Privacy Policy
mr.enzo is a messenger for iPhone with end-to-end encrypted chats and calls and an offline network that works without the internet. This policy explains, in plain words, what data the app and our server handle, why, for how long, and what you can do about it.
In short
- Your one-to-one messages, group and channel posts, attachments and calls are end-to-end encrypted. We cannot read or listen to them.
- To run the service we store your account (email address, username, display name, optional photo and bio), the people you add as contacts, your devices’ push tokens and the encrypted messages that are still waiting to be delivered.
- Stories are not end-to-end encrypted: our server stores them and shows them to other users for 24 hours.
- No advertising, no tracking, no third-party analytics or advertising SDKs, and we do not sell or share your data for advertising.
- You can delete your account in the app at any time.
1. Who is responsible
mr.enzo is developed and operated by an independent developer (“we”, “us”), who is the controller of the personal data described here. Contact for anything about privacy, including requests to exercise your rights: ajkzantokaev@gmail.com.
2. What we process and why
2.1 Your account
- Email address. You sign in with your email address and a one-time code we send to it. We use it to sign you in, to protect your account and to answer you. Other users who already know your email address can find your account by it — by typing it in search or with “Find friends” (see 2.4); we never show your email address to other users.
- Phone number — only for older accounts that were created with a phone number; people who know it can find such an account by it in the same way.
- Username, display name, profile photo and bio. These form your public profile. Any mr.enzo user can find you by username or display name and see this profile. Your profile photo is stored unencrypted and anyone who has its link can open it.
- Optional security settings: a cloud password (stored only as a hash) and its hint, a recovery email address, and a two-step verification secret with recovery codes. They are stored so we can check them when you sign in.
- Sessions. Sign-in tokens (stored as hashes), when they expire and a device label, and the time you were last online.
2.2 Messages, attachments and calls
- One-to-one chats are end-to-end encrypted on your device (Double Ratchet with X3DH key agreement). Our server passes the encrypted messages on and cannot decrypt them. If the recipient is offline, the encrypted message waits on our server until the recipient’s device downloads it and is then deleted.
- Groups and channels. Posts are end-to-end encrypted with keys shared only among members and are stored on our server in encrypted form so members can load the history. They are removed when their author deletes them, when the group’s auto-delete timer expires, when the group or channel is deleted, or when the author deletes their account. The group’s name, description, photo, list of members and their roles, and short service notices (for example “auto-delete turned on”) are stored unencrypted so the service can manage membership.
- Photos, videos, voice messages and files are encrypted on your device (XSalsa20-Poly1305) before upload. The key travels only inside the end-to-end encrypted message. Our server stores the encrypted file together with its size, upload time, uploader and recipient or group, so the recipients can download it. The server cannot decrypt it.
- Voice and video calls are end-to-end encrypted (DTLS-SRTP; each side signs its key fingerprint with its identity key). Our server only forwards the call set-up messages. Audio and video go directly between the devices or, when a direct connection is not possible, through our relay (TURN) server, which forwards the encrypted media without being able to decrypt it. We do not record calls. During a direct connection the other participant’s device can see your IP address. Your call history is kept only on your device.
- What the server necessarily sees. To deliver messages and calls, our server processes who is contacting whom, when, and how large a message is, and whether you are online. We do not keep a separate record of this beyond the delivery queues described above and the server logs described in 2.9. If you turn on “Hide sender in notifications”, one-to-one text messages are sent, where possible, with “sealed sender”: the sender is named only inside the encrypted envelope, so it is not stored with a message waiting for delivery and does not appear in the notification.
- Encryption keys. Your public keys are stored on our server so others can start encrypted conversations with you. Your private keys stay on your device.
2.3 Stories
A story (text or photo) is not end-to-end encrypted. Our server stores it and shows it for 24 hours to mr.enzo users who have you in their contacts, except people you blocked or who blocked you. After 24 hours it disappears from the feed. You can delete your story earlier.
2.4 Contacts
- Your mr.enzo contacts (the people you add in the app) are stored on our server as a list of accounts. We use it to restore your contacts on a new device and to decide who sees whose stories.
- Find friends from your address book is optional and runs only when you tap it and allow access to Contacts. The app then sends the phone numbers and email addresses from your address book over an encrypted connection (HTTPS) to our server, which compares them with registered accounts and returns the matches. The server does not store them, and they are not used for anything else. Names and other address-book details are never sent.
2.5 Notifications
We store the push tokens of your devices (including the VoIP token that lets calls ring) together with a random installation ID created by the app, to send notifications through the Apple Push Notification service. A notification shows the sender’s display name (a neutral title if you turn on “Hide sender in notifications”) and a generic text such as “New message”; message content never passes through Apple.
2.6 The offline network (Bluetooth and local Wi‑Fi)
While the offline network is on (it is on by default, in “Auto” mode), your iPhone announces your display name to nearby devices running mr.enzo over Bluetooth and Apple’s peer-to-peer Wi‑Fi, so people nearby can see it. Messages sent over the offline network are end-to-end encrypted. To reach the recipient they may be carried by other people’s devices for up to 24 hours, and your device may carry theirs; the carrying devices cannot read them. This traffic does not go through our server. You can turn the offline network off in Settings.
