Virexa Private
Privacy Policy
Virexa Technologies · Effective 9/19/2026 · Last updated 9/19/2026 · 18+ only
Virexa Technologies
Compliant with GDPR, CCPA, PIPEDA, and US Federal Privacy Laws
Effective Date: 9/19/2026
Last Updated: 9/19/2026
1. INTRODUCTION AND SCOPE
This Privacy Policy ("Policy") governs how Virexa Technologies ("Company," "we," "us," "our," or "Virexa Private") collects, uses, processes, stores, and protects your personal information when you use our Virexa Private application ("App") and related services ("Services"). This Policy is designed to comply with the data protection laws of:
- United States, including the California Consumer Privacy Act (CCPA/CPRA), and federal regulations
- Canada, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and Canada's Anti-Spam Legislation (CASL)
- European Union, including the General Data Protection Regulation (GDPR) and ePrivacy Directive
Virexa Private is built on a privacy-first architecture. As a fundamental principle, we have designed our system to minimize data collection at every level. Critically, we do not collect, store, process, or have access to phone numbers. Instead, we use usernames as the sole identifier for account creation, user connection, and all communication purposes. All user communications—including text messages, voice notes, audio calls, video calls, and shared media—are protected by end-to-end encryption that prevents even Virexa Private from accessing the content.
2. DATA CONTROLLER, PROCESSOR, AND CONTACT INFORMATION
The entity responsible for your personal information is:
Data Controller: Virexa Technologies Virexa Private Division Privacy Compliance Team Email: Privacy@Resent.app Support Email: Support@Resent.app Legal Email: Legal@Resent.app For EU/EEA residents: EU Data Protection Representative (to be appointed per GDPR Article 27) Email: Privacy@Resent.app Address: [EU Establishment Address] For Canadian residents: Canadian Privacy Officer (to be appointed per PIPEDA requirements) Email: Privacy@Resent.app Address: [Canadian Office Address] Data Protection Authority contacts for complaints: • EU: Your national Data Protection Authority (https://edpb.ec.europa.eu/about-edpb/board/members_en) • Canada: Privacy Commissioner of Canada (www.priv.gc.ca) • USA: FTC and state attorneys general offices
3. WHAT PERSONAL DATA WE COLLECT AND PROCESS
3.1 Information You Voluntarily Provide
- Username: Required for account creation, identification, and user connection within the platform
- Password: Securely encrypted and stored using industry-standard hashing algorithms (bcrypt or Argon2)
- Email Address (Optional): Provided voluntarily for account recovery and receipt of important service notifications only
- Profile Information (Optional): Any biographical details, profile picture, or status message you choose to add to your profile
- Timezone and Language Preferences: Selected to provide localized services and user interface
- Recovery Phone (Optional): If provided, used solely for account recovery in the event of forgotten password
3.2 Information Generated Through Your Use of the Service
- Message Metadata: Timestamps indicating when messages were sent and delivered (NOT the content of messages, which is end-to-end encrypted)
- Connection Information: Login timestamps, session duration, and connection timestamps for security auditing
- Device Information: Device type (iOS/Android), operating system version, app version, and device model for compatibility and bug fixing
- IP Address Information: Your IP address is logged temporarily for security purposes, fraud detection, and DDoS prevention. This information is anonymized within 7 days and non-anonymized copies are deleted within 30 days
- Usage Analytics: Aggregate, non-personally-identifying statistics about which features you use (e.g., "calls feature used 100,000 times in region"), not tied to individual messages or calls
- Call Metadata: Duration of calls and timestamps of call attempts (NOT the content of calls, which is end-to-end encrypted)
- Error Logs: Technical error information for troubleshooting platform issues
3.3 Information We Explicitly Do NOT Collect, Access, or Store
- Phone Numbers: We do not request, collect, store, or process phone numbers under any circumstances
- Message Content: All text messages, voice notes, photographs, video files, documents, and other shared media are end-to-end encrypted and cannot be read, accessed, or stored by Virexa Private in decrypted form
- Voice and Video Call Content: All audio and video communications are end-to-end encrypted and Virexa Private cannot access the content
- Device Contacts: We do not access, read, download, or store your device contacts or address book
