Deutsch · English
Privacy Policy
This is a convenience translation. In case of doubt, the German version (Datenschutzerklärung) prevails.
This policy explains which data this messenger processes. The Swiss Data Protection Act (FADP) applies and – insofar as users from the EU use the service – the European General Data Protection Regulation (GDPR).
1. Controller
Fabian Meyer, Weissensteinweg 10, 5330 Bad Zurzach, Switzerland
E-mail: fabian@diemeyerz.de
2. What data is processed
- Account data: a self-chosen username, a password and optionally a profile picture. The password is stored exclusively as a cryptographic hash – the operator never knows the plain-text password. The profile picture is visible to other users and can be replaced at any time.
- Content: messages as well as sent images, videos and voice messages. They are stored on the server so that they can be delivered to recipients and conversation histories can be displayed.
- Contact and group data: who has added whom as a contact and who is a member of which group.
- Technical data: IP addresses inevitably appear in server logs. A session token is stored in the browser (sessionStorage) for signing in.
- Push notifications (optional): if you enable notifications, your device obtains a delivery address from the push service of your browser vendor (e.g. Google, Apple or Mozilla); this address is stored on the server and delivery technically runs through that service. Notifications never contain message content – only the fact that a new message exists and the sender or group name. You can revoke this at any time in your browser settings.
Not used: advertising, tracking services, analytics tools, third-party cookies, or any sharing of data for commercial purposes.
3. Purposes and legal bases
Processing takes place solely to provide the messenger service (delivery and display of messages; Art. 6(1)(b) GDPR) and to ensure the security and stability of the service (Art. 6(1)(f) GDPR).
4. End-to-end encryption
All data is transmitted encrypted (HTTPS/TLS). In addition, all message content is end-to-end encrypted: text messages in one-to-one and group chats as well as all sent media (images, videos, voice messages). Content is encrypted on the sender's device and only decrypted on the recipients' devices. On the server it exists exclusively in encrypted form that the operator cannot read; for media files the server cannot even tell what kind of content they contain. Private keys never leave the users' devices.
Transparency about the limits: metadata required for delivery cannot be encrypted – i.e. who writes with whom and when, contact lists, group memberships and sender names in groups. Messages sent before encryption was introduced remain unencrypted.
Status posts (stories) are also end-to-end encrypted: only your own contacts receive a sealed key copy. Status posts are automatically and completely deleted from the server after 24 hours; additionally, only the information which contacts have viewed a post is stored.
Note: since private keys exist only on the respective device, end-to-end encrypted messages cannot be recovered after switching devices or clearing browser data.
4a. Voice and video calls
Calls are transmitted directly between the participants' devices (peer-to-peer, WebRTC) and are always end-to-end encrypted (DTLS-SRTP). Audio and video never pass through the server; it only brokers the connection setup. For technical reasons the participants' devices exchange their IP addresses with each other. A STUN service (currently operated by Google) is used for connection setup and thereby learns the device's IP address – it does not receive any call content. Calls are not recorded or logged on the server.
5. Hosting
The service runs on a server managed by the operator and rented from the following provider:
netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany
The server is located in a data centre in Germany; all data is processed and stored there. netcup acts as a processor within the meaning of Art. 28 GDPR on the basis of a data processing agreement. As the data centre operator, the provider technically has access to the infrastructure – however, message content and media are stored there exclusively end-to-end encrypted (see section 3) and therefore cannot be read by the hosting provider either. Beyond that, data is not passed on to third parties unless there is a legal obligation to do so.
6. Storage period
- Account, contact and content data remain stored as long as the account exists.
- On request an account including all associated data will be deleted – an informal e-mail to the address above is sufficient.
- Server logs are kept only briefly for troubleshooting and abuse prevention.
7. Your rights
You have the right to information about the data stored about you, to rectification, erasure, restriction of processing, data portability and objection to processing. Please contact the e-mail address above. You also have the right to lodge a complaint with a data protection authority – in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), in the EU the competent national authority.
8. Changes
This policy will be updated whenever the functionality of the service changes.
Last updated: 24 July 2026