Velixnet
Start Why VXN Trust Tech Account Contact

Plain information about how the VXN closed test handles the data it needs to operate.

This notice applies to the VXN mobile app distributed for closed testing, the Velixnet website, and the limited account and message-delivery data used to operate the service.

Short version

Private keys stay on user devices. Message content is encrypted before upload. The service uses only the account, delivery, timing, permission, and connection data needed to operate the closed test.

Operator and contact · Delete an account

Who runs Velixnet?

Velixnet is an independent project run by the developer who publishes as Krughan Henderson. The operator runs the service, handles invitation requests and is responsible for responding to questions about account data, privacy and deletion.

Contact the operator at privacy@velixnet.com for data requests, or vxn@velixnet.com for general questions.

Scope

Velixnet is the service brand. VXN is the mobile application distributed for testing. In this policy, “the App” means the VXN mobile app and, where relevant, its connection to the Velixnet service.

This policy covers the public Velixnet website, the VXN app, the contact form on this site, and Velixnet-operated testing services.

Information we collect

When you use the contact form, Velixnet may store the name, email address, optional note, submission time, and a hashed value derived from the connecting IP address for rate limiting and abuse review.

For a closed-test invitation, Velixnet uses the email address supplied for that purpose only. When you create or use a test account, the service processes your Velix ID, password-authentication data, login session state, public keys, encrypted message-envelope routing data, acknowledgement state, timestamps, and other delivery records needed to route encrypted messages.

Device data and permissions

The App may request internet access so it can connect to the Velixnet service, camera access for QR-code scanning, and notification permission for message alerts. These permissions are used only for their stated functions, not for advertising, profiling, or unrelated tracking.

The App is intended to request only permissions that are necessary for its stated functionality.

What remains visible to the server

Velixnet is built around encrypted message content, but the server can still process or store information such as sender and recipient identifiers, queue state, timing, payload size, account records, public keys, session information, and connection details needed to operate the service.

Connection choices

Read the separate network guide to compare direct connections, VPNs and Tor, including what they can and cannot hide.

How we use information

Velixnet uses information to run the website, send requested closed-test invitations, respond to contact requests, prevent abuse, operate test accounts, authenticate users, route encrypted message envelopes, maintain service stability, and investigate technical problems during development and testing.

Velixnet does not sell user data to advertisers or data brokers.

Sharing

During testing, Velixnet uses servers located in the United States. Before wider public release, the plan is to move the production service to locally owned hosting providers that own and operate their data centres in Sweden and/or Switzerland. This move has not yet taken place.

Firebase Cloud Messaging is used solely for generic push notifications; it receives push-routing data such as a device registration token and message ID, not VXN message plaintext, encrypted message content, or private keys.

Velixnet may otherwise disclose information only when reasonably necessary to host, secure, maintain, or investigate abuse affecting the service, or when required by law.

The service is not intended as a platform for broad public sharing of user content.

Retention

Testing invitation requests include your name, email address and any optional note. These details are retained until closed testing is completed so the developer can arrange invitations and respond to testing-related questions. The developer will then delete them. Invitations may be sent several weeks after a request; there is no fixed invitation or public release date. You can withdraw your request and ask for deletion earlier by emailing privacy@velixnet.com.

Undelivered encrypted message envelopes are retained for up to 30 days. Abuse and aggregate delivery metadata are retained for up to 7 days.

Your Velix ID and sign-in details are saved for use during testing and public release. Ordinary account records do not expire automatically when testing ends. They remain while the account is active and are removed through the account-deletion process. VXN is not long-term message storage; delivery and account data can be removed according to these rules.

Account and data deletion

Do not have app access? If you reserved a Velix ID on the website, email privacy@velixnet.com with your Velix ID and ask to delete the account. The operator will arrange a check that the account belongs to you before removing it. Do not send your password, private keys or recovery material.

You can permanently delete a VXN account in the app: open Settings, choose Delete account, and confirm the deletion. This permanently removes the account from the active VXN service; no website request is required.

Deletion removes the active account record, authentication record, public identity and one-time public prekeys, device delivery token and client-capability record, failed-login record, and undelivered encrypted message envelopes sent by or addressed to that account. As part of deletion, the app removes its local identity and private keys, contacts, local message history, ratchet state, recovery material, and account settings from that device. If device storage prevents completion, the app informs the user.

The active-service deletion routine does not apply an additional retention period to those records and does not create a deletion-specific operator backup. VXN does not currently maintain a per-account recovery deletion ledger or promise automatic reconciliation after a later server restoration.

The configured disaster-recovery rotation keeps the latest three successful backups. A daily check creates a new backup when the previous one is at least 47 hours old, normally producing one every two days. Older backups are removed after a successful replacement, so a backup normally remains for about six days. This is a rotation based on successful backups, not a guaranteed six-day deletion deadline: failed or paused jobs can leave older copies in place longer. Backups may contain historical account, contact-request and encrypted delivery data after it has been removed from the active service. VXN message plaintext and client private keys are not stored on the transport server. If the app reports that local data could not be removed, delete the app's storage or contact privacy@velixnet.com for assistance.

Security

Velixnet aims to use HTTPS, client-side encryption for message content, rate limiting, and restricted server-side storage.

No website, app, or test service can honestly promise perfect security, perfect secrecy, or zero risk, especially during an early testing stage.

Libraries and SDKs

The App uses open-source libraries and standard Android/Qt build components required for its stated functionality. Firebase Cloud Messaging is used only to provide generic message notifications. Third-party and open-source components are included solely to support the App’s stated functionality.

The App does not use advertising, analytics, or tracking SDKs.

Store disclosures

The App is intended to operate only as described in its store listing, in-app screens and privacy disclosures. Store declarations are updated when the App’s data handling or permissions change.

Software behaviour

The App is not designed to install other applications, introduce undisclosed functionality through downloaded executable code, or use permissions for purposes unrelated to its documented features.

Your choices

You can choose not to submit the contact form and not to create or use a test account. You can also deny optional permissions such as camera access, though some QR-code features may not work without that permission.

You can delete your VXN account directly in the app through Settings > Delete account. You can ask about, correct, or request deletion of information associated with a closed-test invitation by writing to privacy@velixnet.com and including enough detail to identify the request.

Contact and updates

This notice may be updated as Velixnet and VXN change. Last reviewed: 12 September 2026. Account continuity, deletion without app access, operator contact details and backup rotation are described above. Privacy questions, correction requests, and deletion requests can be sent to privacy@velixnet.com.

Velixnet © 2026
Privacy Terms Beta Recovery