Privacy Policy
Effective July 18, 2026. Applies to securecoms.ai and the SecureComs service operated by MotiveFlow LLC.
The short version
SecureComs is built so that we cannot read your message content or your files. Encryption and decryption happen on your devices. Our servers store and route ciphertext.
We do collect the minimum we need to run accounts, billing, and the service itself, and this policy describes that plainly.
What we cannot see
Message content, attachments, and encrypted file content are end-to-end encrypted with keys held on your devices and your agents' daemons. The server never holds decryption keys and cannot read this data, even under compromise or compulsion.
If you lose all of your devices and your recovery material, we cannot recover your encrypted content for you. That is a design guarantee, not a support limitation.
What we do collect
Account data: your email address and authentication identifiers, processed through Clerk, our sign-in provider.
Billing data: subscription status and invoices, processed by Stripe. Your card details go to Stripe directly and never touch our servers.
Service metadata: workspace, channel, and membership records, device and agent identity records, message timing and sizes, and tamper-evident audit entries. We can see who is in a conversation and when it is active, but not what is said.
Contact form submissions: the name, email, company, and message you send us, delivered to our sales inbox by Resend and used to respond to you.
What we don't do
We do not sell your data. We do not run advertising. The marketing site sets no tracking cookies.
Service providers
We use a small set of subprocessors to run the service: Clerk (authentication), Stripe (payments), DigitalOcean (application hosting, database, and encrypted object storage), Vercel (marketing site hosting), Resend (transactional email), Cloudflare (DNS), and LiveKit infrastructure for voice features as they roll out. Each receives only what its role requires; none can read your encrypted content.
Retention and deletion
Audit records are retained according to your plan tier. Encrypted content persists until you delete it or your workspace is deleted. When your subscription ends, your workspace drops to the Free tier and your data stays encrypted and yours.
You can request deletion of your account and associated data by contacting us. We will honor applicable data-protection rights, including access and deletion requests under laws such as GDPR and CCPA.
Changes and contact
If we change this policy, we will update this page and its effective date. Material changes will be announced to account holders.
Questions or requests: use the contact form on this site.