Privacy · last updated 28 August 2026
Privacy
B3 is built so we cannot read your messages, calls or files. They are encrypted on your device before they reach our servers. This page says what we do process — routing metadata — and how you erase it.
Questions: sayhello@bfree.st. Public service hosted in Switzerland. Related: security model · terms.
Controller
B3 operates the messenger at bfree.st and the signaling host ws.bfree.st. Contact for privacy requests: sayhello@bfree.st.
What we cannot see
Message bodies, call media, files, vault items and calendar events are end-to-end encrypted or stored only on your device. We do not receive your app PIN. We do not receive your private keys. We do not run ads, advertising identifiers, third-party analytics, or Google/Apple push SDKs.
What we process, and why
- Account identifier (b3Id) — a fingerprint of the public key your device generated, stored hashed (HMAC-SHA256). Needed to route messages and calls.
- Public identity key and prekey bundle — public keys only, so a contact can start an encrypted session while you are offline.
- Device record — hashed device id, platform, online flag, last-seen. Needed to deliver to the right handset.
- Encrypted ciphertext — held briefly when a recipient is offline, then deleted.
- Delivery and read state — so the app can show sent / delivered / read. Removed with the message.
- Social graph — that two hashed accounts are connected, because routing requires it. Contact-request payloads are sealed to the recipient.
- Connection metadata — IP address and timing at the TLS terminator, for operating and defending the service. Not used for advertising.
- Profile — display name, status, bio, avatar you choose to set, shown to your contacts.
Lawful basis for the account and routing data is performance of the messenger contract. Security logs use legitimate interest in running a service that is not abused.
How long
- Store-and-forward ciphertext: until delivered, and in any case purged on a short timer measured in hours, not months.
- Rejected contact requests: 7 days.
- Account data: while the account exists; deleted when you delete the account.
- Operational logs: high-level events with hashed identifiers, kept only as long as needed to run the service (days, not years).
Who we share with
We do not sell data. Hosting is in Switzerland. We may disclose what we actually hold if legally compelled; because content is end-to-end encrypted, that is the metadata above, not messages. Where the law allows, we will notify affected users.
Your rights
You can access, rectify, erase, restrict, port and object, and you can complain to a supervisory authority.
- Erase: in the app, Settings → Delete Account & Burn Everything. That wipes the server-side account and the local app. You can also email sayhello@bfree.st.
- Export: Settings → Export my data writes a local JSON of contacts, messages, notes and groups from the phone.
Children
B3 is not directed at children. Do not create an account if you are under the age your country requires for this kind of service.
Changes
If this page changes in a way that affects what we process, we will update the date above. The Android app is the source of truth for how encryption behaves; this page describes the public service as operated.