Subscribe to GEN
Login to GEN
Privacy is a human right, not a product feature. People and organisations are entitled to communicate without being watched, to keep their own information to themselves, and to reach an internet that nobody else has filtered for them. Strong encryption is how those rights survive in practice, and it should be available to everyone.
That conviction has shaped how GEN has built its services for three decades. We would rather build a system that does not need to be trusted than ask anyone to trust us.
GEN is a service provider and takes no political position. This page sets out what we hold to and how we act on it, not how we think the law should be.
Your communications and your data belong to you. We collect and keep only what we need to provide a service and meet our legal obligations, as our Retention Policy sets out, because data that is never held cannot be lost, stolen or demanded.
We carry traffic without blocking, throttling or prioritising it by content, application, source or destination. We step in only to protect the network and our clients, to apply filtering a client has asked for, or where a court orders it.
Strong encryption protects everyone who relies on it, and it cannot be built to protect only some people. We build it in by default and recommend it everywhere, from end-to-end encrypted messaging to OpenPGP for email.
Wherever a service allows it, we design it so that GEN never holds the keys. What we cannot read, we cannot be made to hand over, and no client has to take our word for it.
An ethos is only worth what it changes. We encourage clients to host their own services, on their own premises and under their own control. Where we manage those systems, our access is visible to the client and theirs to withdraw at any time.
Data is held in the United Kingdom by default. Where a client's circumstances call for another jurisdiction, we advise on the trade-offs and host accordingly, with keys held apart from the data where that helps, but never to help anyone evade their lawful obligations.
We act only on valid legal process from a competent authority in the United Kingdom. We check every request for validity and scope, disclose only what it requires, challenge anything defective or disproportionate, and tell the client unless the law forbids it. We do not hand over data informally, and requests from outside the United Kingdom must reach us through UK process. The formal position is in our Acceptable Use Policy.
We will not weaken the security of any service. A weakness added for one client is a weakness for every client, everywhere. If we were ever required to weaken a service, we would withdraw it.
We use, recommend and contribute to open source software on its merit: its code, its security record and the health of its maintenance, including its governance. Open source, as the Open Source Definition sets out, does not discriminate against any person, group or field of endeavour, and licences that do are not open source. Where we run a project, contributions are judged on their merit alone.
None of this is new. The rights to privacy and to freedom of expression are set out in Articles 12 and 19 of the Universal Declaration of Human Rights of 1948, and made binding in Articles 17 and 19 of the International Covenant on Civil and Political Rights. They belong to everyone, everywhere, and they are what this ethos rests on.