Privacy Policy
Privacy Policy
Effective Date: June 12, 2026 Website: https://anonime.io
1. Introduction
This Privacy Policy outlines how Leatra Technologies LTD (“we,” “our,” or “us”) collects, utilizes, secures, and discloses your information through our application and service, Anonime. Anonime is architected with a privacy-first methodology, specifically designed to minimize our infrastructure’s access to your sensitive content. By utilizing the Anonime app, including our proprietary “Nym” digital identity structures, secure Vaults, Drops, and Whispers, you consent to the data practices described in this document.
2. Information Collection
We collect information through three primary channels: information you provide directly, data generated through your use of the service, and information obtained from integrated third-party infrastructure.
2.1 Information You Provide In the course of creating an account and utilizing our platform, you may provide:
- Account Credentials: Email addresses and authentication details required for sign-in and onboarding.
- Identity Profiles (Nyms): Display names, categories, aliases, colors, avatars, and related profile configurations used to manage your distinct digital identities.
- Encrypted Content: Vault items (such as passwords and notes), email content, attachments, and recipient data.
- Secure Sharing Data: Content, link-related metadata, and user-defined labels associated with Drops and Whispers.
- Administrative Data: Support tickets, inquiries, feedback, payment selections, and terms acceptance records.
2.2 Information Generated by the Service To operate our infrastructure and deliver communications, we automatically generate and store:
- Operational Metadata: Delivery, routing, retention, and deletion metadata necessary for message transmission.
- Account & Session History: Account status, login activity, session history, and subscription entitlements.
- System Logs: Rate-limit records, audit trails, and operational logs required for security monitoring and abuse prevention.
- Storage References: Object-storage references utilized for managing both encrypted and plaintext files.
2.3 Information from Third-Party Subprocessors Depending on your usage and configuration, we may receive functional data from vetted infrastructure partners, including:
- Mailgun: For the processing of inbound email delivery and outbound sending.
- Paystack: For the secure processing of billing and payment status.
- Push Notification Providers (e.g.,Firebase FCM): For delivering device-level notifications.
- GeoIP Providers: For assigning coarse location labels to active sessions for security monitoring.
3. Local Storage and Session Management
We do not use tracking cookies or third-party behavioral analytics trackers. To securely authenticate you and maintain your active sessions, we utilize strictly necessary local storage mechanisms on your device, authentication session tokens, and JSON Web Tokens (JWTs). These are solely used for authentication, security, and the core operation of the Anonime service.
4. Legal Basis for Processing
For users in jurisdictions that require an explicit legal basis for data processing (such as the EEA, UK, and Nigeria), we rely on the following grounds:
- Contract Performance: To provide the Anonime service, maintain your account, deliver messages, and process subscriptions.
- Legitimate Interests: To maintain system security, debug infrastructure, prevent abuse, and keep our routing infrastructure operational.
- Consent: When you explicitly opt into optional features or marketing communications (which can be revoked at any time).
- Legal Obligations: To comply with applicable tax, accounting, and lawful data retention requirements.
5. Utilization of Information
We strictly limit the use of collected data to the operations necessary to provide and maintain the Anonime platform. We use this information to:
- Provision and maintain your account, Nym identities, Vault storage, Drops, and Whispers.
- Authenticate access and actively manage secure sessions.
- Facilitate the encryption, storage, transmission, and retrieval of data.
- Render inboxes, communication threads, notifications, and subscription statuses.
- Process subscription renewals and validate payment transactions.
- Enforce system quotas, rate limits, content expiry, and abuse-prevention protocols.
- Administer our infrastructure, debug technical anomalies, and improve system reliability.
- Fulfill legal obligations, enforce our Terms of Service, and protect the integrity of the platform.
6. Cryptographic Security Framework
Anonime employs a hybrid architectural model separating end-to-end encrypted secret content from the operational metadata required to route it.
6.1 Client-Side Encrypted Content To ensure a zero-knowledge architecture where applicable, the following data is encrypted on your local device before transmission to our servers:
- Vault items and stored secure notes.
- Private key material utilized to decrypt sealed inbound communications.
- Content within secure Drops and Whisper threads.
- Owner-only labels associated with Drops and wrapped Whisper keys.
Note: Because inbound emails arrive from external networks, they are encrypted as soon as reasonably practicable after receipt by our infrastructure, ensuring that only the authenticated owner can read the contents after unlocking their Vault.
6.2 Unencrypted Operational Data The following data classifications are intentionally readable by us or our respective subprocessors to maintain service functionality:
- Support tickets and administrative communications.
- Outbound email directed to external recipients.
- Operational metadata strictly necessary for routing, billing, identity verification, and account management.
- Push notification tokens and associated notification metadata.
7. Data Sharing and Disclosure
We do not sell or rent your personal information. We disclose information only under the following specific circumstances:
- Service Providers: We share operational data with trusted third-party vendors (identity providers, email routing services, payment processors, and hosting facilities) bound by strict confidentiality agreements to facilitate our core services.
- User-Directed Sharing: When you intentionally publish or share a link, alias, or message with a third party.
- Business Transfers: In the event of a merger, acquisition, restructuring, or asset sale, user data may be transferred as a business asset.