2.7 Link previews
If a message contains a link and link previews are on (you can turn them off in Settings), the app asks our server to open the page and return its title, description and image address. Our server therefore sees that link (not the rest of the message), and the website sees a request from our server. Your device then loads the preview image directly from the website, which sees your IP address. Our server keeps previews in memory for up to one hour.
2.8 Reports and blocks
- Reports. When you report a user, message, group, channel or story, we store the report: your account, the reported account and item, the reason, your optional comment and — because messages are end-to-end encrypted — the text of the messages you choose to include, which your device decrypts and sends only with the report. Reports are also emailed to our moderation mailbox. We keep reports as long as needed to handle them and to prevent repeated abuse, also after either account is deleted.
- Blocks. We store whom you blocked so the server can stop their messages, calls, stories and online status from reaching you. The record is deleted when you unblock the person or delete your account.
2.9 Diagnostics and server logs
- Diagnostics. The app sends technical events to our server — errors and warnings, connection and call set-up steps, and crash and hang reports that iOS provides (MetricKit). They are linked to your account ID so we can investigate problems, and are built not to contain message content or encryption keys.
- Server logs. Our servers log technical data about requests: IP address, time, the requested address (which may include a search term or a link you asked to preview), app and system version, your account ID for signed-in actions, and errors. We use logs only for security, abuse prevention and fixing problems. They are rotated automatically and overwritten, normally within about a month.
2.10 What stays on your device
Your message history, media, contacts and call history are stored on your iPhone. Deleting the app removes them from the device.
3. What we do not do
- We do not show ads and do not use your data for advertising.
- We do not track you across other companies’ apps or websites and do not use the advertising identifier.
- We do not include third-party analytics, advertising or tracking SDKs.
- We do not sell your personal data or share it for money.
4. Service providers and disclosure
- Hosting. Our servers (application, storage and call relay) run in a data centre in Frankfurt am Main, Germany.
- Apple delivers push notifications and provides crash diagnostics to the app.
- Google (Gmail) delivers the one-time sign-in codes by email and receives the report notifications of our moderation mailbox.
- Websites you link to receive the link-preview request described in 2.7.
We share data with nobody else, except when the law requires it (for example a valid order of a competent authority) or when it is needed to protect people from serious harm. Because of end-to-end encryption we cannot hand over the content of messages or calls.
5. How long we keep data
| Data | Kept |
|---|---|
| Account, profile, contacts, keys, push tokens, blocks | Until you delete your account; a push token also when it stops being valid or another account signs in on that device |
| Encrypted one-to-one messages waiting for delivery | Until the recipient’s device downloads them |
| Encrypted group and channel posts | Until deleted by the author, the auto-delete timer, deletion of the group, or the author’s account deletion |
| Encrypted attachments | As long as recipients need them to download; the server cannot decrypt them |
| Stories | 24 hours in the feed |
| One-time sign-in codes | Until used or expired (10 minutes) |
| Link-preview cache | Up to 1 hour, in memory |
| Server logs and diagnostics | Rotated automatically, normally about a month |
| Reports | As long as needed for moderation and to prevent repeated abuse |
6. Deleting your account
Open Settings → Delete Account in the app and confirm by typing your username. We then delete from our servers your account and profile, profile photo, contact list, push tokens, public keys, stories, blocks, the files you uploaded, your group and channel posts, and messages waiting for you. A group you created passes to one of its admins or, if there is none, to its longest-standing member; a channel you created passes to one of its admins or is deleted. What remains: reports (see 2.8), server logs until they are rotated, and messages you already sent, which stay on the recipients’ devices. If you cannot use the app, email ajkzantokaev@gmail.com from your account’s email address and we will delete the account for you.
7. Your choices and rights
You can change your profile at any time, turn off link previews and the offline network, hide the sender in notifications, and withdraw access to Contacts, the camera, the microphone or Bluetooth in iOS Settings. Depending on where you live (for example under the EU/UK GDPR), you have the right to access your data, correct it, delete it, receive it in a portable format, restrict or object to its processing, and withdraw consent at any time. Write to ajkzantokaev@gmail.com; we answer within one month. You may also complain to your data protection authority.
Legal bases under the GDPR: providing the service you asked for (contract) — account, messaging, calls, notifications, contacts, stories; our legitimate interests — security, abuse prevention, moderation of reports, diagnostics and logs; your consent — access to your address book for “Find friends” and other optional permissions; and legal obligations where they apply.
8. Children
mr.enzo is not intended for children under 13, and we do not knowingly collect data from them. If you believe a child under 13 uses mr.enzo, contact us and we will delete the account.
9. Security and international transfers
All connections to our server use TLS, and content is end-to-end encrypted as described above. No system is perfectly secure, but we work to protect your data and limit what we store. Our servers are in the European Union (Germany). Apple and Google may process the data they handle for us (section 4) in other countries, including the United States, under their own safeguards.
10. Changes
If we change this policy, we will publish the new version on this page and update the date above. If a change significantly affects how we use your data, we will tell you in advance, for example by email.
11. Contact
Questions or requests: ajkzantokaev@gmail.com.