- Location Data: We do not collect GPS coordinates, precise location information, or location-based services data
- Biometric Data: Fingerprint data, facial recognition data, iris scans, or other biometric identifiers remain on your device only and are not accessed or transmitted to Virexa Private
- Calendar or Schedule Data: We do not access your calendar, schedule, or event information
- Health Data: We do not collect health, fitness, or medical information
- Payment Information: We do not store full credit card numbers or sensitive payment details (if applicable, handled by PCI-compliant third parties)
4. LEGAL BASIS FOR DATA PROCESSING
4.1 GDPR Legal Basis (EU, EEA, United Kingdom)
Under the General Data Protection Regulation (GDPR), we process personal data on the following legal bases:
- Contract Performance (GDPR Article 6(1)(b)): Processing is necessary to perform the services you have engaged us to provide, including account creation, message transmission, and call facilitation
- Legal Obligation (GDPR Article 6(1)(c)): Processing necessary to comply with applicable laws, court orders, law enforcement requests, and regulatory requirements
- Legitimate Interests (GDPR Article 6(1)(f)): We process data to protect platform security, prevent fraud, abuse, and unauthorized access; to improve service functionality and user experience; to conduct customer support; and to maintain platform infrastructure
- Consent (GDPR Article 6(1)(a)): For optional features not essential to service provision, we obtain explicit, informed, freely-given consent, which you may withdraw at any time
For processing of special categories of data under GDPR Article 9, we do not process special categories of personal data except where necessary for security purposes or with your explicit consent.
4.2 CCPA/CPRA Legal Basis (California)
Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), we collect personal information for the following purposes:
- Service Provision: To provide, maintain, improve, and support the Virexa Private Service
- Security and Fraud Prevention: To detect and prevent fraudulent activity, abuse, and unauthorized access
- Customer Service: To respond to customer inquiries and provide technical support
- Analytics and Improvement: To understand usage patterns and improve our Services
- Legal Compliance: To comply with applicable laws, regulations, and legal processes
Important: We do NOT "sell" personal information in exchange for monetary compensation. We do NOT engage in behavioral profiling or targeted advertising. California residents have the right to know, delete, and opt-out of any data sharing practices, as detailed in Section 9 below.
4.3 PIPEDA Legal Basis (Canada)
Under the Personal Information Protection and Electronic Documents Act (PIPEDA), we collect and use personal information for the following purposes:
- Providing the Service: Account creation, authentication, and service delivery
- Customer Communication: Providing support, updates, and important service announcements
- Improving Services: Analyzing usage to enhance features and performance
- Legal Compliance: Meeting legal and regulatory requirements
- Security: Protecting against fraud, unauthorized access, and security threats
Canadian residents retain all rights under PIPEDA to access, request correction of, and request deletion of personal information, as detailed in Section 9 below.
5. HOW WE USE YOUR PERSONAL INFORMATION
- Service Delivery and Functionality: To enable text messaging, voice calls, video calls, file sharing, and all core features of Virexa Private
- Account Management: Account registration, user authentication, password management, account recovery, and profile administration
- Security and Fraud Prevention: Detecting, investigating, and preventing unauthorized access, fraud, abuse of the platform, and malware
- Customer Support: Responding to support inquiries, technical issues, and user questions
- Legal Compliance and Governance: Complying with applicable laws, court orders, law enforcement requests, and regulatory investigations
- Service Improvement and Analytics: Analyzing aggregate usage patterns to improve features, fix bugs, optimize performance, and enhance user experience
- Notifications and Communications: Sending security alerts, service status updates, important account notifications, and terms/policy changes
- Platform Integrity: Detecting and addressing Terms of Service violations, abuse, and harmful conduct
We will NOT use your personal information for purposes incompatible with these stated uses without first obtaining your explicit, informed consent. We do not engage in marketing or advertising using personal information without your consent.
