Transparency & Data Retention

Privacy is only credible if it survives a subpoena. This page states exactly what Comr can be compelled to hand over, what it never holds, and how legal demands are reported.

Last updated August 21, 2026

The principle: collect little, so little can be demanded

Comr is designed so that a legal demand yields as little as possible. The strongest privacy guarantee is not a promise to resist requests — it is never holding the data in the first place. Comr requires no phone number, no legal name, and no address book, and it does not run advertising or sell personal information. What follows is a plain inventory, not a marketing claim.

What Comr can produce about an account

In response to valid legal process, the most Comr can currently produce about a specific account is a short set of operational fields:

  • The account's public username and display name.
  • The account creation date and last-seen timestamp.
  • Publicly posted content that is still live, which anyone can already view without legal process.
  • Coarse operational records needed to run the service, such as whether an account exists and its current status (active, suspended, deleted).

Comr does not hold a decryptable copy of any password or message PIN — only one-way Argon2 hashes — so those cannot be produced in usable form.

What the server cannot read

  • Authorized one-to-one browser text.New one-to-one text is end-to-end encrypted between enrolled participant devices with no server-readable fallback. Comr cannot produce the plaintext because it never holds the device keys. The encryption design is verified by Comr's own engineering evidence; an independent security review is planned and has not yet been performed (see the Security page).
  • Passwords, message PINs, and recovery codes. Stored only as one-way hashes. A demand for them returns hashes, not the secrets.

What the server can still read

Comr states this plainly rather than implying blanket encryption:

  • Public posts and profiles are server-stored and publicly visible by design.
  • Com (group) chat bodies are server-readable application-layer plaintext protected by access control, not end-to-end encryption.
  • Older, legacy direct messages retained from before the browser encrypted release remain server-readable under the legacy retention policy. They are not relabeled as encrypted history.
  • Metadata that operating any messaging service necessarily exposes: account identities, who is connected when, approximate timing, device counts, and IP-level traffic. Encryption protects message contents, not the fact that an exchange occurred.

How long data is kept

  • Deleted accounts. Account deletion removes account-scoped records; durable cleanup workers may continue to purge associated media shortly afterward. A narrow set of records may be retained only where a specific legal or safety obligation requires it.
  • Public content persists until the author or account removes it, or the account is deleted.
  • Operational logs are minimized and are not a long-term content archive.

Reporting legal requests

Where the law permits, Comr intends to publish the government and law enforcement demands it receives and how it responded, so the record is public rather than taken on trust.

Requests received to date: none. This line will change if and when that is no longer true. A demand accompanied by a valid non-disclosure order may legally prevent Comr from reporting that specific request; Comr does not claim the ability to defeat such an order, and does not make guarantees it cannot keep.

Questions and legal process

Formal legal process and security questions may be sent to contact@provarion.ai. Do not send another person's private data, identity documents, or account credentials through email. This page is an operational description, not legal advice, and the authoritative details of data handling live in the Privacy Policy and Security & Encryption page.