Privacy Notice
Last updated 2026-10-09
Who is responsible
Christopher Brückner, Schwalbenstraße 3, 85232 Feldgeding, Germany, is the controller responsible for MAVYR. This notice covers the MAVYR website and installed app.
The planned privacy contact is impressum@mavyr.org. The mailbox has not yet been confirmed as operational; privacy requests can currently be sent to the postal address above.
Your account
An invitation, username, password and second-factor setup are required to create an account. Without them, we cannot provide account access. You may choose an optional display name. We do not request your telephone number, legal name, postal address, date of birth or address book.
We store account identifiers, a password verifier, protected authentication records and the details needed to determine your plan. Your chosen username, display name and device names can be visible to the service and, where relevant, other participants. Choose them with that visibility in mind.
Your conversations
Message text is encrypted on your device before it is sent. The service delivers encrypted content; intended recipients decrypt it on their devices. Your Recovery Key is not sent to the service in plaintext.
To operate conversations, the server processes account and device identifiers, public encryption keys, room membership, room names, message timestamps, receipts and synchronization state. These metadata are not all end-to-end encrypted. Other participants may retain or share content they receive.
Website connections and security
A connection necessarily exposes your IP address and technical request information to the receiving infrastructure. MAVYR’s public application route does not maintain HTTP access logs. Short-lived messaging-session records and restricted administrative security records are processed separately.
We use account authentication, rate limits and operational monitoring to protect access and keep the service available. We do not use advertising trackers or third-party analytics to follow your use of the app.
Why we process data
Necessary account, authentication, delivery and plan administration supports the service you request, under Article 6(1)(b) GDPR. Handling a service-related support request is part of that purpose.
Limited website and administrative security processing is based on the interest in preventing unauthorized access and maintaining availability, under Article 6(1)(f) GDPR. Processing that is required by a binding legal obligation is based on Article 6(1)(c) GDPR and that obligation.
Communication content and traffic information are additionally protected by German telecommunications confidentiality rules. These restrict processing to permitted purposes, including necessary transmission and narrowly defined fault or misuse handling. A general legitimate interest does not override those restrictions.
Storage on your device
MAVYR stores an encrypted session vault, encrypted conversation history and cryptographic state on your device so the requested app can work. It also caches public application files for startup and offline access. Private API responses and decrypted messages are excluded from that public cache.
When you remember this device, a local browser key can reopen the encrypted session without storing your password. Access to the browser profile may therefore give access to the app. Server-side expiry or revocation still limits the session. This necessary storage provides the service you request; it does not prove that the operating system has authenticated you. Deleting site data may remove keys and history that the operator cannot reconstruct.
Optional notifications
Notifications are optional. When you enable them, your browser asks for permission and creates a subscription through its platform push service: Apple, Google or Mozilla. We store the encrypted endpoint and delivery keys to send generic alerts to your device. These providers also process routing and connection information; their privacy notices are linked below.
This optional delivery is based on your consent under Article 6(1)(a) GDPR. You can withdraw it by switching notifications off in MAVYR and can revoke the operating-system permission separately. Withdrawal applies to future processing. Enabling a browser permission alone does not sign you into an account or authorize access to messages.
We send no message text, sender name or conversation name in a push notification. Your device displays “New MAVYR message”, including on its lock screen if your system settings allow that. Delivery depends on the platform, connectivity and permission settings.
Subscription cancellation
When the public cancellation form is enabled, we use the identity, contract reference, receipt email, cancellation type, reason where applicable and requested end you submit to identify the contract, handle your declaration and provide its receipt. This supports contract administration and applicable legal obligations. You do not have to sign in or disclose a password or Recovery Key.
The declaration is encrypted in the server database and can be read by the operator handling it. The receipt is ordinary email containing your declaration, not end-to-end encrypted MAVYR chat. The configured email service and your mailbox provider process that delivery. Email-provider details and the resolved-case retention period must be supplied before submission is activated; neither is currently configured.
The Data Inventory describes delivery and duplicate-prevention records. The Retention Matrix explains why unresolved requests and pending receipts are kept separately from message expiry and account deletion.
Who receives data
Conversation participants receive your messages and the profile or conversation information shared with them. The operator and authorized technical administrators can access operational data needed to run and protect the service, subject to the limits of message encryption. Authorities receive data only where a verified legal basis permits or requires disclosure.
The application is operated on infrastructure administered for MAVYR. The physical hosting location, external service-provider roles and any international-transfer arrangements have not yet been confirmed for this notice. We therefore make no claim that every processing activity takes place only in Germany or the EEA.
How long data is kept
Encrypted server message history has a 24-hour availability window, with hourly expiry cleanup. Room state and the final retained event in a room are exceptions. Account records, device registrations and encrypted key backups have separate lifecycles. Encrypted local history can remain on your device after server expiry.
Database snapshots expire after 24 hours at the hourly cleanup and can temporarily retain records already removed from the live database. A valid legal preservation obligation may extend retention for covered data. The Retention Matrix gives the full category-by-category explanation.
Your choices and rights
Under the applicable conditions, you can request access to your personal data, correction, erasure, restriction of processing and portability. You can object to processing based on legitimate interests for reasons relating to your situation. Where processing relies on consent, you may withdraw it for the future.
Send a request to the controller using the contact details above. We may need proportionate information to verify that a request concerns your account. Do not send passwords, authenticator secrets or Recovery Keys. A privacy request does not require giving the operator access to your encrypted conversations.
Deleting the app does not close your account. Account erasure is currently requested from the operator. We will explain any records that must remain because of another person’s rights, a technical limitation requiring separate handling or an applicable legal obligation; a technical limitation does not remove your statutory rights.
Complaints
You may complain to a data protection supervisory authority, including one in the EU country where you live or work, or where the alleged infringement occurred. For German telecommunications privacy, the federal authority BfDI is the relevant contact. For other private-sector processing by a controller in Bavaria, the Bavarian State Office for Data Protection Supervision can be relevant. Their official contact pages are linked below.
Changes to this notice
We update this notice when the service or its processing changes. The date identifies the current version. The app does not use advertising profiles or make decisions of the kind described in Article 22 GDPR solely through automated profiling.
Sources
- General Data Protection Regulation
- Confidentiality of communications — § 3 TDDDG
- Communication traffic data — § 9 TDDDG
- Faults and misuse — § 12 TDDDG
- Storage on your device — § 25 TDDDG
- Telecommunications data protection supervision — § 29 TDDDG
- BfDI: data protection complaints
- Bavarian State Office for Data Protection Supervision: contact and complaints
- Apple Privacy Policy
- Google Privacy Policy
- Firefox Privacy Notice