Documentation
Your data & privacy
A directory is public by design — but only for the things you choose to put in it. Here’s the honest breakdown of what’s seen, what isn’t, and who’s involved. For the formal version see the Privacy Policy.
Public vs private
Public (by design)
Your published document: handle, public keys, fingerprint, and the verified claims you chose to include. This is the whole point of a directory — anyone can fetch and verify it.
Private (never touches Subter)
Your messages, your contacts, and your private keys. These live only on your device — Subter neither sees nor stores them.
What Subter stores
- Your account (via our auth provider): your handle and the email/logins you signed up with.
- Your public keys, signatures, key event log, and the documents you publish.
- Your entitlement — whether a subscription is active — mirrored so checks are fast.
What we don’t do: resolve paths (looking people up) keep no per-user logs — no IPs, no per-fingerprint counters. And the link between your account and your published identity is kept internal; it is never exposed on a public page.
Third parties
Accounts, sign-in, and billing run through established, industry-standard providers (payments are processed by Stripe), and the service runs on managed cloud infrastructure. That means a named third party holds your account details — the trade for recoverable accounts and safe payments. Your keys and messages are never part of that.
Deleting your identity
Deleting your account removes your identity, its key event log, and your published document from Subter. Two honest caveats:
- Resolve is free and open.Anyone who already saved your fingerprint or document keeps their copy — you can’t retract what others have downloaded.
- Lapsing ≠ deleting. If you just stop paying, your account and keys are kept; you simply drop out of discovery until you re-subscribe. Deletion is the deliberate, full removal.
Related: Billing · Privacy Policy · back to Help.