Last updated: August 16, 2026
Hexis is built by a small team that believes private communication should be the default, not a paid upgrade or a marketing slogan. This policy explains, in plain language, what information we handle, what we do with it, and — just as importantly — what we don't.
The rest of this page is the detail behind those statements.
Hexis is operated by jay0 dev LLC, a North Carolina limited liability company ("Hexis", "we", "us", "our"). We are the controller of the personal information described here. This policy covers the Hexis applications and our websites, including hexis.chat and accounts.hexis.chat.
You can reach us about anything in this policy at [email protected].
Hexis supports more than one way of protecting your messages, and we want to be precise about which is which rather than make a blanket claim.
Direct messages between you and another person, and voice and screen sharing.
For these, encryption keys are generated and held on your devices. Content is encrypted before it leaves your device and we handle only the encrypted form. We cannot read it, and neither can anyone who obtains it from us.
When someone creates a Hexis server, they choose whether it is an end-to-end encrypted server or a standard server. This choice is permanent for that server and is shown in the app.
In an end-to-end encrypted server, message content is encrypted on your device. We cannot read it. In exchange, some features that require the service to process content are unavailable, and content cannot be recovered by us if you lose access to your keys.
In a standard server, message content is transmitted and stored in a form we are technically able to access. We do not read it for advertising, profiling, or training purposes — see What we never do — but we may process it automatically to enforce server rules and our own policies (for example, automated filters that a server owner has configured, or spam and abuse prevention), and we may access it where we are legally required to or where it is necessary to investigate abuse.
If you want the strongest guarantee, use direct messages or an end-to-end encrypted server. The app tells you which mode you are in.
One important limit that applies to every mode: if a user reports a message for review, their app sends us a copy of that message's content — including in end-to-end encrypted conversations, where the reporting user's own device decrypts it first. This is the only way a report about encrypted content can be reviewed at all. Reported content is accessible to the small number of people who handle abuse reports and is retained only as long as needed to resolve the report and any related enforcement.
Finally, note that encryption protects content, not the fact that communication happened. To deliver a message we necessarily handle information such as which accounts are in which servers and conversations, and when a connection was made.
We try to collect as little as possible. In general terms:
We use information to provide, maintain, and improve the service; to create and secure your account; to deliver messages and notifications; to process subscriptions and provide support; to detect, investigate, and prevent abuse, fraud, spam, and security incidents; and to comply with legal obligations.
Legal bases (for users in the EEA and UK). We rely on: performance of our contract with you (providing the service and billing); legitimate interests (keeping the service secure, preventing abuse, and operating our business), balanced against your rights; legal obligation (including age assurance and financial recordkeeping); and consent, where we ask for it (for example, optional marketing email), which you may withdraw at any time.
We keep our vendor list short and use them to run the service, not to monetize you. They act as our processors, are permitted to use information only to provide services to us, and are bound by their own obligations. They fall into these categories:
A current list of our service providers is available at hexis.chat/subprocessors.
We may also disclose information if we reasonably believe it is required by law, legal process, or a valid government request; to enforce our terms; to protect the rights, safety, or property of users, the public, or Hexis; or in connection with a merger, acquisition, or sale of assets — in which case we will give notice before your information becomes subject to a different policy. Disclosure is limited by design: we cannot produce content we are not able to read.
We keep information for as long as your account is active or as needed to provide the service, and afterwards only as long as necessary for legitimate purposes such as security, dispute resolution, and legal or financial recordkeeping.
When you delete your account, we remove or irreversibly scramble the personal information associated with it — including your email address, credentials, authentication secrets, and profile details — from our live systems promptly, and generally within 30 days.
A few things necessarily survive that, and we would rather say so plainly:
For the step-by-step process, see Delete your account, or Delete your data if you want specific data removed but would like to keep your account.
We design for the principle that the safest data is data we cannot read. Beyond that, we use measures appropriate to the risk, including encryption of data in transit and at rest, strong password hashing, short-lived session credentials, optional two-factor authentication, and restricted internal access to production systems.
No online service can promise perfect security, and we do not. If we become aware of a breach affecting your personal information, we will notify you and any regulator as required by applicable law.
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information; to object to or restrict certain processing; to withdraw consent; and to appeal a decision we make about such a request. Residents of certain US states also have the right not to be discriminated against for exercising these rights — and because we do not sell or share personal information for advertising, there is nothing to opt out of in that respect.
You can request deletion of your account at any time — the steps are at hexis.chat/delete-account — or deletion of specific data while keeping your account, at hexis.chat/delete-data. For anything else, email [email protected]. We will respond within the time required by applicable law. We may need to verify your identity before acting on a request. Users in the EEA or UK also have the right to complain to their local supervisory authority.
We are based in the United States and our infrastructure is operated there. If you use Hexis from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection rules than your country. Where required, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses and the UK Addendum, for such transfers.
Hexis is not intended for anyone under 18, and you must be at least 18 to create an account. We do not knowingly collect personal information from children. If we learn that we have, we will delete it. If you believe a child has provided us information, contact [email protected].
We do not use tracking or advertising cookies. Our apps and websites store only what is needed to work — for example, keeping you signed in, remembering your preferences, and carrying you through the checkout process. There is nothing here that follows you to other sites.
We may update this policy as the service changes. When we make material changes, we will update the date at the top and provide reasonable notice, such as through the app or by email. Continuing to use Hexis after an update means you accept the revised policy.
jay0 dev LLC
North Carolina, United States
Privacy: [email protected]
Support: [email protected]