← Nocta

Privacy Policy

Last updated: 13 June 2026

Nocta is built so that we cannot read your private messages.

This Privacy Policy explains, in plain terms, what Nocta can see, what it cannot see, what data is processed to operate the service, and where the honest limits are.

1. Who we are

Nocta is provided by NOCTA Software Sp. z o.o. (“Nocta”, “we”, “us”, or “our”), a company registered under the laws of the Republic of Poland.

Registered address: pl. Bankowy 2, 00-095 Warsaw, Poland.

Company details: Registered in the District Court for the Capital City of Warsaw, under KRS number: 0001247203, NIP: 5253093572, REGON: 54498950900000.

Privacy questions: support@nocta.wtf.

2. What we cannot see

Nocta is an end-to-end encrypted messenger.

Your messages and attachments are encrypted on your devices before they are sent. Plaintext exists only on your devices and on the devices of the people you choose to communicate with.

Our server stores and forwards encrypted envelopes. It does not hold the keys required to open them.

Your long-term identity keys and Double Ratchet session state remain on your devices and are not uploaded to Nocta in plaintext.

This means that Nocta cannot read, recover, scan, sell, or manually moderate the contents of your end-to-end encrypted conversations.

3. What the server necessarily handles

To operate a messaging service, Nocta must process limited technical and routing data.

This may include:

  • account or user identifiers;
  • device identifiers;
  • public keys and pre-key material required for encrypted session setup;
  • encrypted message envelopes;
  • which account or device an encrypted envelope is addressed to;
  • delivery state, timestamps, and sync cursors;
  • push notification tokens or equivalent wake-up routing identifiers;
  • abuse-prevention, rate-limit, and security logs;
  • diagnostic and operational logs needed to keep the service reliable and secure.

This metadata is used to deliver encrypted messages, sync devices, prevent abuse, debug failures, secure the service, and operate the closed beta.

We minimise this data where possible and do not attach it to message contents, which we cannot read.

No phone number is required to use Nocta.

Nocta does not use advertising identifiers, ad tracking, or third-party analytics SDKs in the app.

4. Contact discovery

Phone-number contact discovery is optional.

If you choose to use phone-number contact discovery, Nocta uses a one-way cryptographic discovery mechanism designed so that the server cannot recover your phone number from the submitted value.

Contact discovery is used only to help you discover contacts who also use Nocta. You can use Nocta without enabling phone-number discovery.

5. Push notifications

Nocta push notifications are designed to be content-free.

A push or wake-up message does not contain message text, sender names, message previews, or attachments. It carries only the minimal technical information needed to wake your device or tell it to sync.

After receiving a wake-up event, your device syncs encrypted envelopes from Nocta, decrypts them locally, and composes any visible notification on the device.

Depending on your device and deployment mode, wake-up delivery may use providers such as Google FCM, Apple APNs, WebSocket-based wake-up, or another configured transport.

Push providers may process technical delivery metadata such as device tokens, timestamps, routing information, and network-level data. They do not receive message plaintext, sender names, or notification previews from Nocta.

On-premise deployments may use deployment-specific wake-up transports. On iOS, Apple APNs may still be required by the operating system for background wake-up.

6. Data on your device

Nocta stores local message history and app state in an encrypted local database.

The database key is designed so that the server alone cannot decrypt your local database. Nocta may use a combination of local device material, user unlock material, and server-assisted unlock material to protect access to local data.

Depending on your device and settings, PIN, biometric unlock, operating system key storage, and device security features may also help protect local data.

If you lose access to your devices and recovery material, your encrypted message history may be unrecoverable. This is a deliberate property of the design.

7. Deliberate exceptions to end-to-end encryption

Some optional features may operate outside the end-to-end encrypted message boundary. These features are labelled in the app.

Support tickets

Messages you send to Nocta support are not private end-to-end conversations. They may be read by Nocta support staff in order to respond to your request.

Bots

Messages sent to in-app bots may use a separate non-end-to-end encrypted processing lane, depending on the bot. Such interactions are marked accordingly.