6. END-TO-END ENCRYPTION (E2EE) AND MESSAGE PROTECTION
End-to-end encryption is a core security feature of Virexa Private. All communications are encrypted at the sender's device and can only be decrypted by the intended recipient. Here's how it protects your privacy:
- Encryption Mechanism: When you send a message, voice note, call, video, or any other content, it is encrypted on your device using a private encryption key before it is transmitted over the network
- Transmission: Virexa Private servers transmit the encrypted data without access to decryption keys or the ability to read the content
- Recipient Decryption: Only the intended recipient, who possesses the corresponding private decryption key, can decrypt and read the message
- Server-Side Access: Virexa Private cannot and does not store decrypted message content at any point. We cannot access, read, monitor, or retrieve message content even temporarily
- Legal Process Limitation: Even in response to a valid subpoena, court order, or warrant, we cannot produce messages, call history, the people book, account access, or similar records because we do not collect that information. We also cannot provide decrypted message content because we do not possess the decryption keys or decrypted content. The only information we can produce is the username and last-seen timestamps
- Scope of E2EE: End-to-end encryption protects text messages, voice notes, photos, videos, documents, voice calls, video calls, and all other content transmitted through Virexa Private
Technical Implementation: Virexa Private uses the Signal Protocol (or equivalent industry-standard encryption algorithm) with perfect forward secrecy. Technical security details are available in our Technical Security Documentation, provided to qualified security researchers under a standard Non-Disclosure Agreement.
7. DATA SHARING, DISCLOSURE, AND THIRD PARTIES
7.1 When and How We Share Personal Information
We share your personal information only in the following limited circumstances:
- Service Providers and Data Processors: We engage third-party service providers to operate our platform, including cloud infrastructure providers (AWS, Google Cloud, Microsoft Azure), payment processors, analytics vendors, customer support platforms, and email delivery services. These providers are bound by Data Processing Agreements and contractually prohibited from using your data except as necessary to provide services
- Legal Requirements and Law Enforcement: If we receive a valid legal subpoena, court order, warrant, or other lawful process, we do not share sensitive information. The only information we can produce is the username and last-seen timestamps. We cannot reproduce messages, call history, the people book, account access, credentials, sessions, or similar records because we do not collect that information. When a request is made about an account, we notify that person inside Virexa Private by sending a message to their own account from the username resent_legal_notifications, displayed as Virexa Private Legals
- Business Transfers: In the event of merger, acquisition, asset sale, bankruptcy, or other business transition, personal information may be transferred as part of that transaction. We will provide notice and seek consent where required by law
- Aggregated and De-Identified Data: We may share aggregated, anonymized statistics and analytics with research partners, industry groups, and the public (e.g., "our platform had 1 million messages sent in January") that cannot identify individuals
- User Consent: We share information with third-party services only when you explicitly authorize it (e.g., integrating with a third-party backup service)
- Safety and Harm Prevention: We may disable accounts and act on reports when necessary to prevent imminent physical harm, death, or serious injury. Any production of account data to authorities remains limited to username and last-seen timestamps, as described above
7.2 Data Processors and Processing Agreements
All third-party service providers who process personal information on our behalf are subject to:
- Data Processing Agreements (DPAs): Legally binding contracts compliant with GDPR Article 28, CCPA requirements, and PIPEDA principles
- Processing Restrictions: Data may be processed only according to our documented instructions
- Sub-processor Approval: Sub-contractors must be approved in advance, and you will be notified of material changes
- International Transfer Mechanisms: Standard Contractual Clauses (SCCs) govern transfers outside the country where data is collected
- Confidentiality: All processors are bound by strict confidentiality obligations
- Security Standards: Processors must implement security measures meeting or exceeding our own requirements
A current list of our primary data processors is available upon request at Privacy@Resent.app.
7.3 International Data Transfers
Personal information may be transferred to, stored in, and processed in countries other than the country in which you reside, including countries outside the EU/EEA and Canada. Where such transfers occur:
- Standard Contractual Clauses: International transfers rely on Standard Contractual Clauses (SCCs) as approved transfer mechanisms under GDPR Article 46
- Transfer Impact Assessment: We have conducted Transfer Impact Assessments (Schrems II TIAs) to ensure adequate protections
- Supplementary Safeguards: Where necessary, we implement supplementary technical and organizational safeguards to protect data in transit and at rest
- Legal Cooperation: EU/EEA residents benefit from ongoing monitoring of third-country laws that may affect data protection
EU/EEA residents may request a copy of our Transfer Impact Assessment by contacting Privacy@Resent.app.
