📣 Notificatie App

Privacy notice

This notice is available in English and Dutch. If the two versions ever differ, the Dutch version is authoritative.
Deze verklaring is beschikbaar in het Engels en het Nederlands. Als de twee versies ooit verschillen, is de Nederlandse versie leidend.

What this app stores

Your account details (username, email, display name), the messages and files you send in ordinary (non-encrypted) conversations, and standard operational data (device registrations for push notifications, login history for security purposes).

End-to-end encrypted conversations

A conversation that is end-to-end encrypted - which new conversations are by default, see below - is protected using the Signal Protocol. For an encrypted conversation, this server never holds a private key, session state, or message plaintext - it only relays opaque, already-encrypted data between participants' own devices. We structurally cannot read an encrypted conversation's content, including in response to a request from us, a government, or anyone else, unless the mechanism described further below applies.

Encryption is on by default

A new direct (1:1) or group conversation is end-to-end encrypted by default. You can choose not to encrypt a specific conversation when you start it; encryption cannot be turned on afterward for a conversation that started without it, since there is no history to retroactively protect.

Where end-to-end encryption is not available

Encryption does not apply everywhere in this app. Here is the complete, current list.

Never encrypted, by design:

Not currently available in the web app (mobile app only):

Not yet available within an encrypted conversation on ANY platform, even though available in a regular conversation:

Link previews in encrypted conversations: an exception to "the server never sees content"

When you send a link in an end-to-end encrypted conversation, we can show a preview card (title, description, image) for it. On the mobile app, your device fetches that preview data directly - the server is never involved and never sees the link. On the web app, your browser cannot do that same direct fetch for an arbitrary third-party site (a technical browser restriction called CORS), so instead your browser asks this server to fetch that one URL on its behalf, and the server sends the resulting preview back before your message is encrypted. This means that, for that one request, the server transiently sees the URL you are about to send - and only the URL, never your message text, never who you are sending it to, and never any other part of the conversation, all of which stay end-to-end encrypted throughout and never reach the server unencrypted. Nothing about this request is stored; it exists only long enough to fetch and return the preview. Link previews are OFF by default; you can turn them on or off at any time in Settings, and while off, no URL from your encrypted conversations is ever sent to the server this way, on web or mobile.

Conversation review capability

This app includes a standing, disclosed capability: an administrator may mark a specific direct or group conversation - encrypted or not - as under review, for purposes such as responding to a report of abuse or a legal obligation. For an end-to-end encrypted conversation specifically:

Support conversations and broadcast channels are never end-to-end encrypted in the first place, by design - their whole purpose already depends on being readable by the agents/admins who staff them, which is disclosed by what those features visibly are, not a hidden exception to encryption.

Questions

If anything here is unclear, contact the operator of this instance through the support channel available in the app.