Privacy Policy
Last updated: 14.09.2026
English translation provided for convenience. In case of any discrepancy, the German version prevails (switch to “DE” above to read it).
1. Controller
The controller responsible for data processing within the meaning of the General Data Protection Regulation (GDPR) is:
West German Encrypted Hosting – Inhaber Alessandro Lindner
c/o Smarvo 251, Südstraße 31, 47475 Kamp-Lintfort
Email: aphotice2ee@proton.me
2. Overview and data minimisation
Aphotic consists of this website with its store, a licensing service and the messenger’s chat server (relay). We operate all of our servers in data centres in the European Union. You need no user account to buy with Monero or Bitcoin, and we do not ask for a name, email address, postal address or phone number. The app does not read your address book. We use no analytics, tracking or advertising services.
The app encrypts message content end to end on your device; we cannot read it. The following sections describe which data is nevertheless created, where it is held and when it is deleted.
3. Website
3.1 Access routes and IP addresses
- Over Tor (.onion): by virtue of the Tor protocol, your IP address does not become known to us.
- Over the public internet (https): when you retrieve pages or the app file, our web server processes your IP address, because no connection can be established without it. The processing lasts only as long as the connection. The web server writes neither an access log nor an error log of individual requests and does not store the IP address. Its other operational messages rotate across three files of 10 MB each.
The web server forwards requests to the store, the contact form and the operator portal to our licensing service over Tor. Before doing so it removes every header that can carry your IP address (X-Forwarded-For, X-Forwarded-Host, X-Forwarded-Proto, X-Real-IP, Forwarded, True-Client-IP), the browser identifier (User-Agent), the language setting (Accept-Language) and the previously visited page (Referer). The licensing service receives only the request itself: path, body and host name. The website loads no content from third-party servers.
3.2 No cookies; browser storage
The website sets no cookies. It places only the following entries in your browser’s storage.
In local storage (localStorage), until you clear it in your browser:
aphotic_lang: your language choice, only when you switch the language explicitly;aphotic_notice_dismissed: that you closed the privacy notice;aphotic_tor_notice_dismissed: that you closed the Tor notice.
In session storage (sessionStorage), which is cleared when you close the tab:
order_<order ID>: the access code of your order;order_meta_<order ID>: plan name, amount in EUR and payment method;bulk_orders: the order IDs of a bulk order;operator_key: your operator license key, in the operator portal only.
These entries are strictly necessary to provide the service you requested (§ 25 (2) no. 2 TDDDG).
3.3 Order ID in the address bar
During checkout the order ID appears in the address of the checkout page, so it can remain in your browser history. A recovery link also contains the access code. Anyone who has that link can retrieve your license key for as long as the access code is stored (section 10). You manage your browser history yourself.
3.4 Contact form
If you send us a message through the contact form (/contact, over either access route), we store your message (at most 4,000 characters) and, if you enter one, a reply address in the licensing service’s database. We do not store your IP address or the time. We read the message in our admin area and delete it once your request has been dealt with. There is no automatic deletion period.
3.5 Contact by email
If you write to aphotice2ee@proton.me, our email provider Proton AG (Switzerland) processes your message together with your sender address.
3.6 Operator portal
Relay operators sign in to the operator portal (/operator) with their operator license key. For each relay we store the onion address, the display name, the visibility (listed publicly or findable by search only), whether the relay accepts messages from other relays, the associated operator license, and the time it was created and last changed. We publish the onion address and display name in the signed relay directory.
4. Store and license management
The following data is held in our licensing service’s database.
- Orders: order ID, selected plan, payment method, amount in EUR, amount in cryptocurrency and the exchange rate used, the payment address generated for the order, the wallet software’s internal payment identifier, the transaction ID (txid) of the payment, the amount received, the number of blockchain confirmations, the status, the times the order was created, expired, paid and delivered, the access code, and a reference to the license created.
- Payment events: created, payment seen in the mempool, partial payment (amount received and amount expected), failed (with reason), license generated, expired; each with a timestamp.