Translation

If translation is enabled, the text to be translated may need to be processed by a translation component.

Depending on the deployment and selected mode, translation may be performed on-device, by a Nocta-operated service, by a third-party translation provider, or inside an on-premise customer environment.

The app will indicate when translation steps outside the normal end-to-end encrypted conversation boundary.

8. Beta access and communications

If you request beta access, we may collect your email address or other contact information you provide.

We use this information to manage beta access, send access invitations, respond to support requests, and communicate important service or security updates.

We do not use beta contact information for third-party advertising.

9. Service logs and security

Nocta may process limited operational logs to run, secure, debug, and improve the service.

These logs may include timestamps, request metadata, device or session identifiers, error reports, rate-limit events, security events, and abuse-prevention signals.

We do not log message plaintext because we do not have access to it.

Operational logs are retained for up to 30 days and then rotated out. Logs tied to security or abuse-prevention events may be kept for up to 90 days where needed to investigate and respond to such events.

10. Retention

Nocta keeps personal data only for as long as needed for the purposes described in this policy, unless a longer period is required by law, security needs, dispute resolution, or abuse prevention.

In practice we apply the following retention periods:

  • Encrypted message envelopes: deleted shortly after they have been delivered to all of a recipient’s devices (a 24-hour grace window allows a reconnecting device to still receive them). Undelivered envelopes are deleted no later than 30 days after they were accepted; envelopes with a sender-set expiry (disappearing or broadcast messages) are deleted when that expiry passes.
  • Delivery metadata and sync cursors: removed together with the envelopes they relate to.
  • Device records and push tokens: kept while the account and device exist; deleted when you remove the device or delete your account.
  • Server logs: up to 30 days (up to 90 days for security-related logs), as described in section 9.
  • Beta and enterprise contact emails: deleted no later than 12 months after they were submitted, or earlier on request.
  • Deleted or revoked accounts and devices: removed promptly when you delete your account or revoke a device, including the associated handle, which is then freed for reuse.

11. Your control

Depending on the app version and deployment mode, you may be able to:

  • revoke a lost or untrusted device;
  • wipe local data from a device;
  • delete or expire messages using TTL features;
  • manage linked devices;
  • manage recovery settings;
  • disable optional features such as contact discovery or translation.

Some data may remain in encrypted backups, recipient devices, system logs, or on-premise operator systems depending on the deployment and feature used.

12. Your privacy rights

Depending on your location and applicable law, you may have rights to:

  • access personal data we process about you;
  • request correction of inaccurate data;
  • request deletion of personal data;
  • request restriction of processing;
  • object to certain processing;
  • request portability of data you provided;
  • withdraw consent where processing is based on consent;
  • lodge a complaint with a data protection authority.

Because Nocta cannot read end-to-end encrypted message contents, we may not be able to provide or recover plaintext message history from the server.

To exercise privacy rights, contact: support@nocta.wtf.

As a user under the jurisdiction of the GDPR, you have the right to lodge a complaint with a supervisory authority. In Poland, this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych – PUODO).

13. On-premise deployments

For corporate or on-premise deployments, the customer or operator runs Nocta inside its own infrastructure.

In that model, the operator may be the data controller or data operator for its users, infrastructure, logs, policies, and compliance obligations. Nocta Software acts as the software vendor and, where agreed separately, may provide support, updates, or processing services under a separate agreement.

On-premise operators are responsible for their own user notices, legal basis, retention rules, access controls, audits, and compliance requirements.

14. Source code and security model

Published Nocta source code is available under the GNU Affero General Public License v3.0 unless stated otherwise in the relevant repository or file.

Nocta’s technical security model is published alongside the code.

The published source code license governs your use, modification, and distribution of the code. This Privacy Policy explains how the Nocta service processes data.

15. Changes to this policy

We may update this Privacy Policy as Nocta develops.

If we make material changes, we will make the updated policy available through the website, app, or another reasonable channel.

Your continued use of Nocta after the updated policy becomes effective means that you acknowledge the updated policy.

16. Contact

Questions about privacy: support@nocta.wtf.