← Back to Wirio

Deutsch · English

Privacy Policy

This is a convenience translation. In case of doubt, the German version (Datenschutzerklärung) prevails.

This policy explains which data this messenger processes. The Swiss Data Protection Act (FADP) applies and – insofar as users from the EU use the service – the European General Data Protection Regulation (GDPR).

1. Controller

Fabian Meyer, Weissensteinweg 10, 5330 Bad Zurzach, Switzerland
E-mail: fabian@diemeyerz.de

2. What data is processed

Not used: advertising, tracking services, analytics tools, third-party cookies, or any sharing of data for commercial purposes.

3. Purposes and legal bases

Processing takes place solely to provide the messenger service (delivery and display of messages; Art. 6(1)(b) GDPR) and to ensure the security and stability of the service (Art. 6(1)(f) GDPR).

4. End-to-end encryption

All data is transmitted encrypted (HTTPS/TLS). In addition, all message content is end-to-end encrypted: text messages in one-to-one and group chats as well as all sent media (images, videos, voice messages). Content is encrypted on the sender's device and only decrypted on the recipients' devices. On the server it exists exclusively in encrypted form that the operator cannot read; for media files the server cannot even tell what kind of content they contain. Private keys never leave the users' devices.

Transparency about the limits: metadata required for delivery cannot be encrypted – i.e. who writes with whom and when, contact lists, group memberships and sender names in groups. Messages sent before encryption was introduced remain unencrypted.

Status posts (stories) are also end-to-end encrypted: only your own contacts receive a sealed key copy. Status posts are automatically and completely deleted from the server after 24 hours; additionally, only the information which contacts have viewed a post is stored.

Note: since private keys exist only on the respective device, end-to-end encrypted messages cannot be recovered after switching devices or clearing browser data.

4a. Voice and video calls

Calls are transmitted directly between the participants' devices (peer-to-peer, WebRTC) and are always end-to-end encrypted (DTLS-SRTP). Audio and video never pass through the server; it only brokers the connection setup. For technical reasons the participants' devices exchange their IP addresses with each other. A STUN service (currently operated by Google) is used for connection setup and thereby learns the device's IP address – it does not receive any call content. Calls are not recorded or logged on the server.

5. Hosting

The service runs on a server managed by the operator and rented from the following provider:

netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany

The server is located in a data centre in Germany; all data is processed and stored there. netcup acts as a processor within the meaning of Art. 28 GDPR on the basis of a data processing agreement. As the data centre operator, the provider technically has access to the infrastructure – however, message content and media are stored there exclusively end-to-end encrypted (see section 3) and therefore cannot be read by the hosting provider either. Beyond that, data is not passed on to third parties unless there is a legal obligation to do so.

6. Storage period

7. Your rights

You have the right to information about the data stored about you, to rectification, erasure, restriction of processing, data portability and objection to processing. Please contact the e-mail address above. You also have the right to lodge a complaint with a data protection authority – in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), in the EU the competent national authority.

8. Changes

This policy will be updated whenever the functionality of the service changes.

Last updated: 24 July 2026