Privacy_Policy
Effective Date: July 31, 2026
01_Overview
B-Message is a free, privacy-first text encryption utility built and maintained by Beaver Byte ("we", "us"), based in Canada. B-Message runs entirely in your web browser and uses AES-256-GCM encryption via the browser’s native Web Crypto API to lock and unlock text.
This policy explains, plainly, what happens to your data when you use B-Message. The short version: your message content and passphrases never leave your device, and we don’t collect personal data.
02_On-Device Processing
All encryption and decryption happens locally, inside your own browser session. When you type a message and a passphrase into B-Message, that text is processed on your device using the Web Crypto API and is never transmitted to any server operated by us or anyone else. We have no servers that receive, process, or store your message content, and no ability to read it.
03_Data We Do Not Collect
B-Message does not have user accounts. We do not collect:
- Message content, plaintext or ciphertext
- Passphrases or encryption keys
- Names, emails, or other account information
- Device identifiers or advertising IDs
- Location data
Because there is no account system, there is nothing tied to your identity for us to store in the first place.
04_Standard Hosting Data
Like any website, the B-Message web app is served by hosting infrastructure that may automatically record standard technical request data (such as IP address, browser type, and timestamps) for security and abuse-prevention purposes. This is infrastructure-level logging common to all websites, is not linked to any message content, and is not used by us to track, profile, or identify individual users.
05_No Analytics, No Tracking, No Cookies
B-Message does not use analytics services, advertising SDKs, or tracking cookies. We do not track how you use the app, and we do not build behavioral or advertising profiles.
06_No Third-Party Sharing
Because we do not collect message content or personal data, we have nothing to share, sell, or disclose to third parties, advertisers, or data brokers.
07_Security
B-Message uses AES-256-GCM authenticated encryption with key derivation performed locally via the Web Crypto API. Your passphrase is the only key to your data — we do not store it, and we have no mechanism to recover it. If you lose a passphrase, the associated message is permanently unrecoverable, by us or anyone else.
08_Children's Privacy
B-Message is not directed at children under the age of 13, and we do not knowingly collect personal data from children. Since the app collects no personal data from any user, this applies equally to all age groups.
09_App Store Data Safety
For the purposes of Google Play’s Data Safety section and Apple’s App Privacy ("Nutrition Label") disclosures: B-Message does not collect or share any user or device data with us or any third party.
10_Changes To This Policy
We may update this policy from time to time to reflect changes in the app or legal requirements. Material changes will be reflected by updating the effective date above.
11_Contact
Questions about this policy can be sent to info@beaverbyte.ca.
Beaver Byte · Canada