HEXIS

Privacy Policy

Last updated: August 16, 2026

Hexis is built by a small team that believes private communication should be the default, not a paid upgrade or a marketing slogan. This policy explains, in plain language, what information we handle, what we do with it, and — just as importantly — what we don't.

The short version

  • We do not sell your personal information.
  • We do not scrape, mine, profile, or data-mine your content, and we do not use it to train machine-learning or AI models.
  • We run no advertising networks, no analytics SDKs, and no third-party trackers in any Hexis app.
  • Your messages can be end-to-end encrypted. Direct messages and voice are always end-to-end encrypted. Servers can be created in end-to-end encrypted mode, in which case we cannot read what is sent in them.
  • We collect the minimum we need to run the service, bill for it, and keep it safe from abuse.

The rest of this page is the detail behind those statements.

Who we are

Hexis is operated by jay0 dev LLC, a North Carolina limited liability company ("Hexis", "we", "us", "our"). We are the controller of the personal information described here. This policy covers the Hexis applications and our websites, including hexis.chat and accounts.hexis.chat.

You can reach us about anything in this policy at [email protected].

Encryption: what we can and cannot see

Hexis supports more than one way of protecting your messages, and we want to be precise about which is which rather than make a blanket claim.

Always end-to-end encrypted

Direct messages between you and another person, and voice and screen sharing.

For these, encryption keys are generated and held on your devices. Content is encrypted before it leaves your device and we handle only the encrypted form. We cannot read it, and neither can anyone who obtains it from us.

Servers — you choose the mode

When someone creates a Hexis server, they choose whether it is an end-to-end encrypted server or a standard server. This choice is permanent for that server and is shown in the app.

In an end-to-end encrypted server, message content is encrypted on your device. We cannot read it. In exchange, some features that require the service to process content are unavailable, and content cannot be recovered by us if you lose access to your keys.

In a standard server, message content is transmitted and stored in a form we are technically able to access. We do not read it for advertising, profiling, or training purposes — see What we never do — but we may process it automatically to enforce server rules and our own policies (for example, automated filters that a server owner has configured, or spam and abuse prevention), and we may access it where we are legally required to or where it is necessary to investigate abuse.

If you want the strongest guarantee, use direct messages or an end-to-end encrypted server. The app tells you which mode you are in.

One important limit that applies to every mode: if a user reports a message for review, their app sends us a copy of that message's content — including in end-to-end encrypted conversations, where the reporting user's own device decrypts it first. This is the only way a report about encrypted content can be reviewed at all. Reported content is accessible to the small number of people who handle abuse reports and is retained only as long as needed to resolve the report and any related enforcement.

Finally, note that encryption protects content, not the fact that communication happened. To deliver a message we necessarily handle information such as which accounts are in which servers and conversations, and when a connection was made.

What we never do

  • We do not sell, rent, or trade your personal information.
  • We do not share your personal information with advertisers, data brokers, or ad networks, and we do not show ads.
  • We do not scrape or harvest your content, build advertising or behavioral profiles, or use your content to train artificial intelligence or machine-learning models.
  • We do not embed third-party analytics, advertising, or tracking software in our apps.
  • We do not use tracking cookies or cross-site tracking on our websites.

Information we handle

We try to collect as little as possible. In general terms:

Information you give us

  • Account information, such as your username, display name, and password (which we store only as a cryptographic hash, never in a readable form).
  • Optional profile information you choose to add, such as an email address, avatar, or short bio.
  • Payment information. Subscriptions are processed by our payment provider. We receive information such as your subscription status and a customer identifier. We never receive or store your full card number.
  • Age verification. In some countries we are required to confirm that users are adults. Where that applies, verification is performed by a third-party identity provider. We receive only a confirmation and an irreversible reference value — we never receive or store your identity document, photograph, name, or date of birth.
  • Communications with us, such as support requests, abuse reports, and feedback.
  • Waitlist information, if you sign up for one, such as your email address and the preferences you tell us about.

Information created by using the service

  • Content, handled as described in Encryption above.
  • Delivery and membership information necessary to route messages, such as which servers, channels, and conversations an account belongs to.
  • Device and connection information, such as IP address, a device name you or your device provides, and app version. IP addresses are used chiefly for security purposes such as rate-limiting and abuse prevention, and appear in short-lived operational logs.
  • Notification tokens, if you enable push notifications, so that the relevant platform can wake your device. Where a notification relates to encrypted content, the notification carries the encrypted content and your own device decrypts it for display — we do not send your message text to Apple or Google.
  • Settings and preferences, such as read state, notification choices, and mutes.
  • Safety and administrative records, such as moderation actions, server audit logs, and records relating to reports or enforcement.

