Our policies

Data Minimization

Nothing is more important to us than your privacy, security, and safety. We do everything we can to minimize data collection - if we don't have any valuable data, no one can steal it or force us to give it to them.

Security Audits

nthLink systems regularly undergo security audits by independent digital security organizations against the latest security standards.

All findings have since been addressed and the fixes were in turn verified. Read the full security audit reports (PDF):

2023 nthLink Security Audit (performed by Include Security)
2020 nthLink Security Audit (performed by Cure53)
2019 nthLink Security Audit (performed by Cure53)

Third-party libraries used by nthLink

Privacy Policy

In the following policy, nthLink refers to the service offered by nthLink (the "Company" or "We") through the nthLink.com website (the "Service"). This Privacy Policy explains (i) what information we collect through your access and use of our Service (ii) the use we make of such information; and (iii) the security level we provide for protecting such information.

By visiting nthLink.com and using the Services provided here, you consent to the terms outlined in this privacy policy.

Data Collection

Our company's overriding policy is to collect as little user information as possible to ensure a completely private and anonymous user experience when using the Service. We also have no technical means to access your encrypted message contents.

Service's user data collection is limited to the following:

Visiting our website: We employ a local installation of an analytics tool, on the home page only. Analytics tool is not employed in the nthLink software. Your IP address in our server logs is hashed and cannot be used to trace back to you.

Software usage: We do not require ANY personal information to use the nthLink software and access the nthLink Servers.

Communicating with nthLink: Your communications with the Company, such as support requests, bug reports, or feature requests may be saved by our staff.

Data Use

We do not have any advertising on our site. Any data that we do have will never be shared except under the circumstances described below in Data Disclosure. We do NOT do any analysis on the limited data we do possess.

Data Disclosure

We will only disclose the limited user data we possess if we receive notice from the United States of America government regarding a court order that is coming from the authorities we are legally obligated to recognize. While we may comply with electronically delivered notices (see exceptions below), the disclosed data can only be used in court after we have received an original copy of the court order by registered post or in person, and provide a formal response.

nthLink may from time to time, contest court orders if there is a public interest in doing so. In such situations, the Company will not comply with the court order until all legal or other remedies have been exhausted. Therefore, not all court orders will lead to data disclosure.

Modifications to Privacy Policy

nthLink reserves the right to periodically review and change this policy from time to time and we will notify users who have enabled the notification preference about changes to our Privacy Policy. Continued use of the Service will be deemed as acceptance of such changes.

Applicable Law

This Agreement shall be governed in all respects by the substantive laws of the State of Virginia and the United States of America. Any controversy, claim, or dispute arising out of or relating to the Agreement shall be subject to the jurisdiction of the competent courts of the State of Virginia, USA.

Open Source

The nthLink client source code repository is published in Github under the 3-Clause BSD license.