Privacy Policy
Information on the processing of personal data under Articles 13 and 14 GDPR
Diese Seite auf Deutsch: Datenschutzerklärung
At a glance
- Our website sets no cookies, uses no analytics or tracking tools and loads no content from third parties. The service sets a single, strictly necessary cookie, and only when the Linux version of the desktop app hands a call over to your browser (section 3.7).
- AmadeusShare runs on a server that we rent from Hetzner Online GmbH. Files are stored in Hetzner Object Storage at the same location: [Serverstandort / Server location: Deutschland (Falkenstein/Nürnberg) oder Finnland (Helsinki)].
- Files in normal spaces are encrypted on our server. Because the server holds the keys, we could technically decrypt them. Only in optional private spaces are files end-to-end encrypted on your device, so that we cannot read their contents.
- Meetings run through our own media server. They are not recorded and not end-to-end encrypted.
- The desktop app loads no content from third parties; its fonts ship with the app.
- In a team workspace, the files in normal spaces belong to the workspace: if you delete your account or are removed, they pass to the owner of the workspace. Private spaces that only you can read are deleted with your account (section 6.2).
1. Controller and contact
The controller responsible for processing personal data in connection with AmadeusShare is:
[Firmenname / Company name] [Rechtsform]
[Anschrift / Address]
Represented by: [Vertretungsberechtigte / Managing director]
Email: [Kontakt-E-Mail / Contact email]
For all questions about data protection, please contact: [Datenschutzkontakt / Privacy contact]
Further company details are available in our imprint.
2. Scope and our role
This privacy policy covers:
- our website at [Domain], including the contact form;
- the AmadeusShare service, meaning our server with its programming interface and the pages opened in a browser for invitations, email confirmation and meetings;
- the AmadeusShare desktop app for macOS, Windows and Linux.
We are the controller for the data we process to operate the website and to provide the service to you, for example your account, security and communication with you.
When a company or another organisation uses a workspace for its team and stores personal data of other people in it (for example documents containing personal data), we process that content on behalf of the organisation as a processor under Article 28 GDPR. For that content, the organisation is the controller; please direct questions about it to the organisation. We will support it in answering such requests. Business customers can conclude a data processing agreement with us: [Auftragsverarbeitungsvertrag / Data processing agreement].
3. What we process, why, and for how long
3.1 Visiting our website
Our website is delivered by our own application server. It sets no cookies, uses no analytics or tracking tools and loads all scripts, stylesheets and images from our own server. No data is passed to third parties when you visit it.
Data processed: When you open a page, your browser transmits technical data. Our reverse proxy and our application server record it in log files: IP address, date and time, request method, host name, status code, amount of data transferred and response time; the application server also records the requested path, without query parameters and with any token in a link removed.
Purpose: to deliver the website and to keep it secure and stable, in particular to detect and investigate attacks and errors.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in operating a secure and functioning website.
Retention: Log entries are deleted automatically after 14 days.
Language setting: To choose a display language, the website reads your browser's language preference locally in your browser. Only if you actively select a language is your choice saved in your browser's local storage (entry "lang"), so that the website remembers it. This entry is not transmitted to us. Storing it is strictly necessary to provide the function you requested (Section 25(2) No. 2 of the German Telecommunications Digital Services Data Protection Act, TDDDG). You can delete it at any time in your browser settings.
3.2 Contact form
Data processed: your name, email address, the topic you select and your message; if you came from a pricing card, also the name of the plan. In addition, your IP address. A hidden field protects against spam and must remain empty.
How it works: We do not store your message in our database. Our server sends it, together with your IP address, as an email to our inbox via our email delivery service. Our server log records that a message was delivered, with the topic and your IP address. To prevent abuse, the number of messages per IP address and the total number of messages per day are limited; for this purpose your IP address is kept briefly in the server's memory.
Purpose: to answer your request and to prevent misuse of the form.
Legal basis: Article 6(1)(b) GDPR if your request relates to a contract with us or to steps prior to entering into one; otherwise Article 6(1)(f) GDPR, based on our legitimate interest in answering enquiries. Processing of your IP address: Article 6(1)(f) GDPR, based on our legitimate interest in preventing abuse.
Retention: We keep the email for as long as we need it to deal with your request and delete it [Aufbewahrungsfrist Kontaktanfragen / Contact request retention period] after the matter is closed, unless statutory retention obligations apply (for example up to six years for commercial correspondence under Section 257 of the German Commercial Code, HGB). For log entries, see section 3.1.
Recipients: our email delivery service [E-Mail-Versanddienstleister / Email relay provider] and the provider of our mailbox [E-Mail-Postfach-Anbieter / Mailbox provider].
Name, email address and message are required; without them we cannot answer you.
3.3 Registration, user account and sign-in
Registration: To register, you provide your email address, a username and a password. You can choose a display name when you register in the app; otherwise we derive one from your email address. We store your password only as a bcrypt hash, never in plain text. If you register yourself, we create your own workspace on the Free plan with you as its owner, and set up a personal meeting room for you.
Joining by invitation: If you join an existing workspace through an invitation, you choose a username and a password; your email address is taken from the invitation.