8. DATA RETENTION AND DELETION
We retain personal information only as long as necessary to provide Services and fulfill legal obligations. Our specific retention periods are:
- Account Information: Retained for the duration of your account and 30 days after account deletion to permit recovery if requested
- Message and Call Metadata: Server logs containing timestamps and connection information are retained for 90 days for security auditing, then permanently deleted
- Device Information: Device logs retained for 12 months for security analysis, then deleted
- IP Address Logs: Non-anonymized IP addresses retained for 7 days; after 7 days, converted to anonymized form; anonymized versions retained for 30 days then deleted
- Error and Access Logs: Technical logs retained for 90 days for troubleshooting, then deleted
- Legal Hold: Information subject to legal holds or litigation requirements retained until legal process concludes
- Compliance Obligations: Information required to be retained by law (tax records, regulatory compliance) retained per legal requirements
Upon expiration of retention periods, data is securely deleted or irreversibly anonymized. You may request earlier deletion of your data subject to legal obligations and platform functionality requirements.
9. YOUR PRIVACY RIGHTS AND HOW TO EXERCISE THEM
9.1 GDPR Rights for EU/EEA/United Kingdom Residents
You have the following rights under the GDPR:
- Right of Access (Article 15): You have the right to obtain a copy of all personal data we hold about you in a structured, commonly-used format
- Right to Rectification (Article 16): You have the right to correct inaccurate or incomplete personal data
- Right to Erasure/"Right to be Forgotten" (Article 17): You have the right to request deletion of your personal data, subject to legal obligations and service continuity requirements
- Right to Restrict Processing (Article 18): You have the right to request that we limit how we use your data
- Right to Data Portability (Article 20): You have the right to receive your personal data in a structured, machine-readable format and to transfer it to another service provider
- Right to Object (Article 21): You have the right to object to processing based on legitimate interests or for direct marketing purposes
- Rights Related to Automated Decision-Making (Article 22): You have the right not to be subject to decisions based solely on automated processing that produces legal or similarly significant effects
- Right to Lodge a Complaint (Article 77): You have the right to file a complaint with your national Data Protection Authority
9.2 CCPA/CPRA Rights for California Residents
Under the California Consumer Privacy Act and California Privacy Rights Act, you have the right to:
- Know: Request what personal information we collect, use, and share about you
- Delete: Request deletion of personal information we have collected from you, subject to legal exceptions
- Opt-Out: Opt-out of any "sale" or "sharing" of personal information for cross-context behavioral advertising (Virexa Private does not sell or share data; this right is available as a matter of law)
- Correct: Request correction of inaccurate personal information
- Limit Use: Limit use of sensitive personal information
- Non-Discrimination: Not be discriminated against or charged different prices for exercising CCPA/CPRA rights
- Authorized Agents: Designate an authorized agent to submit requests on your behalf
9.3 PIPEDA Rights for Canadian Residents
Under PIPEDA, you have the right to:
- Request Access: Obtain access to personal information we hold about you
- Request Correction: Request correction of inaccurate, incomplete, or outdated personal information
- Withdraw Consent: Withdraw consent for certain uses of your information (though this may affect service provision)
- Know Our Practices: Know our privacy practices and the reasons for collecting information
- File a Complaint: File a complaint with the Privacy Commissioner of Canada
10. HOW TO EXERCISE YOUR PRIVACY RIGHTS
To exercise any of your privacy rights:
Email: Privacy@Resent.app Subject Line: [Rights Request] - [Your Username] - [Type of Request] Include: Any information that helps us identify you (username, email, account details) Our Response Commitment: • Identity Verification: We will verify your identity and the authenticity of your request • Response Timeline: We will respond within 30 days (or as required by applicable law, typically 45 days for GDPR, 45 days for CCPA, and 30 days for PIPEDA) • Accessible Format: We will provide information in clear, accessible format • No Fees: We will not charge fees unless your request is manifestly unfounded or excessive, in which case we will notify you • Assistance: We will assist you with your request in your preferred language if possible • Denial Explanation: If we deny a request, we will explain our reasons For Authorized Agents: Authorized agents may submit requests on behalf of California residents with verified power of attorney or written authorization.