- Licenses: the license key (stored in readable form so you can retrieve it again, and additionally as a hash), term, the times it was created, activated and expires, number of devices, license type (user or relay operator) and, where applicable, a reference to the license it was merged into.
- Device activations: on activation the app sends a device identifier (“device_id”). The app generates it from 16 random bytes; it has no relation to your device’s hardware. We store the device_id with the time of activation and, when licenses are merged, the device_id with the time. The identifier is used to enforce the agreed number of devices per license. The same app installation always uses the same device_id, so licenses activated from the same installation can be linked to one another within the licensing database.
- Token issuance: how many anonymous tokens a license received per hour.
- Change log: changes we make to a license in the admin area, with old and new values; for a removed device, the first 8 characters of its device_id. At most 200 entries per license.
- Wallet label: the wallet software labels each receiving address
order_<order ID>. - Invoices: we generate them from the order each time they are retrieved (seller, order ID, plan, amounts, exchange rate, payment method, receiving address, txid, confirmations, dates). They contain no information about your person.
- Logs: the licensing service’s logs contain no IP addresses, license keys or device identifiers, but they do contain order and license IDs with timestamps (such as “license delivered”, “activated”, “tokens issued”).
With the order ID and access code you can retrieve your license key, license status and invoice through the website until the access code is deleted (section 10).
The chat server receives neither license keys nor device identifiers. There the app proves its entitlement with blind-signed tokens; the licensing service cannot tell which token it signed. Whoever operates both services could, however, compare the times at which tokens are issued and redeemed.
5. Messenger
5.1 User ID and identity
The app generates your keys on your device. Your user ID is derived from your public keys (a UUID computed from a SHA-256 hash) and is therefore the same on every relay. It is pseudonymous and linked to no person, phone number or email address. The server stores for your identity:
- user ID, public identity key, public signing key, public sealed sender key with its signature, and the ratchet version in use;
- a SHA-256 hash of your access token;
- your public prekeys, including ones no longer in use.
The server stores no time of registration or of last activity; the database has no column for either.
5.2 Messages and attachments
- Direct messages wait in encrypted form in a queue until the recipient’s device collects them, for at most 7 days. An hourly sweep removes expired messages.
- For each user the server counts expired messages that were never collected and keeps that count for 30 days, so the app can show how many messages expired.
- Attachments are stored as encrypted files with metadata: the uploader’s user ID and the recipients or the community. The server deletes both after 7 days (hourly sweep).
The server cannot read content in any case.
5.3 Sealed sender and its limits
The app sends direct text messages with sealed sender: the envelope names no sender. The server does see the sender’s user ID
- for messages in groups and communities;
- on the fallback path the app uses when no sealed sender key is available for the recipient;
- when attachments are uploaded (uploader’s user ID and recipients, stored for 7 days).
In addition, the server can infer from the timing of sending and delivery that two users are in contact with each other.
5.4 Groups and communities
For groups and communities the server stores:
- group ID, the founder’s user ID, encrypted name and encrypted description, permissions, invite token with expiry and usage limit;
- the members’ user IDs with role, status and capabilities, and the address of each member’s home relay;
- MLS handshake material (KeyPackages, Welcome messages, tree snapshots) until it is used or superseded.
Community messages are held in a shared stream and deleted after 7 days. The founder of a community can switch on saved history: an encrypted archive of up to the newest 100,000 records, kept until the founder switches it off or the community is deleted.
For each community the server keeps a handshake log: every encrypted MLS commit message with the time the server received it. These messages contain user IDs and public keys of members. The log is kept for as long as the community exists.
5.5 Short-lived technical data
The server holds the following in memory only, never written to disk:
- a session cache, 15 minutes;
- proof of your license entitlement, until the end of the current hour;
- rate-limit counters, at most 1 hour;
- during a device transfer through the server, your encrypted vault, 10 minutes.
IP addresses do not exist on the chat server, because it can only be reached over Tor. It keeps no log of individual requests. Some log lines contain internal identifiers (message, upload or group ID).