Acceptance of the terms: Registering and joining by invitation both require you to accept the terms of service and to confirm that you have read this privacy policy. We store the time of your acceptance with your account as a record of the agreement.
Optional profile data: If you provide them, we also store your first name, last name and a link to a profile picture.
Language of emails: The desktop app tells our server its display language (English, German, French, Italian or Spanish) when you sign in and whenever you change it. We store it with your account and write the emails we send you in that language; until the app has told us, they are in English. Emails that you cause to be sent to others, such as invitations, are written in your language as well.
Email confirmation: After you register yourself, we send you a confirmation link that is valid for 48 hours. We store only a hash of the link, not the link itself. Until you confirm your address, users of other workspaces cannot share files with you by email. You can use your account before confirming it. If you do not confirm your address within 30 days, your account and its workspace, including its files, are deleted automatically; a week before, we send you a reminder with a new confirmation link.
Sign-in and sessions: When you sign in, we check your email address and password and record the time of your last sign-in. You receive an access token that is valid for about 60 minutes and contains your user ID, workspace ID, role and email address, and a refresh token that is valid for seven days. The server stores the refresh token only as a hash. Signing out ends the session on the server. Expired session records are deleted automatically. If your account is suspended or removed (sections 6.3 and 6.4), or your workspace is deleted, all your sessions end at once. So that an app that was closed at that moment can tell you why it was signed out, we then keep for each ended session the hash of its refresh token, your user ID and the reason ("suspended", "removed" or "workspace deleted") until the refresh token would have expired, that is for at most about seven days, also after the workspace was deleted; if the account is reactivated, these records are deleted at once.
Password and email address: You can change your password in the app, or reset it with a link we send to your email address (valid for one hour; we store only a hash of it). Changing or resetting the password signs you out on all devices, and we notify you by email. To change your email address, you enter the new address and your password in the app; the change takes effect only when you open the confirmation link we send to the new address (valid for 24 hours), and we inform your previous address.
Confirming important actions: Removing a member, deleting your account or the workspace, transferring the ownership and changing your password or email address take your current password, which our server checks as at sign-in, and, if you use two-step verification, a code.
Two-step verification (optional): If you turn on two-step verification in the app's settings, we create a random secret, which you add to an authenticator app of your choice on your device (we receive nothing from that app), and ten recovery codes, which we show you once. We store the secret encrypted, with a key derived from our server's master key and bound to your account, and the recovery codes only as hashes, each with the time it was used; we also store the time step of the last code used, so that no code works twice. From then on, signing in and the important actions above take a code from the app, or one of the recovery codes, in addition to your password. After you enter the correct password, we keep the sign-in waiting for the code for at most five minutes: we store only a hash of a random token, your user ID, the number of attempts and the time, and delete expired records automatically. When you turn two-step verification on or off, create new recovery codes or use a recovery code, we notify you by email (the email is not stored as a notification); turning it on or off and new recovery codes also end your other sessions. If you lose your device and your recovery codes, we can turn two-step verification off for you at your request after making sure the request is yours; we then end all your sessions and notify you by email. We delete the secret and the recovery codes when two-step verification is turned off, or with your account or workspace; a set-up you do not finish is deleted after 24 hours. The data export shows only whether two-step verification is on.
Server log: Successful sign-ins are logged with email address and IP address, failed attempts additionally with the identifier of the app or browser (see section 3.11).
Visibility to others: Members of your workspace can see your display name and email address in the member list. The owner and the administrators of the workspace also see suspended accounts.
Workspaces organised in groups: The owner of a workspace can organise it in groups (for example one group per client or team). Members of such a workspace see only the members who share at least one group with them — their name, email address and role — and only the names of their own groups; they do not see the other members, the other groups or counts such as the number of members. Spaces, shared files, meetings and calls then belong to one group, and only its members can see and join them. The owner and the administrators see all members and all groups. We store the groups (name, creation time and who created them), their members (who added them and when), the group of each space, share and meeting, the members invited to a meeting and the members allowed into a call (the latter for 12 hours). Groups and memberships are deleted with the workspace; a person's memberships are deleted with their account.
Purpose: to create and manage your account, authenticate you and perform the contract with you.
Legal basis: Article 6(1)(b) GDPR; logging of sign-ins: Article 6(1)(f) GDPR, based on our legitimate interest in protecting accounts against misuse.
Retention: as long as your account exists. For deletion, see section 6.
Devices: For each signed-in device we store the app version, operating system and processor architecture that the app reports. They are kept with the session and deleted with it (at most about seven days after the device was last used), shown to our administrators and included in the data export.
3.4 Workspaces, file storage and synchronisation
Data processed:
- the files you upload (content);
- metadata: names of files and spaces, file type, size, content checksum, owner, time stamps;
- version history (version number, author, optional note), file locks (who locked a file, their name, optional reason);
- change records used for synchronisation (file name, type of change, author) and, for each installation of the desktop app, a random device identifier with the time of the last synchronisation;
- trash records and, after final deletion, a deletion record (file name, number of deleted versions, freed storage);
- usage figures per workspace: storage used, and per calendar month the volume downloaded and the meeting minutes, which we compare with the limits of your plan.