8. Lawful Requests and Law Enforcement
We may receive requests for user data from government agencies, law enforcement, courts, or regulators. We generally require valid legal process (such as a subpoena, court order, or search warrant) where required by applicable law compelling us to disclose data.
What we can and cannot provide: Because Anonime utilizes client-side end-to-end encryption for core features, we do not possess the decryption keys for your Vaults, Drops, or Whispers. Therefore, if legally compelled to produce data, we can only provide what we have access to:
- We can provide: Basic account information, operational metadata, billing records, routing logs, and encrypted data blobs.
- We cannot provide: The plaintext, decrypted contents of your Vaults, Drops, Whispers, or securely sealed emails, as we do not possess the architectural capability to decrypt them.
Where legally permitted, we will attempt to notify you of requests for your data before disclosure. We reserve the right to disclose operational data without notice if we believe, in good faith, that an emergency involving imminent death or serious bodily harm requires disclosure without delay.
9. Data Retention Protocols
We apply strict retention limits to minimize our data footprint. Current maximum retention schedules are as follows:
- Inbound Email: Maximum of 30 days.
- Drops: Retained until user-defined expiry, explicit burn action, or revocation (subject to a strict maximum retention of 72 hours).
- Whispers: Retained until thread expiry, explicit burn action, or deletion (subject to a strict maximum retention of 72 hours).
- Support & Administrative Records: Retained until the ticket is closed, the account is deleted, or an administrator clears the conversation.
- Account Deletion: Upon initiating an account deletion request, the account is immediately disabled, rendered inaccessible, and marked for permanent deletion. Data is removed from active systems within 72 hours. Account restoration is impossible once the deletion action is triggered. Residual copies may persist in encrypted system backups for a limited period before automatic expiration.
- Financial Records: Retained only as long as required for billing, accounting, dispute resolution, and legal compliance.
10. Global Privacy Rights
Anonime is committed to full compliance with global data protection frameworks. Depending on your jurisdiction, you are entitled to the following rights regarding your data:
10.1 Nigerian Data Protection Rights (NDPA/NDPR) As a Nigerian-registered corporate entity, we comply with the NDPA and NDPR. You have the right to request access to, correction of, or deletion of your personal data; object to specific processing activities; and request data portability. Complaints may be lodged with the Nigeria Data Protection Commission (NDPC).
10.2 European and UK Privacy Rights (GDPR) For users in the EEA, UK, or Switzerland, you hold the rights to access, rectification, erasure (Right to be Forgotten), restriction of processing, and data portability.
10.3 California Privacy Rights (CCPA/CPRA) California residents hold the right to know the specifics of data collection, request deletion, correct inaccuracies, and receive non-discriminatory treatment. We do not sell personal information or share it for cross-context behavioral advertising.
To exercise any privacy rights across these jurisdictions, submit a formal request to privacy@anonime.io. Note: Due to our client-side encryption architecture, we cannot recover, access, or export the decrypted contents of your Vaults, Drops, or Whispers.
11. International Data Transfers
Your operational metadata may be processed in global data centers managed by our infrastructure partners. Any cross-border data transfers are executed in accordance with applicable data protection laws, utilizing mechanisms such as Standard Contractual Clauses (SCCs) to ensure adequate protection.
12. Security, Breach Notification, and Assumption of Risk
We implement rigorous administrative, technical, and organizational safeguards, including client-side encryption, server-side access controls, and separation of secret content from operational metadata, to protect your information.
In the event of a data breach affecting personal information, we will provide notifications to affected users and relevant regulatory authorities as required by applicable law.
However, no security system is impenetrable. While we strive to protect your personal data, we cannot guarantee its absolute security against sophisticated cyberattacks or user-side vulnerabilities (such as compromised devices or lost Vault Keys). By using the Anonime app, you acknowledge these inherent risks. You are solely responsible for maintaining the confidentiality of your credentials and Vault Key; if you lose your Vault Key, Leatra Technologies LTD cannot recover your encrypted data.
13. Do Not Track Signals
Certain web browsers provide a “Do Not Track” (DNT) feature that signals to websites that you do not want your online activity tracked. Anonime does not currently respond to browser Do Not Track signals.
14. Age Requirement
Anonime is strictly intended for adult users. You must be at least 18 years old to use our services. We do not knowingly collect personal information from anyone under the age of 18. If we become aware that an individual under 18 has created an account, we will immediately terminate the account and permanently purge the associated data.
15. Modifications to this Policy
We reserve the right to update this Privacy Policy. Material changes will be communicated via platform notifications or administrative email prior to the effective date. Continued use of the platform after updates constitutes acceptance of the revised terms.
16. Governing Law
This Privacy Policy, and any disputes arising out of or related to it, shall be governed by and construed in accordance with the laws of the Federal Republic of Nigeria, without regard to its conflict of law principles.
17. Contact Information
For inquiries regarding this Privacy Policy or our data practices, please reach out to:
- Email: privacy@anonime.io
- Data Controller: Leatra Technologies LTD, a company incorporated in Nigeria (RC Number:
7062719) - Registered Address:
Lagos, Nigeria