Privacy notice
What we collect. Which is very little.
Last updated 16 September 2026 · Operator: PrivacyPortal Ltd, registered in England and Wales (company 14907634).
This website
- No cookies, no local storage, no JavaScript. Every page is static HTML and one stylesheet.
- No third-party requests. Nothing on graphite.chat loads from analytics, font, advertising or social networks. The only external links point to the Graphite relay, PrivacyPortal and GrapheneOS, and following them is your choice.
- No access logs. The web server is configured to discard request logs, so we do not keep IP addresses, user agents or pages visited.
- Transport. The site is served over HTTPS only (HSTS) from a server we rent in the EU. The hosting provider sees network traffic to that server like any host does; it receives nothing from us about you.
Downloads
The Windows and Android builds are served by the Graphite relay at messenger.privacyportal.co.uk, which also runs under a no-logs configuration. Each release is hash-pinned in a signed release manifest; the checksums on the download section let you verify what you received.
The Graphite app and relay
- Your identity is a 12-word recovery phrase generated on your device. There is no sign-up, phone number, email address or password, and the relay holds no recovery copy.
- Message content is end-to-end encrypted on your device. The relay queues sealed envelopes it cannot read and deletes undelivered ones after 7 days at most.
- The relay holds the public-key and routing material needed to deliver envelopes, plus short-lived delivery state. Connections are routed over Tor by default.
- The relay publishes a machine-readable transparency document describing its configuration, endpoints and release identity. Where this page and that document differ, the document is authoritative.
Your rights and contact
Because neither the website nor the relay keeps personal data about you, there is normally nothing for us to export or erase. If you believe we hold something about you, or have any question about this notice, write to admin@privacyportal.co.uk.
Reporting a security vulnerability
If you find a security problem in the app, the relay or this site, please tell us before telling anyone else: admin@privacyportal.co.uk. We will acknowledge within 5 working days, keep you informed, and credit you if you wish. Please give us a reasonable time to fix the issue before disclosure, and do not access other people's data while testing. This information is also published in machine-readable form at /.well-known/security.txt.