Encryption: Before storage, file content is encrypted with XChaCha20-Poly1305. Each file has its own key, which is protected by a key of your workspace, which in turn is protected by a master key of our server. Because the server holds these keys, we could technically decrypt files in normal spaces. The server decrypts content automatically when an authorised user downloads a file, and when it creates a copy for sharing with another workspace. Our staff do not look at file contents unless you ask us to (for example for support) or we are legally obliged to. Metadata is stored in our database without additional encryption. For end-to-end encrypted private spaces, see section 3.6.
Storage location: file content in Hetzner Object Storage, metadata in a PostgreSQL database on our server, both at [Serverstandort / Server location: Deutschland (Falkenstein/Nürnberg) oder Finnland (Helsinki)].
Purpose: to store, synchronise, version and share your files, and to apply the limits of your plan.
Legal basis: Article 6(1)(b) GDPR. Where we process content on behalf of an organisation, we do so under a data processing agreement (Article 28 GDPR).
Retention: until you or an authorised member delete a file. Deleted files first go to the trash for the retention period set for the workspace (30 days by default). By default, about seven days before final deletion, the owner of the file receives a notice in the app (not by email). After the period expires, the file and all its versions are permanently deleted from object storage and from the database. If you remove a file from the trash in the desktop app before then, it is deleted from your device; on our server it remains in the trash until the period expires. The deletion record remains until the workspace is deleted. When a member leaves the workspace, the member's files stay in it and pass to its owner (section 6.2).
3.5 Sharing, invitations and contacts
Within a workspace: Other members of your workspace only get access to a file or space if it is explicitly shared with them. The exception is the owner of the workspace, who receives your files when you leave the workspace (section 6.2).
Share records: We store who shared what with whom (user or email address), the type of share (for example read-only, one-time download or collaborative), any expiry date and download limit, and revocations. Every download through a share is recorded with the recipient's user ID, the time and the IP address. These records are kept until the workspace is deleted.
Sharing with other workspaces: If you share a file with a person who has a confirmed account in another workspace, that person receives their own copy, encrypted with the key of their workspace. From then on the copy belongs to the recipient's workspace. If you revoke the share, or delete your original file (the app first shows you who holds it and asks you to confirm), the copy disappears from the recipient's view and its content is deleted from storage at once; the remaining record of the copy is deleted after 30 days. Deleting your whole workspace does the same for every copy of its files in other workspaces. Files from private spaces cannot be shared in this way.
Contacts: When you share something with a person, you and the recipient are automatically added to each other's contacts, so both of you can see each other's name and email address.
Invitations: Owners and administrators can invite people to their workspace by email. If an owner or administrator shares a file with an email address that has no account yet, an invitation is sent automatically. For each invitation we store the email address, the intended role, the inviting person, the time and the status. The invitation link is valid for seven days; we store only a hash of it. The invitation email contains the email address of the inviting person.
Information for invited persons and share recipients (Article 14 GDPR): We receive your email address from the user who invites you or shares something with you. We use it to deliver the invitation or notification and to link the share to your account once you register or confirm your address. If you do not accept, the invitation expires after seven days and its record, including your email address, is deleted 30 days later. If the person who invited you leaves the workspace before you accept, the invitation passes to the owner of the workspace. An accepted invitation remains as a record of how the member joined until the workspace is deleted; if the member's account is deleted, the email address in it is replaced. You can object to this processing at any time (section 8).
Legal basis: for users, Article 6(1)(b) GDPR. For invited persons and recipients without an account, Article 6(1)(f) GDPR, based on the legitimate interest of the inviting or sharing user, and our own, in enabling the collaboration they requested.
3.6 Private spaces (end-to-end encryption)
Private spaces are optional. When you set up end-to-end encryption, the desktop app generates a recovery phrase on your device and derives your personal key pair from it. The recovery phrase and your private key never leave your device. If you wish, the app keeps the recovery phrase in your operating system's keychain, encrypted with a passphrase that you choose.
What our server receives: your public keys, namely an encryption key and a signing key, together with a certificate in which your signing key confirms your encryption key; the key of each private space, encrypted separately for each member and signed by the owner of the space; the encrypted file contents and file keys; and the signed history of each private space. The server cannot decrypt the keys of the spaces, the file keys or the file contents.
Signed history of a private space: Whenever the owner creates a private space, adds a member or removes one, the owner's device adds an entry to the history of the space and signs it. Each entry names the space, the time, the current key generation and all members, each with their user ID and public signing key. The members' devices use the history to check who belongs to the space and which keys are genuine. Members of a private space receive the public keys of the other members and the history of the space; the app shows a safety number that two members can compare to confirm their keys.
What our server can still see: the names of private spaces and of the files in them, file types, sizes, owners, members (also in the signed history, with their public signing keys) and time stamps, as well as a keyed checksum that cannot be computed without the key of the space.
Important: If you lose your recovery phrase and no longer have access through any of your devices, neither we nor anyone else can restore the contents of your private spaces.
Legal basis: Article 6(1)(b) GDPR. Retention: files as in section 3.4. Your public keys and certificate are deleted when your account or your workspace is deleted. The signed history stays with its space until the workspace is deleted, also after a member's account has been deleted: it then still contains that former member's user ID and public signing key (not their name or email address), because every later entry builds on the earlier ones and the devices of the remaining members check the whole history (see section 6.2).
