Effective: 25 August 2026
This English version is a faithful information translation of the German privacy policy. In case of doubt, the German wording is authoritative.
1. Controller
Detlev PickertWalther-Rathenau-Str. 26
15537 Gosen-Neu Zittau
Germany
Email: d.pickert@konvoro.com
Privacy and support: support@konvoro.com
2. Data minimisation principle
Konvoro is designed so that setting up a communication identity does not require a phone number or email address. The app does not access your contacts or your existing photo library. Text messages and photos captured directly inside Konvoro are end-to-end encrypted within the secure connection.
3. Visiting this website
This website is delivered as a static site and, at launch, uses no analytics, marketing or profiling services, no advertising trackers and no contact form. The website itself sets no analytics or marketing cookies and loads no external fonts.
When the website is requested, the web server processes connection data technically required for delivery. This may include the IP address, time, requested resource, browser and system information, transferred data volume and server status. The sole purposes are secure technical delivery and detection of faults or abuse. The legal basis is Article 6(1)(f) GDPR; the legitimate interest is the secure and reliable operation of the service.
Regular Nginx access logging is disabled for the static website. Technical error logs are kept separately and are rotated or deleted by the server configuration after no more than seven days.
The website and Konvoro backend are operated on server infrastructure provided by Hetzner Online GmbH. The data-centre location used is Helsinki, Finland, within the European Union.
4. Contact and support
If you contact us by email, the information you provide is processed as necessary to handle and answer your request. Depending on the request, the legal basis is Article 6(1)(b) GDPR (contract or pre-contractual measures) or Article 6(1)(f) GDPR (handling other requests and operating secure support).
Please do not send confidential message content, invitation codes, key material or other secret information to support. Support emails are deleted once the matter is closed and no statutory retention or evidence obligation requires further storage.
5. Processing in the Konvoro app
5.1 Identity and technical assignment
Konvoro processes pseudonymous user, device and connection identifiers and the public cryptographic material needed to establish and operate secure connections. A Konvoro identity is assigned to exactly one device; another device receives a new identity.
5.2 Invitations, connections and delivery
For personal invitations and secure one-to-one connections, the server processes technical identifiers, states and timestamps required for setup, assignment, delivery, replay protection and error handling. These may include device and connection identifiers, invitation and delivery identifiers, epoch/protocol states, creation, delivery and read timestamps and status values.
5.3 Messages and photos
Text messages and photos captured directly inside Konvoro are end-to-end encrypted. For delivery, the server receives encrypted message envelopes and technically necessary metadata, but not the message plaintext. No one outside the secure connection – including the server operator or administrator – can read the message content from the normal delivery record.
After successful local decryption, the app confirms that the message was read. The server-side encrypted content is then removed according to the product protocol. Unread encrypted messages expire after the retention period applicable to the connection. The current technical default is 168 hours (seven days), with a technical minimum of one hour and maximum of 720 hours (30 days).
5.4 Local protection and crash recovery
The app stores device-related secrets and session data in protected iOS storage. Short-lived local recovery state may be necessary to avoid losing a message that has already been decrypted but not yet safely handed to the user interface after a crash. Such state is not a message archive and is removed after successful handover or according to the message lifecycle.
5.5 Authentication and abuse prevention
Short-lived challenges, session identifiers, token hashes and technical security data may be processed for device authentication. In the current system, authentication challenges expire after five minutes and authenticated sessions after 24 hours. The source IP may be technically processed for rate limiting and abuse prevention and used in hashed form for counters; current rate-limit records are cleaned after no more than two days. Technically necessary API access and error logs are kept for attack detection and fault diagnosis; they are rotated or deleted after no more than seven days.
5.6 Push notifications
Where push notifications are enabled and technically used, a device push token is processed and Apple Push Notification service (APNs) is used for delivery. Push notifications are intended not to contain confidential message content; they serve only as a discreet technical signal that the app can fetch new data. Apple’s privacy terms additionally apply to Apple’s processing.
6. Purposes and legal bases
- Providing the app and secure message delivery: Article 6(1)(b) GDPR.
- IT security, abuse prevention and fault diagnosis: Article 6(1)(f) GDPR. The legitimate interest is secure and reliable operation.
- Legal obligations: Article 6(1)(c) GDPR where processing is required by law.
- Consent-dependent device functions: where legally required, Article 6(1)(a) GDPR; consent can be withdrawn for the future.
7. Recipients and service providers
Hetzner Online GmbH is used as the technical infrastructure provider for hosting and server operation. When the App Store or push notifications are used, Apple also receives the data required for those services. Konvoro does not provide message plaintext to these recipients.
8. Apple App Store
The iPhone app is downloaded through the Apple App Store. Apple is independently responsible for processing within its services. Konvoro receives only the distribution information that Apple actually makes available to app providers under the App Store agreement.
9. Retention
Konvoro keeps personal or linkable technical data only as long as required for its purpose or by law. The concrete periods stated above apply to message delivery, authentication challenges, sessions and rate-limit records. Identity, device, connection and security metadata is deleted or anonymised when its purpose ceases, an identity is deleted, or necessary security/fault investigations are completed, unless legal retention duties require otherwise.
10. Your rights
Subject to the conditions of the GDPR, you have rights including access, rectification, erasure, restriction of processing, data portability and objection. Where processing is based on consent, consent may be withdrawn at any time with effect for the future.
Please send requests to support@konvoro.com.
11. Right to complain
You may lodge a complaint with a data-protection supervisory authority. The authority at the controller’s place of establishment can be reached at:
Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht BrandenburgStahnsdorfer Damm 77
14532 Kleinmachnow
Germany
Email: Poststelle@LDA.Brandenburg.de
12. Changes
This privacy policy will be updated if the app, technical infrastructure or legal requirements change. The version published on this page is the current version.