Privacy Policy
WhiteStar Enterprise Messenger

Effective Date: April 3, 2026 • Android Application

1. Introduction

WhiteStar Labs ("we," "us," or "our") operates the WhiteStar Enterprise Messenger Android application (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App. Please read this policy carefully. By installing or using the App, you agree to the practices described in this Privacy Policy.

WhiteStar Enterprise Messenger is built on a zero-knowledge architecture with end-to-end encryption. This means we are technically unable to read your messages, view your files, or listen to your calls — even if compelled to do so.


2. Information We Collect

2.1 Account Information

When your organization provisions your account, the following information may be stored on your organization's self-hosted server:

  • Display name and username
  • Organizational email address
  • Profile photo (if provided)
  • Public encryption keys

2.2 Message Content

All messages, files, images, voice messages, and other content transmitted through the App are end-to-end encrypted using the Signal Protocol (X3DH key agreement, Double Ratchet algorithm, AES-256-GCM). Message content is encrypted on your device before transmission and can only be decrypted by the intended recipient. We have no ability to access this content.

2.3 Technical & Device Information

To provide and maintain the service, we may collect:

  • Device type, model, and operating system version
  • App version
  • Push notification tokens (Firebase Cloud Messaging)
  • IP address (transiently, for connection establishment only)
  • Crash reports and diagnostic logs (containing no message content)

2.4 Information We Do NOT Collect

WhiteStar Enterprise Messenger is designed to minimize data collection. We do not collect:

  • Message content, attachments, or call audio/video
  • Contact lists or address books from your device
  • Location data or GPS coordinates
  • Browsing history or app usage analytics
  • Advertising identifiers or tracking data
  • Biometric data (biometric authentication is processed entirely on-device)
  • Phone numbers (the App does not require a phone number to operate)

3. How We Use Your Information

The limited information we collect is used exclusively to:

  • Deliver and route encrypted messages to the correct recipients
  • Establish and maintain secure WebRTC voice and video calls
  • Send push notifications for incoming messages and calls
  • Authenticate your identity to your organization's server
  • Diagnose technical issues and improve App stability
  • Comply with applicable legal obligations

We do not use your information for advertising, profiling, behavioral targeting, or sale to third parties. We do not serve ads of any kind within the App.


4. Data Storage & Encryption

WhiteStar Enterprise Messenger employs a self-hosted deployment model. All server-side data is stored on infrastructure owned and operated by your organization — not by WhiteStar Labs. This ensures complete data sovereignty.

  • Messages at rest: Encrypted with AES-256-GCM. Decryption keys exist only on recipient devices.
  • Messages in transit: Secured via TLS 1.3 in addition to end-to-end encryption.
  • Local device storage: Message database on your Android device is encrypted using Android Keystore-backed keys.
  • Key management: Private keys are generated and stored exclusively on your device and are never transmitted to any server.

5. Data Sharing & Disclosure

We do not sell, rent, or trade your personal information. We may share limited information only in the following circumstances:

  • With your organization: Account metadata is accessible to your organization's server administrators as part of the self-hosted deployment.
  • Firebase Cloud Messaging: Push notification tokens are shared with Google's Firebase Cloud Messaging service solely to deliver push notifications. Notification payloads are encrypted and contain no message content.
  • Legal compliance: We may disclose information if required by law, subpoena, or court order. However, due to our zero-knowledge architecture, we have no access to message content, call data, or encryption keys.

6. Android Permissions

The App requests the following Android permissions, each for a specific and limited purpose:

  • Internet (INTERNET): Required to connect to your organization's messaging server and deliver messages.
  • Camera (CAMERA): Used for video calls and capturing photos to send as encrypted attachments. Only activated when you initiate these actions.
  • Microphone (RECORD_AUDIO): Used for voice calls and voice messages. Only activated during active calls or voice recording.
  • Notifications (POST_NOTIFICATIONS): Used to display incoming message and call notifications.
  • Storage/Media (READ_MEDIA_IMAGES, READ_MEDIA_VIDEO): Used to attach photos and videos from your device to encrypted messages. Access is granted per-selection only.
  • Biometric (USE_BIOMETRIC): Used to lock and unlock the App with fingerprint or face authentication. Biometric data never leaves your device.
  • Foreground Service (FOREGROUND_SERVICE): Used to maintain a persistent connection for real-time message delivery and active calls.
  • Vibrate (VIBRATE): Used for notification and call alerts.
  • Wake Lock (WAKE_LOCK): Used to ensure incoming call and message notifications are received when the device is in sleep mode.

All permissions are requested at runtime and can be revoked at any time through your Android device settings.


7. Data Retention

Because WhiteStar Enterprise Messenger is self-hosted, data retention policies are determined by your organization's server administrators. WhiteStar Labs does not retain any user data on its own infrastructure.

  • On-device messages: Stored locally on your device until you delete them or uninstall the App.
  • Server-side data: Managed by your organization according to their retention policies.
  • Crash reports: Automatically purged after 90 days.

8. Your Rights & Choices

Depending on your jurisdiction, you may have the following rights:

  • Access: Request a copy of the personal data associated with your account.
  • Correction: Update or correct inaccurate account information.
  • Deletion: Request deletion of your account and associated data.
  • Portability: Request your data in a portable format.
  • Withdraw consent: Revoke any previously granted permissions at any time.

Since all data resides on your organization's self-hosted infrastructure, most data rights requests should be directed to your organization's IT administrator. For requests related to WhiteStar Labs services directly, contact us at the address below.


9. Children's Privacy

The App is designed for enterprise and government use and is not intended for children under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us so we can take appropriate action.


10. International Data Transfers

Because WhiteStar Enterprise Messenger uses a self-hosted model, your data remains on infrastructure controlled by your organization in the jurisdiction of your organization's choosing. WhiteStar Labs does not transfer your data internationally. Any limited technical data (such as crash reports) is processed in the United States in accordance with applicable data protection laws.


11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Effective Date" at the top of this page and, where appropriate, notify you through the App or via your organization's administrator. Your continued use of the App after any changes constitutes acceptance of the updated policy.


12. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us:

WhiteStar Labs
Las Vegas, Nevada, United States

Email: privacy@whitestarlabs.com
Web: www.whitestarlabs.com