Privacy Policy

Last updated: 24 September 2026

In one sentence: keepasa is built so that nobody outside a conversation can read it, including us. Messages, photos, voice notes, files, names and avatars are encrypted on your phone before they leave it, and only the participants' phones hold the keys. No ads, no third-party analytics, and we never sell or share data.

1. Who is responsible

keepasa is a private, invitation-only messaging app. The data controller is the keepasa team. For any privacy question write to privacidad@keepasa.com.

2. What we can never see

All content is end-to-end encrypted with standard algorithms (AES-GCM, X25519 and Ed25519). The server stores and relays encrypted packets it cannot open:

Encryption keys are generated on your phone and never leave it unencrypted. If you lose your phone without having set up recovery, not even we can restore your history.

3. What the server does store

To make the app work, the server needs some technical data. This is all of it:

4. What we use that data for

Only to provide the service: deliver your messages, notify you about them, connect calls, maintain your circle and protect your account from unauthorised access. The legal basis is the performance of the service you request by using the app (Article 6(1)(b) GDPR). We do not build profiles, use third-party analytics, show ads, or sell, rent or share data with anyone.

5. How long we keep it

6. Where the data lives and who helps us

The keepasa server runs in a Hetzner Online GmbH data centre in Germany, within the European Union. For notifications we use Apple (APNs) and Google (Firebase Cloud Messaging), which only receive the device identifier and a generic alert. For calls we use our own media server; audio and video pass through it encrypted and are not stored. There are no other third parties.

7. Phone permissions

The app asks for each permission only when you need it, and you can revoke it in the system settings: camera and photo library (to send photos), microphone (voice notes and calls), location (only when you choose to share it), notifications, and Face ID, Touch ID or fingerprint (to lock the app; the check is done by your phone and never leaves it). We do not ask for access to your contacts.

8. Your rights

You can access, rectify, delete and export your data, and object to or restrict its processing. Most of this you do in the app itself: change your name or alias, see and remove devices, delete messages and delete the whole account. For anything else, write to privacidad@keepasa.com. If you feel we have not handled your request properly, you can complain to the Spanish Data Protection Agency (aepd.es) or your local supervisory authority.

9. Children

keepasa is not intended for children under 14. If you believe a child under that age has created an identity without permission, let us know and we will remove it.

10. Changes to this policy

If we change anything relevant, we will announce it in the app before it takes effect and update the date above. The current version is always at keepasa.com/privacy.html.

keepasa · private messaging by invitation · keepasa.com