Transparency
What we store.
For how long. Who sees it.
You don't have to trust us — you can check. In the app, your server file shows the key data our server stores about your account, at any time. Here we explain openly what is encrypted and what isn't, how long we keep data and which service providers are involved.
In the app
Your server file
Profile → Security → “View my data”. The file is read fresh from our database every time you open it — for your account only, over an encrypted connection.
Instant, no request needed
No email, no form, no waiting. The file is put together the moment you open it.
The core sections
Account and sessions with IP address, consents, security, profile, identities, location, messages as raw data, metadata, groups, calls, contacts, files, archive and devices.
With retention period
Every section shows how long it is kept.
Everything else on request
The file shows the core sections. For a complete copy of all data about your account (Art. 15 GDPR), email info@aicq.app.
Honest about large amounts
For each section the app shows the latest 500 entries — and always states the total.
Only for you
The request only returns the data of the signed-in account. Nobody else can pull up your file through the app.
See every section of the file
At the top
- Sign-up IP
- Messages (raw data)
- Chat partners
Account & sign-in
- Account
- Active sessions
- Consents
- Security & keys
Profile
- Profile record
- Sub-accounts
- Location
Communication
- Messages: metadata
- Group messages
- Groups & voice channels
- Calls
Contacts
- Friendships
- Blocked by you
Content & files
- Files & uploads
- Archive (file storage)
Devices
- Devices
What is not in the file — and why
- Passwords, keys and codes. Your password (stored only as a one-way hash), 2FA secret, backup codes, sign-in tokens and key material are never shown — not even to you. The file only states that they exist.
- Further data about your account. The file only shows the core sections. Everything else we store about your account, for example purchases, logs or support requests, is sent to you on request to info@aicq.app — complete and machine-readable.
- Internal abuse signals. We do not show risk scores from abuse detection, so they cannot be bypassed.
- Logs outside the database. Our hosting provider's access logs (with IP address) are not in the database and are deleted there automatically after 7 days.
- Data at service providers. What goes to service providers for individual features is listed below under Service providers.
- What is only on your device. Your private keys for end-to-end encryption, the app's message store and your encrypted chat backup are only on your device. The server only keeps the key to your chat backup, so you can open it again after signing in — without the file on your device it is of no use.
Encryption
What is end-to-end encrypted — and what isn't
- End-to-endOnly the devices of the people involved can read the content — we cannot.
- Encrypted in transitEncrypted on the way. On our server, however, the content is not end-to-end encrypted; access is controlled by permissions.
- Service providerGoes to an external service for this feature.
| What | Protection | Details |
|---|---|---|
| Text of your direct messages | End-to-end | Based on the Signal approach (Double Ratchet, ECDH P-256, AES-256-GCM). The server only stores the encrypted text; the keys are created on and never leave your devices. |
| Blind-chat messages | End-to-end | Encrypted the same way as direct messages. Deleted after 7 days. |
| Local P2P chat | End-to-end | Runs directly between two devices (WebRTC, encrypted) and is not stored. Our server helps set up the connection; STUN servers only see IP addresses. If no direct connection works, messages travel end-to-end encrypted via our server. |
| Photos, videos, voice messages, files | Encrypted in transit | Encrypted on the way and stored in non-public storage — not end-to-end encrypted. |
| Metadata in direct chats | Encrypted in transit | Polls, shopping lists, file names, small preview images, transcripts and summaries are stored with the message entry and are not end-to-end encrypted. The server also sees who writes to whom and when — otherwise no message could be delivered. |
| Group and event chats | Encrypted in transit | Text and media are stored on the server without end-to-end encryption. Access is controlled by database permissions. |
| Voice and video calls | Encrypted in transit | Routed through our call provider LiveKit (USA), encrypted on the way (DTLS-SRTP). Not end-to-end encrypted and not recorded. |
| Push notifications | Encrypted in transit | Contain the sender's name but no message text. Delivered via Google (Android) or Apple (iOS). |
| Chat backup | Device + server | The backup file is encrypted with AES-256-GCM and stays on your device. Its key is stored in your account on the server — the two only come together after you sign in. |
| Archive (folders, text files, photos, videos) | With password: on device | Without a password: encrypted in transit and stored in non-public storage — not end-to-end encrypted. With a password (you set it yourself, from 3 characters): names, texts, photos and videos are encrypted on your device with AES-256-GCM before they reach the server. The key is derived from your password (PBKDF2, 600,000 rounds); the password itself is never stored. Without it nobody can read the contents — not even us. A long password protects much better than a short one. |
| Translate | Service provider | Only for messages that are not end-to-end encrypted, and only when you tap “Translate”: the text (up to 500 characters) is sent in plain text to MyMemory (Translated S.r.l., Italy). End-to-end encrypted messages are never translated. |
| Turn a voice message into text | Service provider | Only when tapped — for recipients only if the sender allowed it. The recording is sent to OpenAI (USA); the transcript is stored with the message without end-to-end encryption. |
| Summarise a transcript | Service provider | Only when tapped: the transcript text is sent to an AI service (Anthropic or OpenAI, USA). The summary is stored with the message. |
Retention periods
How long we keep what
Automatic clean-up jobs tidy the database regularly. Your server file also shows the periods for its core sections.