3.7 Meetings
Technology: Meetings use a media server (LiveKit) that we operate ourselves on our server. Audio, video, screen sharing and chat messages, including files sent in the chat, are transmitted with transport encryption and relayed through our server in real time. They are not end-to-end encrypted, and they are not recorded, transcribed or stored.
What other participants see: the display name and email address of each participant, which are transmitted with the meeting access token.
Data processed by the server: room name, participant identifier (user ID), display name and email address, the connection data needed to set up the media streams (including IP address and port), and the times of joining and leaving.
Stored data:
- meetings (title, call code, planned or actual start and end, the member who created it) and the rooms they use, with the workspace they belong to;
- for each meeting, events such as the start and end of the room and the joining and leaving of participants (room name, participant identifier, time, number of participants, duration);
- per workspace and calendar month, the participant minutes used, for the limits of your plan;
- operational log entries of the media server, for example room name, participant identifier and connection details (see section 3.11).
Guests: Workspaces on paid plans can invite people without an account to a meeting. The host shares the meeting's call code or join link, or has us send it by email to addresses the host enters. The guest opens the link in a browser and enters a name, which the other participants see; an email address is optional. For each guest who joins we create a guest record in the host's workspace (display name, a generated placeholder address, the email address if one was given, the meeting and the time of joining). A call code works only for its meeting and only while the meeting is running or within its planned time; when the meeting ends, the code stops working, the guests' access is revoked and nobody can join any more. The host can also remove a guest, which revokes that guest's access.
Waiting room: In a meeting with a waiting room (the default for new meetings), a guest waits until a host lets them in or declines them. For this, the guest record also holds its status (waiting, admitted or declined) and when the guest's page last checked in; while the guest waits, the page checks in regularly, and the hosts see the names of the guests who are waiting. If the page of a waiting guest stops checking in for 10 minutes, the guest record and the guest's access are deleted. A declined guest cannot join the meeting; the record, marked as declined, is kept and deleted like other guest records (see Retention below).
Co-hosts: The member who created a meeting or its room, and the owners and administrators of the workspace, can make other members of the workspace co-hosts of the meeting. We store who was made co-host, by whom and when; the participants see who is a co-host. These entries are deleted when the meeting ends.
Calls from the desktop app on Linux: The Linux version of the app cannot hold calls in its own window. It opens the call in your web browser instead: the app obtains a one-time hand-off code, valid for 20 seconds, and opens our meeting page with the code in the part of the address that the browser does not send to the server. The page exchanges the code for a call session that is valid only for this one call. We store only hashes of the code and of the session identifier, together with your user ID, your workspace, the room and the times of creation and expiry. The browser keeps the session identifier in a cookie ("amadeus_call_" followed by a short identifier of the room; HttpOnly, SameSite=Strict, sent only to our programming interface, without an expiry date, so the browser deletes it when it is closed). The session ends when you leave the call, when the meeting ends, when you sign out on all devices or change your password or email address, when your role changes or your account is suspended or deleted, and at the latest when the maximum call duration of your plan has passed, plus 10 minutes (6 hours if your plan sets none). Expired codes and sessions are deleted from our database within six hours. The application log records that a call was handed over to a browser, with your user ID and the room (see section 3.11). The cookie is strictly necessary to provide the call you requested (Section 25(2) No. 2 TDDDG); the processing is based on Article 6(1)(b) GDPR.
Storage in your browser: If you join through the browser, the meeting page saves the access tokens and the meeting details needed to take part in your browser's session storage. This is strictly necessary to provide the meeting you requested (Section 25(2) No. 2 TDDDG). Session storage is cleared when you close the tab, and the page clears it when the meeting ends.
Purpose: to hold meetings, to apply the limits of your plan, and to ensure security.
Legal basis: Article 6(1)(b) GDPR. For guests without a contract with us, Article 6(1)(f) GDPR, based on the legitimate interest of the host and ourselves in holding the meeting the guest has chosen to join.
Retention: Meeting events are deleted after 90 days; ended meetings, with the list of guests who joined them, 90 days after they ended; both also together with the workspace concerned. Guest records are deleted 90 days after they were created. Co-host entries are deleted when the meeting ends; hand-off codes and call sessions as described above.
3.8 Emails, notifications and in-app messages
Emails: We send confirmation links, invitations, notices about shares, meeting invitations with the join link and call code, invitations to spaces and, for paid plans, notices to the owners and administrators of a workspace when a limit of the plan is nearly or fully used. When a member leaves a workspace, we notify its owner that the member's files have passed to them; we also notify a member who becomes the owner of a workspace, and a person who is removed from a workspace (section 6.3), and we notify you of changes to your two-step verification (section 3.3). Depending on the type, they contain the recipient's address, the name or email address of the sender, the name of the file, space or meeting, and a link; notices about a member who left contain that person's name. Our emails contain no tracking pixels or tracking links. We send them through our email delivery service [E-Mail-Versanddienstleister / Email relay provider].
Stored notifications: Every notification, including emails to people without an account, is also stored in our database with recipient address, subject, text and delivery status. Registered recipients see notifications in the app and can delete them there; otherwise they are deleted after 12 months. Invitation links, meeting join links and call codes are only contained in the email; they are not stored with the notification. The email to a person removed from a workspace is not stored. Some notifications appear only in the app, for example the notice to the owner of a private space that one of its members has left the workspace.
