Last updated: 9 June 2026
1.1. Privify is operated by 1st Soft Limited, a company registered in England and Wales ("we", "us", "our").
1.2. We are the Data Controller for the personal data described in this policy. If you have any questions about how we handle your data, contact us at support@privify.co.uk.
2.1. Account information: your email address, collected when you register. We use this to provide the service and send transactional communications.
2.2. Payment information: payment details are entered directly into our payment processor's secure form. We never see or store your card number. We hold a customer reference and subscription ID so we can manage your account.
2.3. Your Privify number: the UK mobile number assigned to your account, where your plan includes one (Plus and Premium plans only).
2.4. Incoming messages: SMS messages received on your Privify number are stored in your account for 90 days (where applicable). Voicemail recordings are stored as audio files and linked to your account (Plus and Premium plans). Voicemail transcriptions are generated and stored on Premium plans only.
2.5. Forwarding email address: the email address you want messages forwarded to (defaults to your account email, can be changed in settings).
2.6. Usage data: basic server logs including IP addresses and request timestamps, retained for up to 30 days for security and debugging purposes.
2.7. Email aliases: aliases you create and the forwarding addresses associated with them.
2.8. Identity monitor data: your account email address is used to check against known breach records. We store check results and any alerts generated. We never store passwords or credentials of any kind.
2.9. Privify Send: when you create a secure share ("Send"), we store the content you enter in encrypted form (encrypted at rest), an optional label, and any settings you choose such as expiry and view limits. If you set a passcode, we store only a hashed version of it, never the passcode itself. We also record basic access events (such as when a Send is opened) to operate view limits, read receipts, and abuse prevention; any IP address or browser information in these events is stored only as a one-way hash, not in readable form.
2.10. Send recipient data: if you restrict a Send to specific people by email, we store those email addresses in order to verify the recipient and send them a one-time access code. Where you do not restrict access by email, we do not collect any personal data about the recipient beyond the hashed access events described in 2.9. Recipients are not required to hold a Privify account to open a Send.
2.11. Free breach check tool: if you use our public breach-checking tool at privify.co.uk/breach-check, we process the email address you enter in order to check it against known breach records and email the resulting report to that address. You do not need a Privify account to use the tool. We store only a one-way hash (SHA-256) of the address to operate the tool's result cache and rate limiting — we do not retain the plaintext address from a check itself. We store your plaintext email address only where you explicitly opt in to receive privacy tips and product updates.
3.1. We use your data solely to provide and operate the Privify service, including:
3.2. We do not use your data for marketing purposes, advertising, or profiling. We will never sell your personal data to third parties.
3.3. Our legal basis for processing is the performance of our contract with you (Article 6(1)(b) UK GDPR) and, where relevant, compliance with a legal obligation (Article 6(1)(c)).
3.4. Where you use the free breach check tool at privify.co.uk/breach-check, our legal basis is your consent (Article 6(1)(a) UK GDPR), given when you submit your address. Where you also opt in to marketing emails, that processing is based on your consent, which you can withdraw at any time using the unsubscribe link in any email or by emailing us.
4.1. SMS messages and voicemails are automatically deleted 90 days after receipt.
4.2. When you delete your account, all messages, voicemails, and account data are deleted immediately. Your subscription is cancelled at the same time.
4.3. Privify Send shares are deleted automatically when they expire or, for one-time shares, once they have been read. The encrypted content is destroyed at that point and cannot be recovered. Any recipient email addresses and one-time access codes stored for a Send are deleted with it. Hashed access events may be retained for a short period for security and abuse-prevention purposes.
4.4. We may retain certain records for longer where required to comply with a legal obligation (for example, financial records for tax purposes).
5.1. We use a small number of trusted third-party services to operate Privify. These cover areas including authentication, payment processing, voicemail storage, telecoms, and email delivery.
5.2. Each provider is selected on the basis of their security and privacy standards. We share only the minimum data required for each service to function and do not permit any provider to use your data for their own purposes.
5.3. Where any provider is based outside the UK, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses, to protect your data in accordance with UK GDPR.
5.4. We will never share your personal data with any third party for marketing or commercial purposes.
5.5. To provide breach alerts, your account email address is checked against third-party breach data sources. Only your email address is shared for this purpose, solely to determine whether it appears in known breach records.
5.6. Our breach-checking features (the identity monitor and the free breach check tool) use Have I Been Pwned, a breach-notification service based outside the UK, to determine whether an address appears in known data breaches. Only the email address being checked is shared with Have I Been Pwned for this purpose. The free breach check tool additionally uses Cloudflare Turnstile to prevent automated abuse, and Amazon Web Services to deliver the report email. Where any provider is based outside the UK, the safeguards described in 5.3 apply.
6.1. Under UK GDPR you have the following rights:
6.2. To exercise any of these rights, contact us at support@privify.co.uk. We will respond within one calendar month.
6.3. If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
7.1. We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include encrypted storage, access controls, and use of secure HTTPS connections.
7.2. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify you without undue delay.
8.1. The Privify app uses strictly necessary session cookies to keep you logged in. We do not use advertising cookies, tracking cookies, or analytics cookies.
8.2. The Privify marketing website (privify.co.uk) does not use advertising, tracking, or analytics cookies. The free breach check page loads Cloudflare Turnstile, a bot-prevention tool that may set a strictly necessary cookie or token to confirm you are human; this is required for the tool to work and is not used to track you.
8.3. For full details of every cookie we set, who sets it, and how long it lasts, please see our Cookie Policy.
9.1. We may update this Privacy Policy from time to time. We will notify you by email of any material changes at least 14 days before they take effect. The latest version will always be available at this address.
1st Soft Limited
Email: support@privify.co.uk