices. The installation-scoped free-use count is not linked to the deleted Firebase account. Apple controls retention of App Store transaction records and your Apple-managed purchase entitlement.
Security
Aegis uses device-bound cryptographic keys, encrypted challenge data, Firebase security controls, App Check, and local device protection. No system can guarantee absolute security. Aegis confirms possession of a previously trusted device—not a person's legal or biological identity.
Children
Aegis is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
Changes and contact
We may update this policy as Aegis changes. The effective date will be updated when material changes are made.
For privacy questions, deletion assistance, or other requests, visit Aegis Support.