11. SECURITY MEASURES AND DATA PROTECTION
We implement comprehensive, multi-layered security measures to protect your personal information:
- End-to-End Encryption: All user communications are encrypted using the Signal Protocol with perfect forward secrecy
- Data in Transit: Data transmitted between your device and our servers is encrypted using TLS 1.2 or higher
- Data at Rest: Metadata and account information stored on our servers is encrypted using AES-256 encryption
- Authentication: Multi-factor authentication (MFA) options available to protect your account; all passwords hashed using bcrypt or Argon2
- Access Controls: Role-based access control, principle of least privilege, and automated access reviews
- Network Security: Firewalls, intrusion detection systems, intrusion prevention systems, and DDoS protection
- Monitoring and Logging: 24/7 security monitoring, event logging, and real-time threat detection
- Vulnerability Management: Regular vulnerability scanning, penetration testing, and bug bounty program
- Third-Party Audits: Annual independent security audits by reputable third-party security firms
- Employee Training: Regular security training for all employees with access to personal information
- Data Minimization: We collect and retain only data necessary for identified purposes
While we employ industry-standard security measures, no system is completely secure. Users share responsibility for maintaining password confidentiality and securing their devices.
12. DATA BREACH NOTIFICATION
In the event of a personal data breach that poses a risk to your rights, freedoms, or privacy, we will:
- GDPR Compliance: Notify the competent supervisory authority within 72 hours of becoming aware of the breach, and notify affected individuals "without undue delay"
- CCPA Compliance: Notify California residents without unreasonable delay in the most expedient time possible
- PIPEDA Compliance: Notify the Privacy Commissioner of Canada and affected individuals where required by law
- Breach Details: Notifications will include the nature of the breach, likely consequences, and measures taken to mitigate harm and prevent recurrence
- Contact Methods: We will notify you via email, app notification, and/or phone
Important: Given Virexa Private's end-to-end encryption, even in the event of a server breach, message content cannot be compromised because encrypted data without decryption keys is unreadable. However, metadata such as message timestamps may be affected.
13. CHILDREN'S PRIVACY AND AGE RESTRICTION
Virexa Private is for adults only. You must be 18 years of age or older to create an account. Children are not permitted to use the Service. We do not knowingly collect personal information from anyone under 18. If we become aware that a person under 18 has created an account, we will immediately delete the account and associated personal information. We may notify a parent or guardian when we have contact information that allows us to do so. Age verification: Date of birth is used to confirm you are 18 or older. Accounts that fail this check are not created. Lying about age is a violation of this Policy and the Terms of Service. Email: Privacy@Resent.app with subject "Underage Account"
14. COOKIES, TRACKING TECHNOLOGIES, AND DO NOT TRACK
Virexa Private's mobile application does not use traditional cookies. However:
- Session Tokens: We use secure, encrypted session tokens to maintain your login state and prevent unauthorized access
- Local Device Storage: Non-sensitive settings, preferences, and cache data may be stored locally on your device for user convenience (font size, theme preference, etc.)
- Analytics: We use privacy-respecting analytics that do not identify individual users or track cross-site behavior
- Web Portal: Our website (Virexa Private.app) uses minimal cookies and respects Do Not Track (DNT) signals from your browser
- Third-Party Integrations: We do not use third-party analytics trackers or advertising networks that track users across sites
- Opt-Out: Users may disable analytics in Settings → Privacy
We do NOT engage in cross-site tracking, behavioral profiling, or retargeting advertisements.
