Uxen
How we protect your messages
Uxen reads something very personal. So no big words here: what is protected and how, who can open your data and when — and where our protection ends.
What is encrypted
- The connection. Everything between you and Uxen is encrypted (TLS).
- Conversations with the assistant and what Uxen understood from your messages — memory, people, tasks, events — are stored encrypted. Each person has their own key (AES-256-GCM), and the master key is kept apart from the database.
- Sign-ins to your accounts — Telegram sessions, Google access, your mail and student account passwords — are stored encrypted.
- Backups leave the server only encrypted; their keys are not on the server.
What is not yet separately encrypted
- WhatsApp and MAX sign-ins are kept by their bridge on the server.
- Copies of messages used for search are on the server’s disk.
That’s our next step. We’ll say so here when it’s done.
Where the protection ends
To search your messages and answer, the server decrypts data. So this isn’t end-to-end encryption, and we don’t call it that. Technically a server administrator can read data — so our tools open it only through one door: every access is recorded, you get a notification right away and see it in the product under Security → Who opened your data.
Who can open your data, and when
- With your permission: you ticked “let us look” when reporting a bad answer, answered “Allow” to our request, or opened support access yourself for 7 days.
- Without permission — only two cases: investigating an attack or abuse, and a legal requirement. You are notified then too.
Who receives data
- OpenAI (USA) — to search by meaning and to answer. Under its API terms, OpenAI doesn’t train on this data and keeps logs for up to 30 days to prevent abuse.
- Google and Apple — sign-in and the connections you chose.
- Resend — emails from Uxen: sign-in codes and notifications.
- YooKassa — card and SBP payments only; your messages never go there.
- Aeza — hosting: the server is in the Netherlands.
- Anthropic (USA) — the team’s AI assistant when investigating failures; it sees your data only through the same door — with a basis and a notification to you.
Details are in the privacy policy.
Your sign-ins
- Every new sign-in sends a notification to your other devices and an email with a “Wasn’t you?” link that ends that sign-in.
- A sign-in less than a day old can’t sign out your other devices — so an intruder with a stolen code can’t lock the owner out (Telegram does the same).
- “Sign out everywhere and close access” — one tap: other devices are signed out, assistants and support lose access.
- Lock: Uxen on a device opens only after Face ID, a fingerprint or a passcode.
Deletion
Erased data leaves the working system immediately and backups within 3 weeks. A deleted account is removed after 7 days, and the person’s key is destroyed with it: rows left in backups can no longer be read. You can export your data any time — Security → Download my data.
If Uxen is ever sold or shut down, we’ll tell you in advance, let you export your data, and delete it.
Found a vulnerability?
Write to support@rrrfirstchat.com — we’ll answer. Contacts for researchers are in security.txt.