Privacy Policy
The short version
- Your private keys are created on your device and never reach us. We can't read your messages: they are end-to-end encrypted.
- Files you upload are end-to-end encrypted too: contents and names are encrypted on your device before they reach us. We can still see sizes, times, how folders nest and who a folder is shared with. Folders you make public are the exception: anyone with the address can read them.
- Your ID, public keys and anything you publish are public by design: that's how others find and verify you.
- We keep logs and anonymous diagnostics (which screens are used, errors, speed) to run and improve the service. They contain no Poweur ID and no IP address, and nothing is stored on your device for them. Your ID is included only if you tick Include my ID in Settings → Diagnostics.
- We don't sell data, show ads or build profiles.
1. Who we are and what this covers
This policy covers the Poweur services we operate:
- the hosted relay and web app at poweur.net and your ID's own address (for example
alice.poweur.net); - the sign-in bridge at oauth.poweur.org;
- the website and documentation at poweur.org.
The data controller is Roman Mandryk, R. Prudêncio Franco da Trindade 4, 2655-344 Ericeira, Portugal (VAT / NIF PT307974510). Contact us about privacy at [email protected], or message support.poweur.net from the app.
Poweur is open-source software that anyone can run. A relay someone else operates, including one on your own domain, is their service under their privacy policy. This policy only covers the services listed above.
2. What we can't see
- Your private keys. They are generated on your device. What reaches us is at most an encrypted copy, locked with your passkey or your phone's keystore. We can't unlock it, which also means we can't recover your ID for you: your recovery kit can.
- Message contents. Messages are encrypted on the sender's device for the recipient. We store and forward ciphertext. Your message history is stored in your home encrypted to your own key.
- Your passkey. Your browser or phone keeps it. We see only the public part needed to check a sign-in.
3. What we store, and why
| Data | Why | How long |
|---|---|---|
| Your ID document: your name, public keys, which relay hosts you | So anyone can find and verify you. Public. | Until you delete your ID |
| Profile you choose to publish (display name, picture) | Shown to people who look you up. Public. | Until you change or delete it |
| Encrypted key backup and device list | So your own devices can unlock and add each other | Until you delete your ID |
| Messages in transit: ciphertext plus sender, recipient, time and size | To deliver messages, including while you're offline | Until delivered; undelivered messages expire after 30 days |
| Files you upload, and folder and share settings | To store and share them as you ask. File contents and names are end-to-end encrypted: we see sizes, times, how folders nest and who a folder is shared with, not what is in them. Folders you make public are not encrypted and anyone with the address can read them. | Until you delete them or your ID |
| Contacts, inbox rules, shares and app grants | The relay has to read these to deliver messages and enforce your permissions | Until you change them or delete your ID |
| Public links and link statistics (download counts) | So you can share files with people without an ID and see that they were used | Until the link expires or you remove it |
| Sign-in sessions | To keep you signed in on a device | Short-lived and held in memory only |
| Server logs and metrics: route, result, timing, errors | To keep the service running, debug it and stop abuse | Logs 14 days; aggregate metrics 30 days |
| Storage and backups | Your home (files, message history, settings) is kept in Hetzner Object Storage in one data centre in Germany. Each piece is spread across several servers, so up to three can fail without losing data. Hetzner does not publish a durability guarantee, and we do not yet keep a second copy in another location. The rest of the server is copied daily by Hetzner in the EU, for recovering the service, not for restoring individual files | Your home: until you delete it. Server copies: 7 days, then deleted |
Diagnostics. The app, the sign-in bridge, the website and the docs send anonymous diagnostics to our own server: which screens and pages are viewed, errors and loading speed, with your browser name, version, operating system and screen size. Before anything leaves your browser, Poweur IDs, domain names and email addresses are replaced with placeholders and link queries and fragments are removed; no IP address is kept and nothing is stored on your device. We keep them for 14 days. If you tick Include my ID in Settings → Diagnostics, the app’s diagnostics carry your ID and relay logs about your requests include your ID and IP address, which lets us find problems you run into. Untick it at any time: from then on, logs record only a keyed hash of your ID and no IP address.
Signing in to other apps
When you use your ID to sign in to another website through oauth.poweur.org, the bridge learns which site asked, your ID, and what you approved, and it issues that site a token. The site then receives your ID and whatever profile details you approved. What that site does with them is covered by its own privacy policy. The Connected apps page in the app lists the sites you've approved and lets you disconnect them.
Storage limits and support
Free storage is limited. If you message our support ID to ask for more, we see that conversation like any other contact would, and we keep a note of the higher limit next to your ID.
4. Who else is involved
We use a small number of service providers. They process data on our behalf and only as needed for the service:
| Provider | What for | Data |
|---|---|---|
| Hetzner Online GmbH (Germany) | The servers the relay, bridge and website run on, in data centres in the EU | Everything in section 3, encrypted where described above |
| Cloudflare | DNS and network protection in front of some of our addresses | IP addresses and request data passing through it |
| Better Stack | Uptime checks, and error reports from our servers | Server-side only: request routes, error codes and timings, with IDs hashed unless you opted in. Nothing from your browser. |
Some of these providers are outside the European Economic Area. Where that applies, transfers rely on the European Commission's adequacy decisions or standard contractual clauses.
Messages to people on other relays go to the relay that hosts them. That relay stores and delivers them under its operator's policy.
We don't sell or rent personal data, and we don't use it for advertising.
5. Legal bases
Where the EU or UK GDPR applies, we rely on:
- contract: hosting your ID, delivering your messages and storing your files is the service you asked for;
- legitimate interests: security, preventing spam and abuse, backups, pseudonymous logs, and anonymous diagnostics to keep the service working;
- consent: including your ID in diagnostics (Include my ID), off unless you tick it and withdrawable at any time in Settings;
- legal obligation: where the law requires us to keep or disclose data.
6. Your choices and rights
- Download your data at any time through the app, WebDAV or the CLI. Your ID and files use open formats.
- Move your ID to your own domain or another relay: the protocol is designed for it.
- Delete your ID: message support.poweur.net from the ID, or email us from an address you can prove is yours. We delete your home, ID document and waiting messages within 30 days, and from our backups at most 7 days after that.
- Under the GDPR you can also ask for access, correction, restriction or portability, and you can object to processing based on legitimate interests. Write to [email protected].
- You can complain to a data protection authority. Ours is the Portuguese Comissão Nacional de Proteção de Dados (CNPD), and you can also complain to the authority where you live.
Other people may keep copies of what you sent them or shared with them. Deleting your ID can't remove those.
7. Requests from authorities
We only disclose data when the law requires it and the request is valid. We can only hand over what we have: we don't have your keys or message contents. Where we're allowed to, we'll tell you before disclosing anything.
8. Security
Everything travels over HTTPS. Keys stay on your devices, and messages, message history and files are end-to-end encrypted (public folders excepted). Access to our servers is limited and logged. Poweur is pre-1.0 and has not had an independent security audit yet. Please report vulnerabilities as described on the legal overview.
9. Children
The service is not intended for children under 16. If you believe a child has created an ID, please contact us.
10. Changes
If we change this policy in a way that matters, we'll announce it on poweur.org and in the app before it takes effect. The date at the top shows the latest version, and the change history is public.