15. CALIFORNIA CONSUMER PRIVACY ACT (CCPA) AND CALIFORNIA PRIVACY RIGHTS ACT (CPRA) SUPPLEMENT
For California residents, this section provides additional information required under CCPA and CPRA:
- Sale of Personal Information: Virexa Private does NOT "sell" personal information in exchange for monetary or other valuable consideration. We do not share your data with third parties for behavioral advertising or cross-context behavioral advertising
- Sharing for Advertising: Virexa Private does NOT share personal information with third parties for cross-context behavioral advertising purposes
- Sensitive Personal Information: We do not collect or process sensitive categories of personal information (Social Security number, financial account details, biometric data, or health information)
- Do Not Sell/Share My Information: A toggle to opt-out of any potential sale or sharing is available in Settings (though we do not engage in such practices)
- Non-Discrimination: Exercising your CCPA/CPRA rights will not result in discrimination, denial of service, or reduced pricing
- Retention: We retain personal information only as long as necessary for identified purposes (see Section 8)
- Metrics and Reporting: We maintain and can disclose metrics regarding data requests and our responses
16. CANADA'S ANTI-SPAM LEGISLATION (CASL) AND ELECTRONIC MESSAGES
For Canadian users, we comply with Canada's Anti-Spam Legislation (CASL) regarding electronic messages:
- Consent: We obtain prior express consent before sending marketing or promotional emails
- Identification: All commercial electronic messages identify Virexa Private and provide contact information
- Unsubscribe: All marketing emails include clear, easy unsubscribe mechanisms
- Service Messages: Transactional messages (security alerts, service notifications) are not subject to CASL requirements but may be declined where permitted
To manage your communication preferences, visit Settings → Notifications or email Privacy@Resent.app.
17. EUROPEAN PRIVACY RIGHTS AND GDPR COMPLIANCE DETAILS
For EU/EEA residents, Virexa Private is committed to full GDPR compliance:
- Data Protection Impact Assessments (DPIA): We conduct DPIAs for high-risk processing activities
- Data Protection by Design: Privacy and security are built into all systems from inception
- Data Protection Officer (DPO): [Will be appointed if required; contact Privacy@Resent.app for DPO inquiries]
- Processing Records: We maintain detailed records of processing activities per GDPR Article 30
- Data Sharing Agreements: All data processors execute Data Processing Agreements per GDPR Article 28
- Consent Management: Consent is freely given, specific, informed, and unambiguous; withdrawal is easy
- Supervisory Authority Cooperation: We cooperate with EU data protection authorities and respond to inquiries
For questions specific to GDPR compliance, contact Privacy@Resent.app with subject "GDPR Inquiry".
18. POLICY CHANGES AND UPDATES
We may update this Privacy Policy from time to time. Changes will be reflected with an updated "Last Updated" date at the top of this document.
For Material Changes: • We will provide notice via email (if available) and/or through the app • For GDPR-relevant changes, EU residents will be provided at least 30 days to object • Continued use of Virexa Private after changes take effect constitutes your acceptance of the updated Privacy Policy If you do not agree with changes, you may delete your account.
19. CONTACT US
If you have questions about this Privacy Policy, your privacy rights, or our privacy practices:
General Privacy Questions: Email: Privacy@Resent.app Data Subject Rights Requests: Email: Privacy@Resent.app Subject: [Rights Request] - [Your Username] GDPR Inquiries (EU/EEA): Email: Privacy@Resent.app Subject: GDPR Inquiry EU Representative: [To be appointed per Article 27] PIPEDA Inquiries (Canada): Email: Privacy@Resent.app Subject: PIPEDA Inquiry Canadian Privacy Officer: [To be appointed per PIPEDA] CCPA/CPRA Inquiries (California): Email: Privacy@Resent.app Subject: CCPA Rights Request Technical/Security Issues: Email: Support@Resent.app Legal/Regulatory Matters: Email: Legal@Resent.app Company Address: Virexa Technologies Virexa Private Division [Corporate Address] [Country]
20. ADDITIONAL RIGHTS AND RESOURCES
For additional resources and to file complaints with regulatory authorities:
- EU/EEA: European Data Protection Board (EDPB) - https://edpb.ec.europa.eu/
- EU Member States: National Supervisory Authorities - https://edpb.ec.europa.eu/about-edpb/board/members_en
- United Kingdom: Information Commissioner's Office (ICO) - https://ico.org.uk/
- Canada: Office of the Privacy Commissioner of Canada - https://www.priv.gc.ca/
- United States (California): California Attorney General's Office - https://oag.ca.gov/privacy/
- United States (Federal): Federal Trade Commission (FTC) - https://www.ftc.gov/
END OF PRIVACY POLICY
Last Updated: 9/19/2026