Account & sign-in
| Data | Kept for |
|---|---|
| Account, profile, contacts, settings | Until you delete your account |
| Active sessions (device, IP address, last activity) | Until you sign out on that device |
| Sign-up (IP address, device, check results) | 90 days |
| Sign-in attempts (IP address, email only as a hash) | 24 hours |
Messages & content
| Data | Kept for |
|---|---|
| Direct messages including metadata | Until both of you have deleted them — at the latest with either account |
| Group and event messages | Until they are deleted — at the latest with your account |
| Self-destructing messages | Once read |
| View-once photos and videos | A few minutes after opening |
| Chat images no message refers to any more | 30 days |
| Scheduled messages | Until delivered |
| Blind-chat messages | 7 days |
| Stories | Until they expire, at most 90 days |
| Offer & Search listings including photos | 30 days |
| Archive (folders, text files, photos, videos) — separate for every UIN | Until you delete it — at the latest with your account |
Logs & abuse protection
| Data | Kept for |
|---|---|
| The app's automatic error reports | 30 days |
| Activity log (e.g. searches) | 14 days |
| Counters against spam and overload | 1 hour to 7 days |
| Call invitations | 24 hours |
| Group call participation | 6 hours |
| Moderation log | 365 days |
| Hosting provider's access logs (outside the database) | 7 days |
| Automatic database backups | 7 days |
No automatic deletion yet
| Data | Kept for |
|---|---|
| Waitlist on this website (email address) | Until you ask us to delete it |
| Security events, reports sent via “Report a bug”, review history of profile changes, suspension records | No automatic period yet |
| Manual backups made before larger changes | Until we delete them |
Service providers
Who else sees data
We don't sell data, show no ads and include no advertising or analytics libraries. For individual features we work with these providers:
| Provider | What for | Which data | Location |
|---|---|---|---|
| Supabase | Database, sign-in, file storage, real-time delivery | Your account data — exactly what your server file shows | Servers in the EU (Ireland); US-based provider |
| Google Firebase Cloud Messaging | Push notifications on Android | Device token, sender's name, type of notification — no message text | USA |
| Apple Push Notification service | Push notifications and calls on iOS | Device token, sender's or caller's name — no message text | USA |
| LiveKit | Voice and video calls, voice channels | Audio and video during the call (encrypted on the way, not recorded), room and participant IDs, IP address | USA |
| OpenAI | Turning voice messages into text (only when tapped); automatic checks of new profile details, listings and group pictures for prohibited content | The recording; for checks the username, display name, bio and profile picture, or the listing’s text, city and photos, or the group picture | USA |
| Anthropic (or OpenAI, depending on setup) | Summarising a transcript (only when tapped); analysis of error reports by our team | The transcript text; for error reports you send via “Report a bug”: description, device details, log and your UIN | USA |
| MyMemory (Translated S.r.l.) | Translation (only when tapped, never for end-to-end encrypted messages) | The text to translate, up to 500 characters, in plain text | Italy |
| Google (Tenor) | GIF search | Search terms, IP address | USA |
| Cloudflare (Turnstile) | Protection against automated sign-ups | IP address, technical features of device and browser | USA |
| RevenueCat | In-app purchases | App user ID, purchase receipts from the app stores | USA |
Smaller technical requests
| Who | What for | What is transmitted |
|---|---|---|
| STUN servers (Nextcloud, sipgate, Telekom, 1&1 — Germany) | Setting up the local P2P chat connection | IP address |
| Relay server (TURN) | Only if no direct P2P connection is possible | The encrypted data stream is passed on; only IP addresses are visible |
| Google News | News in the news window | City or country and language — normally requested by our server, without your ID. If our server delivers nothing, the app asks Google News directly; Google then also sees your IP address. Article preview images come from Google servers. |
| Google (favicon service) | Small logos of news sources | IP address, address of the source |
| Open-Meteo (Switzerland) | City search in the news window | The place name you typed, IP address |
| CORS proxies (allorigins.win, corsproxy.io, codetabs.com) | Fallback for news, only if our server delivers none | IP address, the news source requested |
| Kleinanzeigen, mobile.de | Importing a listing by link (only when tapped) | The link you entered — requested by our server |
| LottieFiles, jsDelivr, unpkg | Animations, emoji images, map data | IP address |
| Apple (App Store) | Update notice on iOS | IP address, app ID |
| Google (Play Store) | Update notice on Android | App ID and version — via the Google Play services on your device |
| Have I Been Pwned (Australia) | Check by our team whether an email address appears in known data breaches | Only the first 6 characters of a hash — not the address itself |
Deletion
What happens when you delete
Deleting your account
In the app under Profile → Account → “Delete account”. Among other things, your profile, your messages (sent and received), files, friendships, groups you founded and your keys are deleted immediately. Instructions (German)
What runs out later
Some protection logs stay until their period ends, for example sign-up data (90 days) and the moderation log (365 days). Automatic database backups are overwritten after 7 days.
Individual content
Messages disappear from the server once both of you have deleted them. You can delete or switch off listings, profile details and location yourself at any time.
To be clear
A few tables do not have automatic deletion yet, and manual backups are not cleaned up immediately when an account is deleted. Both are listed above under “No automatic deletion yet”.
Our promise
What we never do
- Read your private texts. They are end-to-end encrypted; only your devices hold the key.
- Sell data or use it for advertising. There are no ads in AICQ.
- Include tracking or analytics services. The app contains no such libraries and this website sets no cookies.
- Ask for your phone number. You get your own AICQ number (UIN).
- Record calls. Audio and video are only transmitted, never stored.
- Make it hard to see your data. Your server file is free and needs no request.
As of 27 September 2026. This page describes the technical implementation. The legally binding text is the privacy policy (German). Questions: Support & contact.