Privacy in practice

Privacy is shaped by what a service can know.

Encryption matters, but privacy starts earlier: with what an account asks for, what the provider can read, what it keeps, and what would be exposed if something went wrong. These are the choices behind Polymorph’s approach.

The wider context

A digital identity is assembled one ordinary detail at a time.

Almost everyone now has a digital counterpart they never deliberately created. Searches, purchases, locations, device identifiers, accounts, contacts, and everyday interactions accumulate across companies and databases. Each fragment may appear unremarkable. Put together over time, they can describe someone’s routines, relationships, interests, finances, beliefs, health concerns, and vulnerable moments with surprising precision.

Collecting data is not inherently harmful. Some information is needed to deliver a service, prevent abuse, and keep it reliable. The risk grows when collection becomes excessive or opaque, when information is retained indefinitely or combined beyond its original purpose, and when the person behind it loses meaningful control.

The concern is not one company or one particular use. Information can be copied, inferred, traded, sold, breached, and repurposed through systems most people cannot reasonably follow. The same data can be used to categorize or target people, influence the prices they see, support investigations, or—when abused or obtained by malicious actors—enable manipulation, discrimination, fraud, harassment, and other harm. The organization using a piece of data tomorrow may not be the one it was originally shared with. As more of life becomes digital and large-scale analysis becomes easier, that portrait grows broader, more detailed, and more persistent.

Polymorph cannot undo that entire system. We can choose not to add some of your most intimate information to it. Your conversations and connections reveal who you trust, who matters to you, and what you plan, share, and build together. Our part is to give that part of your life—and the messages, calls, files, and shared work around it—a private place.

The risk

A login can become an identity anchor.

A phone number or personal email address can persist for years. It may connect an account to other services, breached datasets, an address book, or a real-world identity. Phone numbers also create an account-recovery path that can be targeted through SIM swapping.

Polymorph’s response

Creating an account does not require a phone number, email address, real name, or access to your address book. Your account is not automatically built around an identifier you already use everywhere else.

ENISA: how SIM swapping threatens phone-number accounts

The risk

The details around a conversation can reveal plenty.

Who communicates, when, how often, and from where can describe relationships and routines even when nobody reads the message itself. Research into telephone metadata has shown that these records can be readily reidentified and used to draw sensitive inferences.

Polymorph’s response

Polymorph is designed to use limited operational data to deliver, secure, and maintain the service—not to build advertising profiles or turn people’s relationships and behavior into a product.

PNAS research: the privacy properties of telephone metadata

The risk

Privacy should include protection from the provider.

A private service should not ask users to rely only on a promise that employees, contractors, future owners, or anyone gaining access to its systems will behave correctly. The safer starting point is to limit what the service is technically able to see.

Polymorph’s response

Messages, calls, shared media, Personal Files, Spaces, and online backups are end-to-end encrypted. Polymorph carries and stores encrypted content, but is designed not to hold the keys needed to read it.

The risk

A breach should expose as little as possible.

No responsible service can promise that its infrastructure will never be attacked. Security therefore also depends on reducing the usefulness of whatever an attacker could reach.

Polymorph’s response

Polymorph is designed to reduce what a compromised server could reveal: content remains encrypted, accounts are not inherently tied to a phone number or email address, and unnecessary personal information is not collected. This makes stored information harder to read and harder to connect to a real person—it does not make any system invulnerable.

NIST: protecting data against breaches and confidentiality events

The risk

Collected data can outlive its original purpose.

Information retained for convenience today can later be exposed, repurposed, combined with another dataset, or requested from the provider. Even well-intentioned collection creates an obligation and a future risk.

Polymorph’s response

We choose through policy and architecture to keep the personal and operational data required to run a reliable service limited. Information that was never collected cannot later be profiled, leaked, sold, or handed over by Polymorph.

NIST Privacy Framework: managing privacy risk across the data lifecycle

The risk

A subscription should not become proof of identity.

Payments necessarily leave information with the services and institutions that process them. If that payment record is attached directly to an account, it can quietly recreate the real-world identity link that a private signup process was designed to avoid.

Polymorph’s response

Payments are handled separately through Stripe. Anyone can buy a subscription for any Polymorph handle—the payer and the person using the account do not have to be the same. Polymorph validates the subscription through a one-way-hashed token linked to the receiving account, rather than attaching the payment record and payer’s identity to that account. Together, these choices effectively sever the direct link within Polymorph between an account and the identity behind the payment that funds it.

Note: This does not make a card payment anonymous: Stripe and the financial institutions involved still process the information needed to complete it. The separation limits what a Polymorph account itself reveals and prevents us from treating the payer as the account holder.

Stripe privacy information

Clear boundaries

What these protections cannot do.

Polymorph can protect content while it travels through and is stored by the service. It cannot protect a message after a recipient copies or records it, secure a device that has already been compromised, or make internet activity invisible to every network involved in carrying it.

Avoiding a permanent recovery identifier also places more responsibility on the user to protect their account credentials. Those limits are part of the privacy model, not details to hide in small print.

The objective

Reduce how much trust you have to place in us.

Polymorph’s privacy model is meant to let you feel secure across the service—not only in a private chat, but when you call, upload, share, organize, and collaborate. Future Polymorph features and products will be held to the same foundation.

Read the technical security architecture