VC-PR-002 / 7 MIN / 09 AUG 2026

Metadata and privacy boundaries

Which operational data remains necessary despite content protection and how VENTEX separates content, metadata and evidence.

State: controlled MVP · not externally audited
MaturityCurrent product state
Review basisRepository-aligned
Reviewed2026-08-09
01

Content protection is not metadata absence

Encrypted content and operationally necessary metadata are different data classes. A service must, for example, process accounts, devices, memberships, delivery state and technical timestamps.

VENTEX therefore claims neither complete anonymity nor operation without metadata.

02

Operationally necessary data

The documented core includes account and device identifiers, session state, conversation membership, encrypted payloads, file objects, delivery and read receipts, and security-relevant events.

File type, ciphertext size, participant relationships and timestamps may remain visible despite protected content.

03

Retention and deletion

Technical deletion jobs limit selected history and revoked-session data. Concrete legal periods depend on controller, purpose, contract, hosting model and applicable law.

A technical default must not be presented as a fully approved legal retention policy.

04

Before production approval

Privacy notice, processing agreement, subprocessors, storage locations, data-subject rights and international transfers require real provider information and legal review.