In-app messages: System messages (for example notices about the trash), messages from our team and messages you send to our support from within the app are stored in our database until the workspace is deleted. Our administrators can read them.
We do not forward notifications to third-party messaging services.
Legal basis: Article 6(1)(b) GDPR; for recipients without an account, Article 6(1)(f) GDPR (see section 3.5).
3.9 Plans and billing
For each workspace we store its plan, the associated limits and the usage figures described in section 3.4. Paid plans are currently arranged individually through our sales contact; there is no online checkout. For the conclusion and performance of such contracts and for invoicing we process the contact and billing details you give us. [Zahlungsdienstleister / Payment provider]
Legal basis: Article 6(1)(b) GDPR; for retaining invoices and accounting records, Article 6(1)(c) GDPR together with Section 147 of the German Fiscal Code (AO) and Section 257 HGB. Retention: accounting records for up to ten years.
3.10 Desktop app
Data stored on your device: The app keeps on your device a local database (account data, including a password hash that allows offline sign-in, file metadata, contacts, notifications, messages, settings and the guest list you keep for meeting invitations — names and email addresses you save), a local cache of your files and a random device identifier. File contents in the cache are encrypted with XChaCha20-Poly1305; the key is kept in your operating system's keychain. The local database is currently not encrypted; it is protected by your operating system's user account. In the keychain the app also stores the server address and, if you select "Remember Me", your session tokens and basic profile data; if you use private spaces, your encrypted recovery phrase; and API keys for AI providers if you enter any. We have no access to this local data. By default the app writes no log file. Depending on your operating system, uninstalling the app may not remove local data; you can delete the "AmadeusShare" folder in your user profile's application data directory.
Suspended or removed account: If our server reports that your account has been suspended or removed from its workspace, or that its workspace was deleted, the app notes this on your device (user ID, email address, reason and time), so that the account no longer opens without a connection and a later sign-in can tell you why. The note is deleted when a sign-in with this address succeeds again. For a removed account, and for an account whose workspace was deleted, the app also offers to delete the account's data from the device; it deletes it only if you agree, and the note itself remains.
Encrypted USB vault: If you use the optional vault on an external drive, the data remains on that drive and is not transmitted to us.
Connections: The app connects to our server and to our media server. It loads no content from third parties (its fonts ship with the app), sends no telemetry or crash reports and does not check for updates automatically.
AI settings: The app contains settings for connecting an AI language model, either a program running locally (Ollama, LM Studio, vLLM) or a cloud service (OpenAI, Anthropic, Google Gemini, Zhipu GLM). The current version contains no function that sends your files or other content to an AI model. If you use "Test Connection", the app connects directly from your device to the provider you have chosen, using the API key you have entered, and retrieves the list of available models. This happens only on your initiative; we receive no data. The provider's own privacy terms apply. Cloud providers may be located outside the EU, for example in the USA or China.
3.11 Security, abuse prevention and logs
- Rate limiting: To limit requests and block password-guessing attempts, the server keeps IP addresses, and for sign-ins also the email address entered, in its memory; to limit password and code attempts for important actions and two-step verification, it keeps the user ID. They are removed after 30 minutes without activity.
- Application log: every request (method, path, status, duration, data volume, IP address); sign-ins (email address, IP address, for failed attempts also the app or browser identifier); attempts with an unknown call code (IP address); creation of workspace invitations (email address of the invited person); suspension, reactivation and removal of members, deletion of one's own account and transfers of ownership (user IDs, workspace ID); hand-over of a call to a browser (user ID, room); sign-ins waiting for the two-step code and wrong codes (IP address), resets of two-step verification by our administrators (user ID); delivery of contact form messages (topic, IP address).
- Reverse proxy access log: see section 3.1.
- Media server log: see section 3.7.
- Retention of logs: 14 days.
- Administrator audit log: Every change made through our administration interface is recorded with the administrator's user ID, email address and IP address, the action, the path, the result and a copy of the request with secrets removed. The following actions in the app are recorded in the same way: the deletion of a workspace or of one's own account, the suspension, reactivation and removal of members and the transfer of ownership by the owner or an administrator, and turning one's two-step verification on or off and creating new recovery codes (without the secret or the codes). Instead of a copy of the request, these entries contain the user IDs of the persons concerned, the workspace and figures such as the number of files and spaces handed over; an entry about the deletion of one's own account contains no email address. These records may contain data of the users concerned. The audit log cannot be altered; entries are deleted after 12 months, also where the accounts or workspaces they refer to were deleted earlier.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in protecting our systems and your data and in being able to demonstrate compliance (Articles 5(2) and 32 GDPR).
Security figures: We count successful and failed sign-ins, wrong two-step verification codes and throttled attempts per hour, without email or IP addresses, and keep these counts for 13 months. While an account is temporarily locked after failed attempts, our administrators can see that it is locked; IP addresses appear there only shortened to their first three parts.
Email delivery: For each email we send we record whether it was delivered and, if not, the error message of the receiving mail server, as part of the notification records (12 months); of other emails (for example confirmation and reset links) we keep only counts per type.
