Privacy Policy
V31L LTD | Company Number: 16890413 | Registered in England and Wales
Last Updated: 17 April 2026 · Version 1.1
1. Introduction
This Privacy Policy explains how V31L LTD ("We," "Us," "Our"), a company registered in England and Wales (Company Number 16890413), collects, uses, and protects your information when you use Veil ("the Platform").
Veil is the creative communication platform that combines messaging, community spaces, creative tools, and an optional AI companion, with end-to-end encryption built in as infrastructure. This policy describes what data we collect, what we cannot access due to our end-to-end encryption, and your rights under UK data protection law. If you use Veil's AI companion (Aurora), additional data handling is described in the separate Aurora Terms of Service.
2. Data Controller
V31L LTD is the data controller for your personal data:
3. What We Collect
Account Information (Required):
- Username: Account identification
- Password: Stored using industry-standard irreversible hashing; the plain password is never stored or transmitted in reversible form
- Public encryption key: Enables E2EE messaging
- Encrypted recovery data: Used to recover your account on a new device
- Account creation timestamp
Profile Information (Optional):
- About text, bio, and display preferences
- Profile picture
Email Address (Optional):
- Email address, used only for password reset, payment receipts, and critical service notifications. Stored with appropriate security measures.
Subscription and Billing Data (Paid Tiers Only):
- Subscription tier, billing cycle, and subscription status
- Payment is processed by Stripe. We do not store your full payment card details. Stripe's own privacy terms apply to payment data.
Technical Data (Automatic):
- IP address, used for security and abuse prevention (not persistently stored)
- Device and browser information, used for service compatibility (session only)
4. What We CANNOT Access (End-to-End Encrypted)
Due to our end-to-end encryption architecture, we do not have access to and cannot read:
- Message content (direct messages and group chats)
- Media content (images, files)
- Voice messages
- Voice call content
- Your private encryption key
- Your Superkey (recovery phrase)
This data is encrypted on your device before transmission. Only you and your intended recipients possess the keys to decrypt it. We cannot decrypt this content even if compelled by law - we do not possess the decryption keys.
5. User-Submitted Content for Moderation
The Reporting System:
Whilst Veil uses end-to-end encryption and we cannot normally see or decrypt your messages, we provide a user-initiated reporting mechanism to address harmful or illegal content. When you submit a report through our platform:
What You Share:
- You decrypt and voluntarily share a limited snapshot of conversation content with us
- Typically, this includes the reported message plus five (5) messages before and five (5) messages after for context
- The reporting interface shows you exactly what will be shared before you submit
- You must explicitly consent to sharing this content
- This applies to all content types: direct messages, group chats, Hub chats, Hub posts, and other encrypted content
Legal Basis for Processing Report Data:
Under UK GDPR, we process user-submitted report content on the following legal bases:
- Legitimate interests (Article 6(1)(f)): Trust and safety, preventing abuse, protecting our users and the integrity of our platform
- Legal obligations (Article 6(1)(c)): Compliance with UK law, including the Online Safety Act 2023, where we have obligations to address illegal content (particularly CSAM) when it comes to our attention
How We Use Report Data:
Report content and associated message snippets are processed strictly for the following purposes:
- Investigating the reported content and behaviour
- Enforcing our Terms of Service
- Taking appropriate moderation action (warnings, account suspension/termination, Hub removal, etc.)
- Complying with legal obligations, including reporting illegal content to relevant authorities where required
- Preserving evidence for potential legal proceedings
What We Do NOT Do With Report Data:
We will never use report content for:
- Advertising, marketing, or promotional purposes
- User profiling or behavioural targeting
- Training AI models (ours or third parties')
- Analytics or research unrelated to trust and safety
- Any purpose unrelated to moderation and legal compliance
Data Retention:
- Report content is retained only as long as reasonably necessary for moderation, enforcement, and potential legal proceedings
- Once a report is resolved and any appeals period has passed, report data is deleted unless retention is required by law
- In cases involving serious illegal activity (particularly CSAM or threats to life), we may retain report data longer to comply with legal obligations or for ongoing law enforcement investigations
6. Metadata We Can Access
While message content is encrypted, we do process certain metadata necessary to operate the service:
Message Metadata:
- Sender and recipient user IDs
- Timestamps (sent, delivered, read)
- Message IDs and delivery status
Usage Metadata:
- Last active timestamp
- Online/offline status
- Read receipts (if enabled)
Hub Metadata:
- Hub membership lists
- Roles and permissions
- Join timestamps
- Hub configuration and module settings (e.g. which features are enabled)
- Metadata relating to Hub-level content such as scheduled events, posts, and galleries (timestamps, authorship, visibility settings)
This metadata is necessary to route encrypted messages and provide service functionality.
