Privacy Policy
Last updated: 24 September 2026
In one sentence: keepasa is built so that nobody outside a conversation can read it, including us. Messages, photos, voice notes, files, names and avatars are encrypted on your phone before they leave it, and only the participants' phones hold the keys. No ads, no third-party analytics, and we never sell or share data.
1. Who is responsible
keepasa is a private, invitation-only messaging app. The data controller is the keepasa team. For any privacy question write to privacidad@keepasa.com.
2. What we can never see
All content is end-to-end encrypted with standard algorithms (AES-GCM, X25519 and Ed25519). The server stores and relays encrypted packets it cannot open:
- Text messages, replies, reactions and private notes.
- Photos, albums, videos, files and voice notes, including their thumbnails.
- Your name, your avatar and the details on your introduction card.
- Room names and icons, meetups, polls, lists, shared locations and reminders.
- Call audio and video, which are also end-to-end encrypted.
- Your recovery keys, which are stored encrypted so that only you can open them.
Encryption keys are generated on your phone and never leave it unencrypted. If you lose your phone without having set up recovery, not even we can restore your history.
3. What the server does store
To make the app work, the server needs some technical data. This is all of it:
- Your identity: a random identifier, your public keys and your alias (the short name people in your circle find you by). We do not ask for a phone number, an e-mail address or access to your contacts.
- Your devices: the name you give them, when they last connected and a hash of the session (never the raw token), so you can see where you are signed in and kick a device out.
- Conversation structure: which identities take part in each chat or room, when each encrypted packet was sent and its size. This is the minimum needed to deliver messages to the right people.
- Invitations, introductions and blocks: who invited whom, pending introductions and whom you have blocked. A refusal is never communicated to the other person; it simply expires.
- Notifications: the identifier Apple or Google assigns to your phone so we can alert you. The notification does not contain the message content.
- Calls: who calls whom and when, so the other phone can ring. Nothing is ever recorded.
- Scheduled and disappearing messages: the encrypted packet with its send or expiry date.
4. What we use that data for
Only to provide the service: deliver your messages, notify you about them, connect calls, maintain your circle and protect your account from unauthorised access. The legal basis is the performance of the service you request by using the app (Article 6(1)(b) GDPR). We do not build profiles, use third-party analytics, show ads, or sell, rent or share data with anyone.
5. How long we keep it
- Encrypted packets are kept for as long as they exist in the conversation. If you delete a message for everyone, it is removed from the server and from the other phones without a trace. Disappearing messages are deleted automatically as soon as they expire.
- Invitations and introductions expire on their own (24 hours or 7 days depending on the type) and are then deleted.
- If you delete your account from the app, your identity, devices, direct chats, messages and files are removed immediately. Rooms you took part in continue to exist for the others, without your messages.
- We keep encrypted server backups for 14 days and then destroy them. Deleted data disappears from backups within that period at most.
6. Where the data lives and who helps us
The keepasa server runs in a Hetzner Online GmbH data centre in Germany, within the European Union. For notifications we use Apple (APNs) and Google (Firebase Cloud Messaging), which only receive the device identifier and a generic alert. For calls we use our own media server; audio and video pass through it encrypted and are not stored. There are no other third parties.
7. Phone permissions
The app asks for each permission only when you need it, and you can revoke it in the system settings: camera and photo library (to send photos), microphone (voice notes and calls), location (only when you choose to share it), notifications, and Face ID, Touch ID or fingerprint (to lock the app; the check is done by your phone and never leaves it). We do not ask for access to your contacts.
8. Your rights
You can access, rectify, delete and export your data, and object to or restrict its processing. Most of this you do in the app itself: change your name or alias, see and remove devices, delete messages and delete the whole account. For anything else, write to privacidad@keepasa.com. If you feel we have not handled your request properly, you can complain to the Spanish Data Protection Agency (aepd.es) or your local supervisory authority.
9. Children
keepasa is not intended for children under 14. If you believe a child under that age has created an identity without permission, let us know and we will remove it.
10. Changes to this policy
If we change anything relevant, we will announce it in the app before it takes effect and update the date above. The current version is always at keepasa.com/privacy.html.
keepasa · private messaging by invitation · keepasa.com