Privacy Policy

This policy explains what personal data qwabbl processes, why, and the rights you have. The controller responsible for this processing is pocketservices GmbH; our full contact and legal details are on the Impressum page. The conditions for using the service are separate, in the Terms of Service.

Data we process

Account data. When you register we store your username, e-mail address, a securely hashed password and any profile details you add. We use this to provide your account and the service (Art. 6(1)(b) GDPR, performance of a contract).

Content you create. Posts, replies and uploads you publish are stored to operate the service. Content in private channels is end-to-end encrypted on your device, so we cannot read it — that covers texts, titles, files, and the names and descriptions of private channels; their web addresses are random identifiers that mean nothing. Who is a member of a channel, and when reading or writing happens, remains visible to us as metadata the service needs to operate. Public content is, by design, visible to others and may be indexed by search engines.

What members of a private channel see about each other. Inside a private channel, a post's history card shows every member who has contributed and who has not opened the post yet — without timestamps, but visible to the whole room. We keep no read log: the card is derived from the read pointers that run the service anyway (Art. 6(1)(b) GDPR). The card does not exist outside private channels.

Invitations. When you invite someone to qwabbl we send, at your request, one e-mail to the address you entered (Art. 6(1)(f) GDPR — your and the invitee's legitimate interest in getting in touch). We store the address encrypted until the link expires or the person joins, and afterwards only a hash, so we never write to it again and an opt-out is respected permanently. Every invitation carries an opt-out link; we send no reminders.

Technical and usage data. For each request our servers briefly see your IP address. We do not store your full IP — only a coarse, country/city-level approximation and the network operator (autonomous system), together with the page requested, the time, and your browser's user-agent. We use this for security, abuse prevention and aggregate statistics (Art. 6(1)(f) GDPR, legitimate interest) and delete it after about 90 days. Security events — sign-in attempts, changes to your password, keys or two-factor settings, tripped rate limits — are recorded with your full IP address for 7 days; after that only the coarse network form remains, and the whole record is deleted after 90 days.

Cookies. We set two strictly necessary first-party cookies: a session cookie so that you stay logged in, and an opaque token that gives your browser its own share of our rate limits, so that other people behind the same network address cannot lock you out. The token identifies no one — it is derived from your account and grants nothing — and it is removed as soon as you are no longer signed in. We do not use advertising or third-party tracking cookies.

Payments. Tips are settled on the public Solana blockchain. On-chain transactions are inherently public and outside our control. We never take custody of your funds or wallet keys.

Connected mailboxes (e-mail sync). This feature is optional and off by default. If you set it up, we store your IMAP credentials (server, username and password — the password only in encrypted form) and fetch messages from your inbox to file them as posts in your personal channel. That processing covers the sender, subject, body and PDF attachments — including personal data of third parties who wrote to you. The legal basis is Art. 6(1)(b) GDPR (providing the service you asked for). In move mode, which you have to choose explicitly, messages are deleted from your mailbox once they have been filed; in the default mode your mailbox is opened read-only and never modified. Filed content lands in a personal channel only you can see and follows the normal post lifetime. You can disconnect at any time, which deletes the stored credentials.

AI-assisted features. Several features rely on third-party services. Sent to OpenAI: your voice recording (dictation) and the transcript it produces, the text of your post (proofreading), the photograph itself when you ask for a suggested caption, and the name and organisation you type into an @(Name, Organisation) mention, which is looked up on the web — that search runs through OpenAI or, depending on our configuration, Anthropic (USA, Standard Contractual Clauses), and we cache the result (name, organisation, profile address) for up to 180 days so the same mention need not be looked up again. Sent to Voyage AI: the contents of pictures, videos and documents you attach — the image itself, video frames, rendered PDF pages — so that search can find them by what they show. Titles and post text are turned into vector embeddings by our database provider. These providers are located in the USA; transfers are made on the basis of the EU Standard Contractual Clauses. The legal basis is Art. 6(1)(b) GDPR.

You decide, per channel. AI features are off by default in private (end-to-end encrypted) channels and can be switched off in any other. As long as they are off for a channel, nothing from that channel reaches these services. If you explicitly switch them on for a private channel — the settings warn you when you do — then that channel's pictures, videos and documents are processed like any other channel's; the message text itself stays end-to-end encrypted and is never sent.

Your search words are a separate case, because a search looks across every channel you can see and so no single channel's setting can govern it. When you search, your search words are sent to OpenAI and Voyage AI so that pictures and scanned pages can be matched by what they contain. You can switch this off in your profile; search then still finds titles, text and file names, and your search words never leave qwabbl.