How we use information

We use information to provide, maintain, and improve the service; to create and secure your account; to deliver messages and notifications; to process subscriptions and provide support; to detect, investigate, and prevent abuse, fraud, spam, and security incidents; and to comply with legal obligations.

Legal bases (for users in the EEA and UK). We rely on: performance of our contract with you (providing the service and billing); legitimate interests (keeping the service secure, preventing abuse, and operating our business), balanced against your rights; legal obligation (including age assurance and financial recordkeeping); and consent, where we ask for it (for example, optional marketing email), which you may withdraw at any time.

Service providers

We keep our vendor list short and use them to run the service, not to monetize you. They act as our processors, are permitted to use information only to provide services to us, and are bound by their own obligations. They fall into these categories:

  • Payments and subscription management.
  • Identity and age verification, where legally required.
  • Cloud hosting, storage, and content delivery / network security.
  • Transactional email (for example, verification and security notices).
  • Mobile push notification delivery (Apple and Google, for their respective platforms).

A current list of our service providers is available at hexis.chat/subprocessors.

We may also disclose information if we reasonably believe it is required by law, legal process, or a valid government request; to enforce our terms; to protect the rights, safety, or property of users, the public, or Hexis; or in connection with a merger, acquisition, or sale of assets — in which case we will give notice before your information becomes subject to a different policy. Disclosure is limited by design: we cannot produce content we are not able to read.

Retention and deletion

We keep information for as long as your account is active or as needed to provide the service, and afterwards only as long as necessary for legitimate purposes such as security, dispute resolution, and legal or financial recordkeeping.

When you delete your account, we remove or irreversibly scramble the personal information associated with it — including your email address, credentials, authentication secrets, and profile details — from our live systems promptly, and generally within 30 days.

A few things necessarily survive that, and we would rather say so plainly:

  • A minimal, anonymized placeholder record is retained so that conversations, reports, and administrative logs referencing your past activity remain coherent. Your account appears as a deleted user.
  • Content you sent to other people or into shared servers does not disappear from their view. Messages and files you sent remain where you sent them, attributed to a deleted user. This is a property of a shared conversation, not a choice about your data — the same way an email you sent stays in the recipient's mailbox.
  • Encrypted backups. We keep encrypted backups for disaster recovery on a rotating schedule. Deleted information persists in those backups until they age out, which may take up to six months. Backups are not used to restore individual accounts.
  • Records we must keep, such as transaction records required for tax and accounting.

For the step-by-step process, see Delete your account, or Delete your data if you want specific data removed but would like to keep your account.

Security

We design for the principle that the safest data is data we cannot read. Beyond that, we use measures appropriate to the risk, including encryption of data in transit and at rest, strong password hashing, short-lived session credentials, optional two-factor authentication, and restricted internal access to production systems.

No online service can promise perfect security, and we do not. If we become aware of a breach affecting your personal information, we will notify you and any regulator as required by applicable law.

Your rights and choices

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information; to object to or restrict certain processing; to withdraw consent; and to appeal a decision we make about such a request. Residents of certain US states also have the right not to be discriminated against for exercising these rights — and because we do not sell or share personal information for advertising, there is nothing to opt out of in that respect.

You can request deletion of your account at any time — the steps are at hexis.chat/delete-account — or deletion of specific data while keeping your account, at hexis.chat/delete-data. For anything else, email [email protected]. We will respond within the time required by applicable law. We may need to verify your identity before acting on a request. Users in the EEA or UK also have the right to complain to their local supervisory authority.

International transfers

We are based in the United States and our infrastructure is operated there. If you use Hexis from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection rules than your country. Where required, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses and the UK Addendum, for such transfers.

Children

Hexis is not intended for anyone under 18, and you must be at least 18 to create an account. We do not knowingly collect personal information from children. If we learn that we have, we will delete it. If you believe a child has provided us information, contact [email protected].

Cookies and local storage

We do not use tracking or advertising cookies. Our apps and websites store only what is needed to work — for example, keeping you signed in, remembering your preferences, and carrying you through the checkout process. There is nothing here that follows you to other sites.

Changes to this policy

We may update this policy as the service changes. When we make material changes, we will update the date at the top and provide reasonable notice, such as through the app or by email. Continuing to use Hexis after an update means you accept the revised policy.

Contact

jay0 dev LLC
North Carolina, United States
Privacy: [email protected]
Support: [email protected]

© 2026 jay0 dev LLC. All rights reserved. Privacy · Terms · Refund · Subprocessors · Delete account · Delete data