B3

Privacy · last updated 28 August 2026

Privacy

B3 is built so we cannot read your messages, calls or files. They are encrypted on your device before they reach our servers. This page says what we do process — routing metadata — and how you erase it.

Questions: sayhello@bfree.st. Public service hosted in Switzerland. Related: security model · terms.

Controller

B3 operates the messenger at bfree.st and the signaling host ws.bfree.st. Contact for privacy requests: sayhello@bfree.st.

What we cannot see

Message bodies, call media, files, vault items and calendar events are end-to-end encrypted or stored only on your device. We do not receive your app PIN. We do not receive your private keys. We do not run ads, advertising identifiers, third-party analytics, or Google/Apple push SDKs.

What we process, and why

Lawful basis for the account and routing data is performance of the messenger contract. Security logs use legitimate interest in running a service that is not abused.

How long

Who we share with

We do not sell data. Hosting is in Switzerland. We may disclose what we actually hold if legally compelled; because content is end-to-end encrypted, that is the metadata above, not messages. Where the law allows, we will notify affected users.

Your rights

You can access, rectify, erase, restrict, port and object, and you can complain to a supervisory authority.

Children

B3 is not directed at children. Do not create an account if you are under the age your country requires for this kind of service.

Changes

If this page changes in a way that affects what we process, we will update the date above. The Android app is the source of truth for how encryption behaves; this page describes the public service as operated.