7. Legal Basis for Processing (UK GDPR)
We process your personal data under the following legal bases:
- Account creation and authentication: Contractual necessity (Article 6(1)(b))
- Message routing and delivery: Contractual necessity
- Security and abuse prevention: Legitimate interests (Article 6(1)(f))
- Email for password reset: Consent (Article 6(1)(a))
- Payment receipts by email: Consent
- User-submitted report content: Legitimate interests (trust and safety) and legal obligations (Article 6(1)(f) and 6(1)(c))
- Legal compliance: Legal obligation (Article 6(1)(c))
8. Data Retention
- Account data: Until account deletion
- Encrypted messages: Until deleted by user or chat deleted
- Password reset tokens: 24 hours
- Email verification tokens: 24 hours
- Deleted messages: Immediately purged from our servers
- User-submitted report content: Retained only as long as reasonably necessary for moderation, enforcement, and potential legal proceedings. Deleted once resolved unless retention required by law
Self-Destruct Messages: When you send a self-destruct message, it is automatically deleted from our servers after the specified time period. Due to E2EE, we cannot access the content before or after deletion.
9. Data Disclosure and Law Enforcement Cooperation
When We May Disclose Data:
We may disclose limited personal data to law enforcement, regulatory authorities, or other third parties in the following circumstances:
- Legal obligation: When required by valid legal process (court order, warrant, statutory obligation)
- Prevention of serious harm: When necessary to protect someone from serious harm, including credible threats to life, child exploitation, or other emergencies
- Online Safety Act 2023 compliance: Where we have legal obligations to report certain illegal content (particularly CSAM) to authorities such as the National Crime Agency (NCA) or Internet Watch Foundation (IWF)
What We Can Disclose:
Due to our end-to-end encryption architecture, we can only disclose data we have access to:
We CAN provide:
- Account data (username, account creation date, subscription status)
- Email address (if provided by the user)
- Message metadata (sender/recipient IDs, timestamps, delivery status)
- User-submitted report snippets (voluntarily decrypted content shared through our reporting system)
- Hub membership and activity logs
- Invitation tree data (who invited whom)
- IP addresses where available (not persistently stored)
We CANNOT provide:
- Encrypted message content (we do not hold the decryption keys)
- Message history beyond what users have voluntarily reported
- Private encryption keys or Superkeys
- Voice call content or voice message content
Even when served with legal process, we cannot decrypt general message content. Only users possess the keys to decrypt their own communications.
Data Minimisation:
When responding to lawful requests, we will:
- Only disclose the minimum data necessary to comply with the legal obligation
- Verify the validity of the legal process before disclosing any data
- Notify affected users where legally permitted and appropriate
- Publish transparency reports where feasible
10. Your Rights (UK GDPR)
Under the UK General Data Protection Regulation, you have the following rights:
- Right of Access: You may request a copy of the personal data we hold about you. Note that we cannot provide copies of encrypted message content as we cannot access it.
- Right to Rectification: You may update your account information through your settings.
- Right to Erasure: You may delete your account at any time. This permanently removes your account data from our servers.
- Right to Restrict Processing: You may request restriction of processing in certain circumstances.
- Right to Data Portability: You may request your account data in a structured, machine-readable format.
- Right to Object: You may object to processing based on legitimate interests.
- Right to Withdraw Consent: Where processing is based on consent (e.g., optional email), you may withdraw consent at any time through your account settings.
To exercise these rights, contact admin@v31l.chat.
Right to Complain: You have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection:
11. Email Usage
If you choose to provide an email address:
Used For:
- Password reset requests
- Payment receipts (only if opted-in)
- Critical security alerts
- Subscription expiry notifications (7 days before)
Never Used For:
- Marketing communications
- Promotional emails
- Third-party advertising
- Selling or sharing with advertisers
Email Cannot Recover Encrypted Messages: Your email enables password reset for account access only. Only your Superkey can recover encrypted message history.
12. Third-Party Services
Minimal Dependencies: Veil is designed with minimal third-party dependencies. Where third parties are used, they are limited to operational necessities:
- Payment processing: Stripe processes subscription payments. Stripe's privacy policy applies to payment card data.
- Email delivery: A transactional email provider delivers password-reset emails, payment receipts, and critical service notifications (only if you have provided an email address).
- Push notifications: Operating system push services (Apple, Google, browser vendors) are used to deliver message alerts using device tokens only.
We do not use:
- Third-party analytics
- Advertising networks
- Social media trackers
- Data brokers
13. Data Location and Security
Data Storage: Your data is stored on servers located in the European region (primarily Iceland).
Security Measures:
- End-to-end encryption for all private communications
- Industry-standard irreversible password hashing
- Encrypted transport for all traffic
- Regular security audits
- Access controls and logging
14. Children's Privacy
Veil is not intended for children under 13. We do not knowingly collect personal data from children under 13. If we learn we have collected data from a child under 13, we will delete it promptly.
15. International Transfers
Your data is primarily stored and processed within the European Economic Area (EEA), which provides equivalent data protection standards to the UK under UK GDPR adequacy decisions. Certain third-party operational services (such as payment processing or push notification delivery) may involve transfers outside the UK/EEA; in those cases appropriate safeguards (such as standard contractual clauses or adequacy decisions) are in place in compliance with UK GDPR.
16. Aurora (AI Companion)
Aurora is Veil's optional AI companion. Using Aurora is entirely opt-in and subject to the separate Aurora Terms of Service, which describes the processing of Aurora conversations, memory features, AI limitations, and your associated rights. If you do not use Aurora, no Aurora-specific data is generated or processed for your account.
17. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes through Veil or by other reasonable means. The "Last Updated" date at the top indicates when the policy was last revised.
18. Contact
For privacy enquiries or to exercise your data protection rights: