Content protection is not metadata absence
Encrypted content and operationally necessary metadata are different data classes. Since August 2026, VENTEX has decoupled several direct identifiers: message rows contain no senderId, key envelopes store an opaque recipient mark instead of a device ID, and reactions and favourites use conversation-scoped member references.
VENTEX therefore claims neither complete anonymity nor operation without metadata.
Operationally necessary data
The documented core includes account and device identifiers, session state, conversation membership, encrypted payloads, file objects and security-relevant events. New read state uses the membership sequence instead of creating individual receipt rows; legacy rows age out within the 30-day retention window.
Opaque membership references are bound to possession proofs. In the current source/test state, the client rebuilds the directory from encrypted account state on cold start and counts only proofs that were actually sent. History transfers there use an opaque target mark and skip older unmarked envelopes rather than guessing their destination. The live signed runtime requires a separate app release and migration for these changes; the service still needs limited account and relationship links for authorisation and delivery.
Affected timestamps are reduced to minute granularity. Realtime output is constrained to the public message contract. Local drafts, interface preferences and safety verification are account-scoped and selectively removed after revocation where the browser permits access.
Profile images require authentication and are protected at rest, but they are not end-to-end encrypted and remain readable to the service. An exact account identifier is sufficient for retrieval; an existing communication relationship is not required.
Retention and deletion
Technical deletion jobs limit selected history and revoked-session data. Concrete legal periods depend on controller, purpose, contract, hosting model and applicable law.
A technical default must not be presented as a fully approved legal retention policy.
Before broader organisational approval
Privacy notice, processing agreement, subprocessors, storage locations, data-subject rights and international transfers require real provider information and legal review.
