Skip to document
Baal
Terms Privacy policy
EN PL

Baal documents

Baal Terms of Service

Current document v1.1

Contents

  1. 011. Service provider and contact details
  2. 022. Definitions
  3. 033. Scope and nature of the Service
  4. 044. Technical requirements
  5. 055. Contract, Account and age
  6. 066. Encryption, delivery and security boundaries
  7. 077. Acceptable use
  8. 088. Subscription, trial and payments
  9. 099. Consumer rights and conformity with the contract
  10. 1010. Duration, termination and Account deletion
  11. 1111. Availability, maintenance and changes
  12. 1212. Complaints and dispute resolution
  13. 1313. Liability
  14. 1414. Personal data and privacy
  15. 1515. Rights in the Application
  16. 1616. Changes to these Terms
  17. 1717. Governing law and final terms

Version 1.1

Published: August 1, 2026

Effective from: September 1, 2026

These Terms govern the use of the Baal application and service and constitute the rules for the provision of services by electronic means. They also contain information concerning an interpersonal communications service and a paid digital service. Nothing in these Terms limits mandatory consumer rights.

1. Service provider and contact details#

  1. Baal is provided and operated by SKY LEGAL TECHNOLOGY Spółka z ograniczoną odpowiedzialnością, with its registered office at ul. Generała Tadeusza Klimeckiego 9/2, 33-100 Tarnów, Poland, entered in the Register of Entrepreneurs of the National Court Register under KRS number 0000790701, tax identification number NIP 8733271704 and statistical number REGON 383622561, referred to as the “Provider”.
  2. Contact details:
    • email: biuro@skylegaltech.com;
    • postal address: ul. Generała Tadeusza Klimeckiego 9/2, 33-100 Tarnów, Poland.
  3. Security vulnerabilities may be reported through the form on the Baal website or by email to biuro@skylegaltech.com. The security form is not intended for ordinary complaints.

2. Definitions#

  1. Baal or the Service — the application and infrastructure enabling pseudonymous, encrypted communication between users.
  2. Application — the Baal software for supported iOS or Android devices.
  3. Account — a user’s pseudonymous Baal identity based on a random 256-bit technical AccountId, linked to a separate signed public profile containing the chosen pseudonym and to approved Devices.
  4. Device — a supported phone or other device on which cryptographic keys and a device certificate are generated.
  5. User — an individual aged 18 or over who uses Baal.
  6. Store — Apple App Store or Google Play, through which the Application is distributed and the Subscription is managed.
  7. Subscription — the paid, renewable right to access Baal features, purchased exclusively through a Store.
  8. Ciphertext — a message encrypted on the sender’s Device which the Provider cannot read.

3. Scope and nature of the Service#

  1. Baal enables users to:
    • create a pseudonymous Account without providing a real name, email address or telephone number;
    • add and approve Devices connected to the Account;
    • exchange end-to-end encrypted messages;
    • store message history locally in an encrypted vault on Devices, with read messages logically deleted 12 hours after first reading;
    • use the Service subject to an active Subscription.
  2. Baal does not provide calls to telephone numbers, SMS messaging, access to emergency numbers or access to emergency services. In an emergency, use a telephone or another service that provides access to the appropriate authorities.
  3. Baal is not a backup service for messages, Accounts, keys or conversation history.
  4. The Provider does not guarantee a minimum quality level, uninterrupted availability or a specific message delivery time. Performance may depend on the internet connection, Device, operating system and third-party services.

4. Technical requirements#

  1. To use Baal, a User needs:
    • a supported Device running the iOS or Android version identified in the Store;
    • internet access;
    • the current version of the Application;
    • acceptance of these Terms and acknowledgement of the Privacy Policy;
    • to be at least 18 years old.
  2. Certain updates, particularly security and communications protocol updates, may be required to continue using the Service.
  3. Bypassing system security through jailbreak or root, using an unsupported operating system or installing the Application from an unverified source may materially reduce security and may prevent some features from working.
  4. Information about currently available accessibility features and compatibility with assistive technologies is published in the Store or provided on request through the Provider’s contact details. Baal does not currently offer separate hardware or services intended exclusively for users with disabilities.

5. Contract, Account and age#

  1. The agreement for the Service is concluded when the User accepts these Terms and successfully creates an Account.
  2. Before creating an Account, the User must actively select the statement: “I confirm that I am at least 18 years old.” The Provider records only the time of the statement and does not collect the User’s date of birth.
  3. The User chooses a pseudonym in a separate signed public profile. The pseudonym may be changed and is neither the AccountId nor a delivery-mailbox address. It must not be unlawful, infringe third-party rights, mislead others about identity or impersonate another person or organisation.
  4. A pseudonym is not proof of another user’s real identity. Baal provides a safety number and a public key-transparency mechanism. In conversations requiring elevated trust, Users should compare the safety number through an independent channel.
  5. The User is responsible for securing Devices, access codes and local keys and for approving only Devices the User recognises.
  6. The Account, history and keys cannot be recovered if all approved Devices are lost. The Provider does not keep backup keys and offers no reset procedure capable of restoring past correspondence. The User may create a new Account, which will be a new cryptographic identity.

