Privacy Policy

Information under Articles 13 and 14 of the General Data Protection Regulation · version of 20 August 2026

This is a translation. The service is operated from Germany and the German version is the authoritative one. Where the two differ, the German text applies.

1. Controller

Lutz Maier, Vogelweide 22, 22081 Hamburg, Germany
Email: datenschutz@safetyimg.app

No data protection officer has been appointed. Under § 38 Bundesdatenschutzgesetz (the German Federal Data Protection Act) this only becomes a duty once at least 20 people are constantly engaged in automated processing.

2. First things first: what we cannot see — and what we can

Photos and videos are encrypted on the sender's device and leave it in encrypted form only. What sits on our servers is ciphertext and nothing else. The keys are on the devices of the people involved. We cannot decrypt the content. Folder names are encrypted too.

It would be dishonest to leave it at that. For the service to work, traffic and relationship data arise which we very much do see, and which on their own can say a great deal about a person:

We need this data to operate the service, to check access rights and to detect misuse. We do not sell it, do not evaluate it for advertising, and pass it on only where we are legally obliged to.

Test operation: an exception to exactly that promise. An installation can be switched into a test mode. While it is active, the media of all accounts on that installation are collected by a backup service and stored there unencrypted. The end-to-end encryption described above then does not protect the content from the operator.

The app does not hide this: in test mode it changes colour and shows a fixed banner on every screen stating that all media are stored unencrypted on the backup server. Without that banner, test mode is not active. The legal basis is Article 6(1)(a) GDPR (consent through deliberate participation in the test) [[ to be confirmed by a lawyer ]].

3. The processing in detail

3.1 Account

Datausername, display name, email address, password (only as an Argon2id hash), public identity key, language, storage quota and usage, account status, time of registration and of email confirmation
Purposeproviding the service, signing in, attributing shares
Legal basisArticle 6(1)(b) GDPR (performance of a contract)
Perioduntil the account is deleted

A real name is not required. We need the email address to confirm the registration and to be able to restore access.

3.2 Encrypted content and its metadata

Dataencrypted media and thumbnails, encrypted folder names, media type, file size, image dimensions, video duration, time of upload, key generation
Purposestorage and delivery to the recipients the user chooses
Legal basisArticle 6(1)(b) GDPR
Perioduntil the user deletes the medium or their account

Location and camera data (EXIF in a photo, the corresponding fields in a video file) are removed by the app before encryption. They reach neither us nor the recipient.

3.3 Connections and shares

Datawho is connected to whom and in what state; who shared which folder with whom, with the kind of expiry, the time of expiry and the time of first opening; encrypted key envelopes
Purposeenforcing access rights on every single retrieval; without this data, withdrawing a share would have no effect
Legal basisArticle 6(1)(b) GDPR
Perioduntil the share or the account is deleted

3.4 Reports of capture attempts

Dataidentifier of the medium, identifier of the viewer, time, platform
Purposeinforming the sender that a screenshot was attempted
Legal basisArticle 6(1)(b) GDPR — the notification is a promised feature of the service
Perioduntil the medium or the account is deleted

The sender learns that a capture attempt was detected, not what came of it. A screenshot itself never reaches us.

3.5 Sessions and devices

Datasession identifier (as a hash only), device label as reported by the device, times of expiry and revocation
Purposestaying signed in across days, signing out all devices when the password changes
Legal basisArticle 6(1)(b) GDPR
Period30 days from the last sign-in

3.6 Access log

Datauser identifier, media identifier, time, salted hash of the IP address, browser or app identifier
Purposedetecting and investigating misuse, such as the bulk retrieval of other people's media
Legal basisArticle 6(1)(f) GDPR (legitimate interest)
Period90 days, then automatic deletion

Balancing. Our interest is in defending against misuse of a service which, precisely because of its encryption, can be vulnerable to misuse. We do not store the IP address in the clear but only as a salted hash: that makes it possible to tell that several accesses came from the same source without being able to read the address itself. The retention period is limited to 90 days. An objection under Article 21 GDPR is possible (see clause 8).

3.7 Rate limiting

To protect against password and username guessing, we count requests per IP address and per account in a sliding window. These counters are held in memory only and expire at the end of the respective window (at most one hour). Legal basis: Article 6(1)(f) GDPR.

3.8 Sending email

Datarecipient address, subject, content (confirmation, reset and recovery links)
Purposeconfirming the address, resetting the password, access to recovery, notice of account deletion
Legal basisArticle 6(1)(b) GDPR
Periodthe queue is emptied once sending succeeds; [[ check retention at the mail provider ]]

3.9 Push notifications

Datathe device's push token, device label
Purposea hint that something has happened (new share, new contact request)
Legal basisArticle 6(1)(b) GDPR; can be switched off in the settings
Perioduntil the device is signed out or the account is deleted

The content of a push message is empty. All we transmit to Google is a type code such as “share_created” — no name, no username, no preview, no folder name. The text of the notification is composed by the app on the device from its own resources.

The recipient is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, where applicable with the involvement of Google LLC in the United States. The transfer is based on the European Commission's adequacy decision on the EU-US Data Privacy Framework of 10 July 2023 [[ check before publication: current status of the decision ]]. Anyone who does not want push notifications switches them off in the settings; no token is then transmitted.

