A plain description of what push.tt stores, what it is technically unable to read, and who else is involved. Where a limitation exists it is on this page rather than left for you to discover.
Voice, video and messages on organisation and private channels are end-to-end encrypted. They are sealed on the sending device to each recipient device's public key, and the server relays bytes it has no key for. This is a property of the design, not a policy we promise to keep: there is nothing for us to hand over, because we never hold it.
Public channels are the exception, and the app labels them. Anyone may join one, so an end-to-end guarantee would be theatre. They get TLS in transit and encryption at rest instead.
There is no forward secrecy yet. A stolen device key could expose that device's past messages. A ratchet is planned; until it ships, we would rather write this down than let a padlock icon imply more than it delivers.
Each of these is refused by the server until an administrator acknowledges, in writing, what it changes. That refusal is enforced server-side, not by the app being polite.
When someone joins an organisation, they are shown which of these are actually switched on for it — not a list of what could be.
push.tt runs cells in Dallas, Mexico City, Toronto and Nuremberg, all served by one primary database in Dallas, United States. Your handset connects to the nearest cell; the data lives in the US. If your organisation needs data resident in a specific jurisdiction, ask us — that is a deployment question with a real answer, not a checkbox.
Crashes are recorded with a fingerprint, capped per organisation, and visible only to that organisation and to push.tt staff. They carry no message content.
The in-app report attaches your account, organisation, app version and handset model, and says so on the screen before you send it. It carries no message content, location or recordings.
You can delete your account yourself, from Settings → Your account → Delete account in the app, or ask us to do it if you cannot reach the app. That removes your profile, devices, keys, sessions, sent messages and direct conversations.
Two things deliberately survive, and both are on the delete your account page in full: a channel you own that other people are still in is handed to another member rather than destroyed, and if you ever bought anything the purchase record is kept — required of us, and our own rule is that nothing deletes a record of money moving. In that case your account row remains as a tombstone with no name, no address, no password and no key.
Write to us through the contact page. Note that for anything end-to-end encrypted the honest answer is that we cannot produce it — your organisation's administrators can, from their own key, if retention is on.