6. Encryption, delivery and security boundaries#

  1. Messages are encrypted on the sender’s Device and decrypted only on recipients’ Devices. The server has no private keys, key escrow, “master key” or other mechanism capable of decrypting a conversation.
  2. An undelivered Ciphertext is held in the server’s memory queue for no more than 24 hours after acceptance. It is deleted immediately after the recipient’s Device confirms receipt. A server restart may delete an undelivered Ciphertext earlier.
  3. The Provider does not create backups of the Account database, Devices, public keys or Ciphertexts.
  4. End-to-end encryption does not protect content displayed on an unlocked, compromised or infected Device. Security also depends on the integrity of the Application, updates, operating system and proper key verification.
  5. Baal maintains a public append-only key-transparency log checked by two separate witnesses operating outside the main VPS. If the required confirmations are inconsistent, contact initiation is blocked rather than allowing the warning to be hidden.
  6. The server must process limited technical data necessary to establish a connection, route a Ciphertext and confirm delivery. This includes, among other things, the random AccountId, current public pseudonym, Device identifiers, sender and recipient delivery addresses, a random group identifier, and the frame type, size and delivery state. These data can permit inferences about part of the communications graph even though the content remains encrypted. The Privacy Policy provides details.
  7. An unread message remains in the encrypted local vault until first reading. It is logically deleted 12 hours after first reading; reopening it does not extend that period. Logical deletion and key destruction do not guarantee immediate physical overwriting of Device flash storage.
  8. Because there is no central copy, the Provider cannot restore lost history or redeliver a Ciphertext removed after expiry, delivery acknowledgement, failure or restart.

7. Acceptable use#

  1. Users must not:
    • provide or transmit unlawful content;
    • use Baal for threats, harassment, fraud, spam, malware distribution or infringement of another person’s rights;
    • attempt to gain unauthorised access to Accounts, Devices, infrastructure or data;
    • disrupt the Service, circumvent security limits or automate traffic in a harmful manner;
    • decompile or circumvent security measures except to the extent permitted by law.
  2. Because of end-to-end encryption, the Provider generally cannot access conversation content and does not proactively monitor messages.
  3. The Provider may restrict or block an Account or Device where necessary for security, abuse prevention, breach of these Terms or compliance with law. Where possible and lawful, the User will be informed of the reason and available means of appeal.

8. Subscription, trial and payments#

  1. The Subscription is offered as an annual plan. The reference price for the English offer is EUR 22.99 including VAT per year. The price for the Polish offer is PLN 99.99 including VAT per year. The final price, currency, taxes and purchase conditions are always displayed in the Store before confirmation.
  2. Where the Store offers a three-day free trial, the Subscription will automatically renew for one year and the price shown in the Store will be charged at the end of the trial unless the User cancels before the deadline shown by the Store.
  3. Purchase, renewal, cancellation, billing and payment refunds are handled exclusively through Apple App Store or Google Play, subject to applicable law and the Store’s procedures. The Provider does not receive card numbers, bank account details or billing addresses.
  4. Baal receives only the information required to confirm entitlement to the Service: platform, product, Subscription status, expiry date, last verification time and the transaction identifier or signature required by Apple or Google.
  5. Cancelling a Subscription prevents future renewals but generally does not end access before the close of the paid period.
  6. Deleting a Baal Account does not cancel the Store Subscription. Before deleting the Account, the Application provides a link to Subscription management. The User must cancel separately in the relevant Store.
  7. A price change may apply only to future billing periods and will be communicated in accordance with law and Store procedures.

9. Consumer rights and conformity with the contract#

  1. Consumers have the rights granted by applicable consumer protection law, including the right to require the digital service to be brought into conformity with the contract and, where provided by law, to obtain a price reduction or terminate the contract.
  2. Where a consumer has a statutory right to withdraw from a distance contract, that right may be exercised in accordance with applicable law. Because the payment is processed by the Store, the operational refund process may require the Apple or Google procedure. This does not limit mandatory rights against the Provider.
  3. Information about beginning performance before the withdrawal period expires, any required consent and its consequences will be provided in the contracting or purchase process where required by law.
  4. Nothing in these Terms excludes or limits the Provider’s liability where such exclusion or limitation is prohibited.

