Documentation

Your data & privacy

A directory is public by design — but only for the things you choose to put in it. Here’s the honest breakdown of what’s seen, what isn’t, and who’s involved. For the formal version see the Privacy Policy.

Public vs private

Public (by design)

Your published document: handle, public keys, fingerprint, and the verified claims you chose to include. This is the whole point of a directory — anyone can fetch and verify it.

Private (never touches Subter)

Your messages, your contacts, and your private keys. These live only on your device — Subter neither sees nor stores them.

What Subter stores

What we don’t do: resolve paths (looking people up) keep no per-user logs — no IPs, no per-fingerprint counters. And the link between your account and your published identity is kept internal; it is never exposed on a public page.

Third parties

Accounts, sign-in, and billing run through established, industry-standard providers (payments are processed by Stripe), and the service runs on managed cloud infrastructure. That means a named third party holds your account details — the trade for recoverable accounts and safe payments. Your keys and messages are never part of that.

Deleting your identity

Deleting your account removes your identity, its key event log, and your published document from Subter. Two honest caveats:

Related: Billing · Privacy Policy · back to Help.