5.6 Delete account
Under “Settings” → “Delete account” in the app, the server immediately deletes your identity, your prekeys, all your memberships of groups and communities, the waiting messages addressed to you, the count of expired messages and the proof of your license entitlement. The app also tries to delete your guest identities on other relays (section 5.7) and shows you any relay it cannot reach.
Groups and communities you founded are dissolved in the process, including their saved history and handshake log. Their members lose these groups.
The following remain until their respective period expires:
- messages you have already sent that are still waiting in other users’ queues (at most 7 days);
- attachments and their metadata (at most 7 days);
- your records in community streams (at most 7 days);
- your records in the saved history and handshake logs of communities founded by someone else (until the history is switched off or the community is deleted);
- rate-limit counters (at most 1 hour).
Order and license data in the licensing service (section 4) is not affected.
5.7 Relays run by other operators
In the app you choose a home relay: our central relay or one run by another operator. If your home relay is run by another operator, the data listed in sections 5.1 to 5.5 is held by that operator. The app delivers messages and attachments for a contact with a different home relay to that contact’s relay. If you join a group or community hosted on another relay, the app registers a guest identity there with the same user ID, your public keys, a token hash and a few prekeys.
The operator of such a relay processes this data as an independent controller. Conversely, our central relay stores guest identities of users of other relays. Relays run by other operators retrieve no personal data from us. The app loads the message of the day, app updates and the relay directory from our central server over Tor without identifying you.
5.8 Data on your device
Contacts, message history and private keys are held in an encrypted vault on your device. They leave the device only if you export an encrypted backup file, transfer your data directly to another device, or use the “chats only” transfer through the server. In that case the server relays your encrypted vault and holds it for at most 10 minutes.
6. Payment processing
You pay in Monero or Bitcoin to an address generated for your order. We check Bitcoin payments on our own full node and Monero payments with our own wallet. No payment service provider is involved. Bitcoin transactions are permanently visible on the public blockchain; anyone who knows the payment address or txid can trace the transaction there.
To convert prices, our server fetches exchange rates from CoinGecko, Kraken and CoinPaprika over Tor. It sends only the names of the cryptocurrencies and no personal data.
7. App
The app contains no analytics and no crash reporting, uses no push notifications (it raises notifications on the device), and reads neither an advertising ID nor your address book.
The app recognises QR codes on the device with the Google ML Kit library and a recognition model bundled with the app; no model is downloaded. From app version 1.0.1790 the app no longer includes ML Kit’s own upload path (Google “datatransport”) and itself sends nothing to Google; older versions could send scanner usage data to Google directly through it.
If Google Play services is installed on your device, ML Kit passes anonymous usage statistics about each scan to Google Play services via the Android system: which function ran, how long it took, and timestamps, but not the content of the scanned code. Google Play services may transmit this data to Google over its own connection, outside Tor. The EU contact for Google Play services is Google Ireland Limited. On devices without Google Play services this does not happen. You avoid this transfer by typing license keys and contact codes instead of scanning them.
8. Recipients and processors
- Data-centre operator in the EU: the chat server and licensing service, the payment node and the web server are virtual servers that we operate in data centres of a hosting provider in the European Union. The provider is our processor under Art. 28 GDPR.
- Proton AG, Switzerland: our email provider (section 3.5). Switzerland is covered by an adequacy decision of the European Commission (Art. 45 GDPR).
- 1984 Hosting, Iceland (EEA): operates the name servers for the domain aphotic.me.
- Let’s Encrypt: issues the website’s TLS certificates. We hold the account for this without an email address; Let’s Encrypt receives no visitor data.
- Google (via Google Play services on your device): usage statistics from the QR scanner, where Google Play services is installed (section 7). The EU contact is Google Ireland Limited.
- Exchange-rate sources (CoinGecko, Kraken, CoinPaprika) receive no personal data (section 6).
- Blockchains: Bitcoin transactions are public (section 6).
- Operators of other relays process the data your app sends to their relay as independent controllers (section 5.7). Where such a relay is located is decided by its operator.
We use no analytics or advertising service providers. The only transfer of personal data we make to a country outside the EEA is to Proton AG in Switzerland. Where Google transfers the data from Google Play services is decided by Google.