10. Duration, termination and Account deletion#

  1. The Account agreement is concluded for an indefinite period. Paid access continues for the active Subscription period.
  2. The User may stop using Baal and initiate Account deletion in the Application settings at any time.
  3. Account deletion removes from the server:
    • the active public Account profile;
    • registered Devices and their certificates;
    • unused KeyPackages;
    • pending Ciphertexts and delivery metadata held in server memory.
  4. The following remain after Account deletion: the public AccountId anchor and Account public-key history, entries in the append-only key-transparency log, and one-way hashes of retired pseudonyms. They are retained indefinitely to prevent takeover of a deleted identity, reuse of a retired name and to allow log consistency to be checked. They do not include message content or private keys.
  5. The Application deletes local history, keys and identity from the Device that performs the operation. Local data on other Account Devices may be deleted if those Devices are connected and receive the instruction.
  6. Immediate deletion cannot be guaranteed for a Device that is switched off, offline, lost or outside the User’s control.
  7. Account deletion does not remove copies of messages already delivered to other users’ Devices. Those copies remain under the recipients’ control and are subject to local retention: until first reading and then for 12 hours after first reading.
  8. Data that must be retained by law or is necessary for billing or the establishment, exercise or defence of legal claims may be kept for the required period. This does not include decryption keys or a central archive of conversation content.
  9. The Provider may discontinue the Service for important reasons, including permanent product closure, an authority’s order, a material change in law or an insurmountable technical obstacle. Users will be informed with appropriate notice unless law, security or the nature of the event requires immediate action.

11. Availability, maintenance and changes#

  1. The Provider uses measures intended to maintain security and availability. The Service may nevertheless be temporarily unavailable due to maintenance, updates, failures, attacks, infrastructure providers or events outside the Provider’s reasonable control.
  2. The Provider may change the Service in order to:
    • comply with law;
    • remedy vulnerabilities or improve security;
    • maintain interoperability and compatibility with iOS and Android;
    • respond to Store or infrastructure changes;
    • develop features without reducing agreed consumer protection.
  3. Changes beyond what is necessary to maintain conformity will not result in additional consumer cost. Where a change materially and negatively affects access to or use of the Service, consumers will receive the information and remedies required by law.

12. Complaints and dispute resolution#

  1. A complaint concerning Baal may be submitted:
    • by email to biuro@skylegaltech.com;
    • by post to the Provider’s address stated in section 1.
  2. A complaint should include the Account pseudonym or identifier, a description of the issue, the date it occurred, the User’s requested outcome and contact details for a response. Do not send private keys, passwords or another person’s message content.
  3. The Provider will respond to a consumer complaint within 14 days of receipt unless mandatory law provides another period.
  4. A consumer may seek assistance from a Polish municipal or district consumer ombudsman and may use consumer alternative dispute resolution conducted by the President of the Polish Office of Electronic Communications where the dispute falls within that authority’s jurisdiction. Information is available at uke.gov.pl/konsument.
  5. A complaint or alternative procedure does not exclude the right to bring a claim before a competent court.

13. Liability#

  1. The Provider is liable for failure to perform or improper performance and for lack of conformity of the Service in accordance with applicable law.
  2. The User acknowledges that the absence of server backups for keys and history is a core privacy feature of Baal and makes data recovery impossible after all Devices are lost.
  3. The Provider is not liable for consequences caused by:
    • giving a third party access to an unlocked Device;
    • installing malware or an unauthorised Application build;
    • failure to update the operating system or Application;
    • another user misrepresenting their identity where the User did not verify identity or keys;
    • the operation of the internet, Store or hardware outside the Provider’s control,

except where the Provider is liable under mandatory law.

  1. Liability limitations do not apply to intentional harm or any other case where liability cannot lawfully be limited.

14. Personal data and privacy#

  1. The Baal Privacy Policy describes processing purposes, retention, encryption, data recipients and data subject rights.
  2. The Provider does not use Baal for behavioural advertising, marketing profiling or the sale of user data.

15. Rights in the Application#

  1. The Application, marks, interface, code and materials are protected by law. The User receives a limited, non-exclusive, non-transferable and revocable right to use the Application for personal purposes in accordance with these Terms and Store rules.
  2. The Baal name and related marks must not be used in a way that suggests an association with the Provider without permission.
  3. This section does not limit mandatory statutory rights or licences applying to open-source components.

16. Changes to these Terms#

  1. These Terms may be amended for important reasons such as changes in law, an authority’s decision, changes to features, technology, payment model, Store requirements or security needs.
  2. A User whose ongoing agreement is affected will receive clear notice appropriate to the nature of the change, through the Application or another available durable medium. An urgent security change or a legally required change may take effect earlier.
  3. The notice will state the effective date and the User’s applicable rights. Mandatory consumer rights concerning changes to a digital service remain unaffected.

17. Governing law and final terms#

  1. These Terms are governed by Polish law. This choice does not deprive a consumer of protection granted by mandatory provisions of the country of the consumer’s habitual residence.
  2. If a provision is invalid or unenforceable, the remaining provisions remain effective.
  3. The Polish version is the primary version. The English translation is provided for accessibility and does not limit rights arising under applicable law.
  4. The current Terms are available at baal-app.com/en/terms.
Baal

Private communication without a central conversation archive.

YubiKey integration in development Yubico
Terms Privacy policy biuro@skylegaltech.com

© 2026 Sky Legal Technology Sp. z o.o.