3.12 Operation, backups and administrator access
Hosting: Our server and the object storage are provided by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, at [Serverstandort / Server location: Deutschland (Falkenstein/Nürnberg) oder Finnland (Helsinki)], acting as our processor under a data processing agreement (Article 28 GDPR).
Backups: Once a day we create a full backup of the database (account data, metadata, share, notification and message records). It is encrypted on the server with a key that is not kept there, and only the encrypted backup is copied to [Speicherort Backups / Backup storage location]. File contents in object storage are not backed up separately. Database backups are deleted after 14 days.
Administrator access: Our administrators reach the server and the administration interface only through an encrypted VPN (Tailscale); the administration interface is not publicly accessible and refuses any request that does not come through it. Administrator sessions end after eight hours at most. Tailscale Inc. processes only connection metadata of our administrators' devices. The content of these connections is end-to-end encrypted and cannot be read by Tailscale. Our administrators can see account data (for example email address, name, workspace, plan, storage used, last sign-in), in-app messages and the audit log; they can change plans and roles, suspend, reactivate and remove accounts, move an account into another workspace, transfer the ownership of a workspace (sections 6.3 to 6.5), see whether an account uses two-step verification and turn it off at the account holder's request (section 3.3). The administration interface has no function for viewing file contents.
Usage statistics: Once a day we record for each workspace its plan, the number of members, the storage used (including the trash and versions), the number of files, versions and spaces, meeting minutes, meetings, guests, the download volume and completed and failed uploads, and for the whole platform the totals of these figures and of requests, errors, sign-ins and emails — without names, email or IP addresses. We use them for capacity planning, a stable and secure operation and to see whether plans fit. Legal basis: Article 6(1)(f) GDPR. They are kept for 13 months; a workspace's statistics are deleted with the workspace.
Server resources: We monitor the server's resources (processor, memory, disk, network, database); these contain no personal data. Alert and summary emails to our administrators contain no personal data either.
What our administrators also see: the usage statistics and their history per workspace; the app versions and operating systems of an account's signed-in devices and when each last connected; aggregated security figures and temporarily locked accounts; and the delivery status of emails (type, domain of the recipient, error).
Legal basis: Article 6(1)(b) and (f) GDPR. Our legitimate interest lies in secure and reliable operation and in being able to restore data after a failure.
4. Recipients
- Hetzner Online GmbH (hosting and object storage), as a processor;
- [E-Mail-Versanddienstleister / Email relay provider] (sending emails), as a processor;
- [E-Mail-Postfach-Anbieter / Mailbox provider] (our mailbox for contact requests), as a processor;
- other users, to the extent described above: members of your workspace, recipients of your shares and participants in your meetings, and the owner of your workspace when you leave it (section 6.2);
- public authorities, where we are legally obliged to disclose data.
Tailscale Inc. receives no data of our users (section 3.12). We do not sell personal data and do not use it for advertising.
5. Transfers to third countries
We store and process your data in the European Union. We do not intend to transfer it to countries outside the EU or the European Economic Area, with the following exceptions:
- connections you initiate yourself to a cloud AI provider of your choice (section 3.10);
- emails to recipients whose email provider is located outside the EU; this is inherent in sending email.
6. Retention and deletion
We store personal data only for as long as necessary for the purposes described, or as long as statutory retention obligations require. Overview:
- Server and proxy logs: 14 days (section 3.1).
- Rate limiting data in memory: 30 minutes after the last activity.
- Contact requests: [Aufbewahrungsfrist Kontaktanfragen / Contact request retention period] after the matter is closed, subject to statutory retention obligations.
- Account data: until the workspace or your account is deleted, also by removal from the workspace; accounts not confirmed within 30 days are deleted; suspended accounts are kept until they are reactivated or removed or the workspace is deleted.
- Files: until deleted, followed by the trash retention period of the workspace (30 days by default); the files of a member who leaves stay in the workspace with its owner (section 6.2).
- Share, download, message, synchronisation and deletion records, contacts, accepted invitations: until the workspace is deleted.
- Invitations not accepted: 30 days after they expire.
- Notifications and the administrator audit log: 12 months.
- Meeting events and guest records: 90 days; guests who stop waiting in the waiting room: after 10 minutes; co-host entries: until the meeting ends.
- Public keys and certificates for private spaces: until the account or the workspace is deleted; the signed history of a private space: until the workspace is deleted.
- Copies shared with other workspaces, once the share is revoked or the original or its whole workspace deleted: content at once, the remaining record after 30 days.
- Sessions, sign-in, confirmation and reset links: when they expire or are used.
- Two-step verification (section 3.3): the encrypted secret and the hashed recovery codes until it is turned off or the account or workspace is deleted; a set-up not finished: 24 hours; sign-ins waiting for the code: five minutes.
- Records of sessions ended by a suspension, a removal or the deletion of the workspace: until the refresh token would have expired, at most about seven days, or until the account is reactivated (section 3.3).
- Call hand-off codes and call sessions in the browser (section 3.7): when they are used or end, at the latest when they expire; the records are deleted within six hours after that.
- Usage and operating statistics (section 3.12): 13 months; a workspace's statistics until the workspace is deleted. Hourly operating figures: 35 days.