9. Legal bases
- Art. 6 (1) (b) GDPR (contract): order, payment, license, device activations, retrieval with the access code, invoice and wallet label; the operator portal and relay directory; the messenger with identity, messages, attachments, groups, communities, saved history, handshake log, guest identities, device transfer and the short-lived data in section 5.5; contact requests concerning a contract or its conclusion.
- Art. 6 (1) (c) GDPR (legal obligation): retention of orders that received a payment under § 147 AO and § 14b UStG.
- Art. 6 (1) (f) GDPR (legitimate interest): transient processing of the IP address and the web server’s operational messages (secure and functioning operation); contact form and email (answering your request); token-issuance counts and rate limiting (protection against abuse); change log and the logs of the licensing service and chat server (traceability and operational security); QR-scanner usage statistics passed to Google Play services (needed for the scanner in the app); retention of licenses after expiry until the limitation period ends (establishment, exercise or defence of legal claims).
- § 25 (2) no. 2 TDDDG: entries in your browser’s storage (section 3.2).
10. Storage period
Website
- IP address when accessed over the public internet: not stored, processed only for the duration of the connection.
- Web server operational messages: rotate across three files of 10 MB each.
- localStorage entries: until you clear them in your browser. sessionStorage entries: until you close the tab.
- Contact form: until your request has been dealt with; there is no automatic deletion period.
- Emails: until your request has been dealt with.
- Relay entries in the operator portal: until the operator or we delete the entry.
Store and license management
- Access code and payment events: deleted 90 days after the order was created, once it has been delivered, has expired or has failed. After that, retrieval through the website is no longer possible.
- Orders that received no payment (expired or failed, no amount received, no txid, no license): deleted entirely 90 days after creation.
- Orders that received a payment: they keep the payment address, payment identifier and txid as tax records and are deleted once 10 full calendar years have passed since the end of the year of payment (§ 147 (4) AO).
- Licenses: deleted once 3 full calendar years have passed since the end of the year in which they expired (§§ 195, 199 BGB). Device activations, merge records, token-issuance counts and the change log are deleted with them, and a retained order loses its reference to the license. Licenses that were never activated have no expiry date yet and remain stored.
- Token-issuance counts: 7 days.
- Change log: at most 200 entries per license, deleted with the license.
- Invoices: not stored separately; generated from the order each time they are retrieved.
- Licensing service logs: rotate at 50 MB and are deleted when the container is recreated.
Messenger
- Identity, public keys and prekeys: until you delete your account.
- Direct messages: until collected, at most 7 days. Count of expired messages: 30 days.
- Attachments and their metadata: 7 days.
- Memberships: until you leave, are removed, the group is dissolved or you delete your account. MLS handshake material: until it is used or superseded.
- Community streams: 7 days.
- Saved history of a community: at most the newest 100,000 records, until the founder switches it off or the community is deleted.
- Handshake log: for as long as the community exists.
- Session cache 15 minutes; proof of license entitlement until the end of the current hour; rate limiting at most 1 hour; vault during a device transfer through the server 10 minutes.
- Chat server logs: rotate at 50 MB and are deleted when the container is recreated.
App
- QR-scanner usage statistics (section 7): we neither receive nor store them; how long Google stores them is decided by Google.
11. Obligation to provide data
You are under no statutory obligation to provide us with personal data. We need the order data to complete the purchase; without it we cannot deliver a license. Your public keys and the user ID derived from them are technically required to use the messenger. The reply address in the contact form is optional; without it we cannot answer you.
12. No automated decision-making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.
13. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21, see below).
Because we keep no accounts, we can only attribute data to you if you give us details that let us find it and check that you are entitled to it, such as the order ID and access code. Messenger data is linked only to your user ID; you can delete it yourself in the app (section 5.6).
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the member state of your habitual residence, your place of work or the place of the alleged infringement. The authority competent for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2–4, 40213 Düsseldorf, Germany
14. Right to object (Art. 21 GDPR)
Where we process data on the basis of Art. 6 (1) (f) GDPR (section 9), you have the right to object to that processing at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
You can send your objection informally to aphotice2ee@proton.me.