3.10 Reports about content

Dataidentifier and account of the reporting user, identifier of the medium, identifier of the owner, the reasons given, and a decrypted copy of the reported medium
Purposeexamining the report, meeting our duties under Article 16 of Regulation (EU) 2022/2065
Legal basisArticle 6(1)(c) GDPR (legal obligation) and (f) (legitimate interest in a service free of misuse); for content within Article 9 GDPR additionally Article 9(2)(f) and (g) GDPR [[ to be confirmed by a lawyer ]]
Perioduntil the case is closed, then 90 days, after which the decrypted copy is deleted automatically; the case itself (who reported what, when, and how it was decided) is kept as a record. Where a criminal complaint is made, until the proceedings end

This is the only way content ever becomes visible to us, and it requires a deliberate act by a user who is allowed to view the medium anyway. Without a report, every piece of content remains unreadable to us. Anyone reporting should know that they are sending us an unencrypted copy; the app says so in the reporting dialogue.

3.11 Moderation log

Every measure (medium deleted, account suspended, report dismissed) is logged with the person acting, the time and the nature of the measure. The purpose is that our decisions can be traced; the legal bases are Article 6(1)(c) and (f) GDPR. Retention: 3 years.

3.12 Moderation interface

The password-protected web interface for moderation sets a single cookie holding the session identifier. It is strictly necessary for operation within the meaning of § 25(2) no. 2 Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (the German Telecommunications Digital Services Data Protection Act) and therefore requires no consent. It expires after one hour. We set no other cookies; the app itself uses none.

3.13 Feedback and contact requests

The app carries a form for bug reports and suggestions (Settings → “Send feedback”). The same form exists on the start page without an account, for the cases where the app cannot be used at all — a failed installation, a confirmation mail that never arrived. That same form is also the contact route named in the imprint (§ 5 DDG); a contact request needs an address, because we promise an answer there.

This text is not encrypted. Unlike photos and videos, we can read a piece of feedback — that is what it is for. The app says so directly above the input field.
Datacategory, the text written, and — only with the user's agreement — device model, Android version, app version and language setting. From the app additionally the account identifier; from the web form no identifier
Email addressFrom the app no address is stored; whoever asks for an answer is reached at the address of their account. In the web form an address may be given voluntarily, solely so that we can answer; for a contact request it is required, otherwise there is nobody to answer
Purposefinding faults and improving the service; through the web form also answering contact requests
Legal basisArticle 6(1)(f) GDPR (legitimate interest in a working service); for the address given voluntarily in the web form, Article 6(1)(a) GDPR (consent); for a contact request, Article 6(1)(f) GDPR (answering the enquiry, § 5 DDG) [[ to be confirmed by a lawyer ]]
Period180 days after it is handled, then automatic deletion

The form on the start page is protected against automated submissions without transferring anything to a third party: an arithmetic question, a hidden field, and a limit on how often one connection may submit. A service such as reCAPTCHA or Turnstile is deliberately not used, because it would send every visitor past a third party. The connection identifier is held only as a salted hash in memory and is not stored.

4. What we do not do

5. Recipients

RecipientPurposeBasis
[[ hosting provider, address ]] running the servers and storing the data processing on our behalf under Article 28 GDPR
Google Ireland Limited delivery of push notifications Article 28 GDPR, third-country transfer as in clause 3.9
law enforcement and supervisory authorities only on a legally effective order in the individual case Article 6(1)(c) GDPR

[[ Before launch: conclude data processing agreements with all the providers named and set up a record of processing activities under Article 30 GDPR. ]]

What we can hand over to authorities is limited by the encryption: we cannot supply content even on order, because we cannot decrypt it. We can hand over account data and the traffic data named in clause 2.

6. Retention periods at a glance

DataPeriod
Account and contentuntil deleted by the user
Suspended account30 days, then automatic deletion
Username after account deletionblocked for 12 months, then free again
Access log90 days
Sessions30 days from the last sign-in
Incomplete uploads24 hours
Confirmation and recovery links24 hours and 1 hour respectively
Decrypted copy from a report90 days after the case is closed, then automatic deletion
Feedback (app and web form)180 days after it is handled, then automatic deletion

7. Why deletion does not achieve everything

When a user deletes their account, we remove all the data named above. What we cannot undo is a medium a recipient has already seen and photographed with a second device. That limit applies to every service of this kind, and we would rather name it than create an impression we cannot live up to.

8. Rights of the data subject

Every user has the right

Please address requests to datenschutz@safetyimg.app.

On access and portability: we can hand over in full the account data and metadata stored about a person. The media themselves we can only hand over as ciphertext — the key to it belongs to the user alone. Anyone who needs the content in the clear can save their own recordings to their device from within the app.

9. Right to lodge a complaint

Every data subject may lodge a complaint with a data protection supervisory authority, in particular the authority where they habitually reside or the one responsible for us: [[ competent supervisory authority for the provider's seat, with address ]].

10. Obligation to provide data

The details given on registration are necessary to conclude the contract. Without them we cannot create an account. There is no statutory obligation to provide them.

11. Minors

The service is aimed exclusively at persons aged 18 and over. We do not knowingly process data of children or adolescents.

12. Changes to this policy

We adapt this policy when the processing changes. The version in force at any time is available at this address; the date at the head of the page identifies the version.