- Database backups: 14 days.
- Accounting records: up to ten years.
6.1 Deleting a workspace
The owner of a workspace can delete it in the desktop app under "Settings" with the "Delete Account" function. The deletion takes effect immediately and cannot be undone. It removes from our database the workspace and all accounts belonging to it, including the accounts of invited members, together with all files and versions, shares, invitations, contacts, notifications, messages, meeting access data and keys. Copies of its files that were shared with other workspaces are deleted as well: they disappear from the recipients' view as when a shared file is deleted. The stored files, and the content of those copies, are then deleted from object storage. The following remain:
- entries in the administrator audit log, for up to 12 months;
- for each session of the workspace's accounts that the deletion ended, the hash of its refresh token, the user ID and the reason, so that the members' apps can say that the workspace was deleted, until the refresh token would have expired, at most about seven days (section 3.3);
- log files and database backups, for up to 14 days.
An owner who wants to leave the workspace but keep it for the others first makes another member the owner (section 6.5) and can then delete their account as a member (section 6.2).
6.2 Deleting your account as a member of a team workspace
Members can delete their account in the desktop app under "Settings" with the "Delete my account" function. The app first shows what will happen to your content (see below). It then offers to save the data we store about you as a JSON file, and a copy of your own files, with the files of your private spaces decrypted, in a folder you choose. Finally it asks you to confirm. The deletion takes effect immediately and cannot be undone.
As long as you own a private space that other members belong to, the deletion is not possible: first hand the space over to one of its members who may write in it (the app takes you there). Nor is it possible while one of your spaces is in the middle of a conversion to end-to-end encryption; wait until the conversion has finished. The owner of a workspace cannot delete their account in this way (section 6.1).
What passes to the owner: Content in a workspace belongs to the workspace. Everything you own in its normal spaces therefore passes to the owner of the workspace, also when an administrator removes you (section 6.3): your files with their names, versions and version history, including files you have not shared with anyone and files in the trash; the normal spaces you created; the shares and space memberships you created, which keep running and which the owner can end; your pending invitations; and the meetings you planned. Copies of files that users of other workspaces shared with you pass to the owner as well; their senders can still revoke them. Shares that others in the workspace made with you, and your memberships in their spaces, end.
Files in "My Files": The files in your "My Files" are moved into a new normal space that only the owner holds. It is named after you in the owner's language, in English for example "From Anna Example", using your display name, or else your first and last name, or else the part of your email address before the @. People with whom you had shared individual files from "My Files" keep their access; they then see these files in that space. The owner can rename the space.
What is deleted: Private spaces that you own and that no one else belongs to, and your end-to-end encrypted personal files (your "My Files" after its conversion to end-to-end encryption), are deleted with all their files and versions, because only your devices hold their keys. Neither the owner of the workspace nor we nor anyone else can recover them. People with whom you had shared files from them lose access. Files you added to other people's private spaces stay there and pass to the owner of the space in question. The stored files are then deleted from object storage.
Your account: We replace your email address and username with random values, delete your password hash, names and profile picture link, end all your sessions and calls and delete your contacts, the notifications and messages addressed to you, your sign-in and confirmation links, your two-step verification (secret, recovery codes, sign-ins waiting for a code), meeting access, co-host entries, your personal meeting room and your encryption keys. Where your email address appears in invitations, stored notifications or shares, it is replaced as well. Your public keys for private spaces are deleted; the signed history of the private spaces you belonged to keeps your user ID and public signing key, but not your name or email address, as long as the space exists (section 3.6). The app also deletes the account's data on your device.
What still refers to you: The version history and the download records of the files keep your user ID, but not your name or email address. Your name remains in the name of the space created from your "My Files" until the owner renames it, and in the notices about your departure described below. Notifications that other users received earlier about something you did, for example a share, keep their text, which may contain your name, until the recipients delete them or they are deleted after 12 months (section 3.8).
Notices: The owner of the workspace receives a notice in the app, and by email if the owner's address is confirmed, that your files are now theirs, with your name, the reason (account deleted or removed), the number of files and spaces handed over and the name of the new space. If you held a key to private spaces of other members, your key is deleted, and the owner of each such space receives a notice in the app with your name. The owner then confirms your removal in the list of members of the space, and the owner's device gives the space a new key. Our server does not do this on its own, because only the members' devices hold the key of a private space and every change of its members must be signed by its owner.
The deletion is recorded in the administrator audit log (section 3.11).
6.3 Removal from a workspace
The owner of a workspace and its administrators can remove a member in the desktop app on the "Users" page. Administrators can remove only members, not other administrators; nobody can remove the owner or themselves. Before the removal, the app shows the person removing the member what will happen, as described in section 6.2, and asks them to confirm. The removal takes effect immediately and cannot be undone: the member's content passes to the owner of the workspace, and the account is erased, as described in section 6.2, with these differences:
- The removed person is not asked first and therefore cannot save their data or files through the app beforehand.
- Private spaces owned by the removed person that other members belong to are neither deleted nor handed over: they stay as they are, with their content, and the other members can continue to read and write in them. Because only the members' devices hold the key of such a space, nobody can take over its ownership; until a recovery function for workspaces is available, no members can be added to such a space or removed from it. Private spaces of the person that no one else belongs to, and their end-to-end encrypted personal files, are deleted and cannot be recovered by anyone.