How we protect your data

Passwords are stored only as salted hashes. Private channels are protected with end-to-end encryption. Sensitive key material is additionally wrapped with a server-side envelope key, so a copy of our database alone does not reveal it. Traffic is encrypted in transit (TLS).

Recipients and processors

We do not sell your personal data. The following providers process data on our behalf as processors under Art. 28 GDPR:

  • Vultr (server hosting and DDoS mitigation) — our server runs in the Frankfurt data centre, Germany. The provider is The Constant Company, LLC (USA); as the network operator it sees the IP addresses of the traffic. Access from the US in the course of support and operations cannot be excluded; a data processing agreement and the EU Standard Contractual Clauses (Art. 46 GDPR) are in place.
  • MongoDB Atlas (database hosting) — stored in the AWS Frankfurt region, Germany. The provider is MongoDB Inc. (USA) and access from the US in the course of support and operations cannot be excluded; a data processing agreement and the EU Standard Contractual Clauses (Art. 46 GDPR) are in place.
  • OpenAI (USA) — dictation and proofreading, the suggested captions for photographs, the look-up behind an @(Name, Organisation) mention, and — unless you switch that off in your profile — your search words. Only for channels where AI features are enabled. Standard Contractual Clauses.
  • Voyage AI (Voyage AI, USA — called directly by us, not through MongoDB) — embeddings of the pictures, videos and documents in channels where AI is allowed, and of your search words unless you switch that off. Standard Contractual Clauses.
  • Anthropic (USA) — only the web search behind an @(Name, Organisation) mention: what is transmitted is the name and organisation you type. Standard Contractual Clauses.
  • OpenStreetMap (Nominatim and Overpass, operated in the EU) — only when you ask for a suggested caption for a photograph that carries location data: the coordinates are sent to name the place. Nothing identifying you is transmitted.
  • Apple (APNs, USA) — only if you install our app and enable notifications: the device token and the notification text. Standard Contractual Clauses.
  • MailChannels (Vancouver, Canada) — delivery of our e-mails (account confirmations, for example); what is transmitted is the recipient address and the message content. Canada is covered by an EU adequacy decision (Art. 45 GDPR, commercial organizations under PIPEDA).

Solana blockchain lookups (for instance when you connect a wallet) go to the public endpoints of the Solana network; the only thing transmitted is your wallet address, which is public on the blockchain anyway.

If you connect a mailbox or a news feed, qwabbl fetches from the server you name, on your behalf. Information you place in the Solana blockchain is public by nature and cannot be deleted.

Retention

  • Account data: for as long as your account exists. Inactive accounts are deleted: after roughly six months without a sign-in or activity we delete the account and all its data — we warn you by e-mail one month ahead, and simply signing in is enough to keep the account. New accounts need a little initial activity and a confirmed e-mail address during their first month; new accounts that stay unused or unconfirmed are deleted after one month (a notice appears on the site in good time).
  • Posts: deliberately mortal — without activity a post expires after a while and is permanently deleted with its replies and attachments.
  • IP addresses on posts: removed automatically after 7 days.
  • Usage statistics: 90 days, and only ever as a hash — the plain text is never stored.
  • Credentials of connected mailboxes: deleted as soon as you disconnect.
  • Raw copies of synced mail (only if you switch that option on): 30 days.
  • Security log: entries (sign-in attempts, key, password and two-factor changes, tripped rate limits) for 90 days; the full IP address within them for 7 days only. Such entries may outlive a deleted account by up to 90 days.
  • Backups: our database provider keeps encrypted backup snapshots for up to 180 days. They serve solely to restore the service after a failure and are not used otherwise; deleted or scrubbed data can therefore persist in a backup for up to 180 days.

If you delete your account, its data is removed immediately — subject to statutory retention duties, for instance invoices for paid features.

Your rights

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21), and the right to withdraw consent at any time.

Two of these you exercise directly in your account — no request, no waiting: on Edit profile you will find “Download my data” (access and portability, Art. 15 and 20 — a zip archive of everything stored under your account) and “Delete my account” (erasure, Art. 17). You can correct your profile details there yourself at any time. For anything else, reach us through the Contact page; we answer within one month (Art. 12(3) GDPR).

You also have the right to lodge a complaint with a supervisory authority — for us that is the Hessischer Beauftragter für Datenschutz und Informationsfreiheit, Postfach 3163, 65021 Wiesbaden, Germany.

Changes

We may update this policy as the service evolves; please review it periodically.

Keyboard shortcuts
Are you sure?