- If the address of the account was confirmed, we send the removed person an email to that address, in the language of the account: that they were removed from the workspace, that their account was deleted, that the files remain with the workspace and that the address can be used again. We read the address and the language for this before the account is erased, and we do not store the email as a notification.
- The email address is then free again: it can be used to register or to accept an invitation.
- When the app of the removed person next connects to our server, it reports the removal and offers to delete the account's data from that device; the data is deleted only if the person agrees (section 3.10).
We can also remove an account through our administration interface, for example at the request of the member or of the owner; the same then applies, and the content passes to the owner of the workspace. Nobody can remove the owner: ownership must first pass to another member (section 6.5). Every removal is recorded in the administrator audit log (section 3.11).
6.4 Suspension
Instead of removing a member, the owner or an administrator can suspend them on the "Users" page, with the same restrictions as in section 6.3. A suspended account can no longer sign in: its sessions and calls end at once, and the app shows the suspension when it next connects to our server (section 3.3). Nothing is erased: the account, its files, spaces, shares and memberships remain as they are, and its email address remains reserved for it. We do not notify the suspended person by email. The owner or an administrator can reactivate the account at any time, provided the plan of the workspace has a free seat; files that were added in the meantime to spaces the person is a member of are then shared with them. A suspended account is kept until it is reactivated or removed, or the workspace is deleted. We can also suspend and reactivate accounts, including the account of an owner, through our administration interface, for example under section 9 of our terms of service. Suspensions and reactivations are recorded in the administrator audit log (section 3.11).
6.5 Transfer of ownership
The owner of a workspace can make another member its owner in the desktop app on the "Users" page ("Make owner"); to do so, the owner enters their current password and, if they use two-step verification, a code. The new owner must be an active member or administrator of the workspace with a confirmed email address. The previous owner becomes an administrator. The new owner receives a notice in the app and by email. From then on, the new owner holds the owner's rights, including the right to delete the workspace (section 6.1), and receives the content of members who leave (section 6.2). We can also transfer ownership through our administration interface, for example when the owner's account is suspended or the owner can no longer act; no password is needed then. Every transfer is recorded in the administrator audit log (section 3.11).
7. Security measures
- All connections to our website, our server and our media server are encrypted with TLS (at least version 1.2); browsers are instructed to use encrypted connections only (HSTS).
- File contents are stored encrypted with XChaCha20-Poly1305, using separate keys per file and per workspace; their integrity is checked with BLAKE3 checksums. In normal spaces the server holds the keys (section 3.4); in private spaces only your devices do (section 3.6).
- Passwords are stored only as bcrypt hashes; refresh tokens, invitation and confirmation links only as hashes. Call codes are random, work only for their meeting and stop working when it ends.
- The server is protected by a firewall that blocks all ports not needed; the database and internal services can only be reached locally on the server; administration is possible only through an encrypted VPN; requests are rate-limited; administrative changes are recorded in the audit log.
- Limitations: account data and metadata in our database and in its backups are not additionally encrypted by the application, and the local database of the desktop app is currently not encrypted.
No system can be completely secure. We review and improve our measures on an ongoing basis.
8. Your rights
You have the following rights with regard to your personal data:
- access (Article 15 GDPR);
- rectification of inaccurate data (Article 16 GDPR);
- erasure (Article 17 GDPR);
- restriction of processing (Article 18 GDPR);
- data portability (Article 20 GDPR);
- objection to processing (Article 21 GDPR, see below).
To exercise your rights, please contact [Datenschutzkontakt / Privacy contact]. You can download your files at any time through the desktop app. In the app you can also export the data we store about you (Settings, "Your data"), change your email address and delete your account yourself; before the deletion, the app also offers to save a copy of your own files. If your account is suspended, you can no longer sign in; to obtain access to your data, a copy of it or the deletion of your account, please contact the owner of your workspace or us. When your account is deleted, the files in normal spaces stay with the workspace and pass to its owner (section 6.2). If your request concerns such files or other content in a workspace that an organisation uses for its team (section 2), please also contact that organisation.
We currently do not base any processing on your consent.
Right to object (Article 21 GDPR)
Where we process your personal data on the basis of legitimate interests (Article 6(1)(f) GDPR), you have the right to object to this processing at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. We do not use your data for direct marketing.
9. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR), in particular in the EU member state of your habitual residence, your place of work or the place of the alleged infringement. The authority responsible for us is: [Zuständige Aufsichtsbehörde / Competent supervisory authority].
10. Are you obliged to provide data?
You are not legally obliged to provide personal data. However, we need your email address, a username and a password to set up an account, and your name, email address and message to answer a contact request. Without these details we cannot provide the respective service.
11. No automated decision-making
We do not use automated decision-making, including profiling, within the meaning of Article 22 GDPR. The technical limits of your plan, such as the storage quota, are applied automatically; this is not a decision within the meaning of Article 22 GDPR.
12. Changes to this privacy policy
We will update this privacy policy when our service or the legal situation changes. The current version is always available on this page. We will inform registered users of significant changes in the app or by email.
Last updated: [Datum / Date]