Privacy Policy

Last updated: 28 September 2026

mr.enzo is a messenger for iPhone with end-to-end encrypted chats and calls and an offline network that works without the internet. This policy explains, in plain words, what data the app and our server handle, why, for how long, and what you can do about it.

In short

  • Your one-to-one messages, group and channel posts, attachments and calls are end-to-end encrypted. We cannot read or listen to them.
  • To run the service we store your account (email address, username, display name, optional photo and bio), the people you add as contacts, your devices’ push tokens and the encrypted messages that are still waiting to be delivered.
  • Stories are not end-to-end encrypted: our server stores them and shows them to other users for 24 hours.
  • No advertising, no tracking, no third-party analytics or advertising SDKs, and we do not sell or share your data for advertising.
  • You can delete your account in the app at any time.

1. Who is responsible

mr.enzo is developed and operated by an independent developer (“we”, “us”), who is the controller of the personal data described here. Contact for anything about privacy, including requests to exercise your rights: ajkzantokaev@gmail.com.

2. What we process and why

2.1 Your account

2.2 Messages, attachments and calls

2.3 Stories

A story (text or photo) is not end-to-end encrypted. Our server stores it and shows it for 24 hours to mr.enzo users who have you in their contacts, except people you blocked or who blocked you. After 24 hours it disappears from the feed. You can delete your story earlier.

2.4 Contacts

2.5 Notifications

We store the push tokens of your devices (including the VoIP token that lets calls ring) together with a random installation ID created by the app, to send notifications through the Apple Push Notification service. A notification shows the sender’s display name (a neutral title if you turn on “Hide sender in notifications”) and a generic text such as “New message”; message content never passes through Apple.

2.6 The offline network (Bluetooth and local Wi‑Fi)

While the offline network is on (it is on by default, in “Auto” mode), your iPhone announces your display name to nearby devices running mr.enzo over Bluetooth and Apple’s peer-to-peer Wi‑Fi, so people nearby can see it. Messages sent over the offline network are end-to-end encrypted. To reach the recipient they may be carried by other people’s devices for up to 24 hours, and your device may carry theirs; the carrying devices cannot read them. This traffic does not go through our server. You can turn the offline network off in Settings.

2.7 Link previews

If a message contains a link and link previews are on (you can turn them off in Settings), the app asks our server to open the page and return its title, description and image address. Our server therefore sees that link (not the rest of the message), and the website sees a request from our server. Your device then loads the preview image directly from the website, which sees your IP address. Our server keeps previews in memory for up to one hour.

2.8 Reports and blocks

2.9 Diagnostics and server logs

2.10 What stays on your device

Your message history, media, contacts and call history are stored on your iPhone. Deleting the app removes them from the device.

3. What we do not do

4. Service providers and disclosure

We share data with nobody else, except when the law requires it (for example a valid order of a competent authority) or when it is needed to protect people from serious harm. Because of end-to-end encryption we cannot hand over the content of messages or calls.

5. How long we keep data

DataKept
Account, profile, contacts, keys, push tokens, blocksUntil you delete your account; a push token also when it stops being valid or another account signs in on that device
Encrypted one-to-one messages waiting for deliveryUntil the recipient’s device downloads them
Encrypted group and channel postsUntil deleted by the author, the auto-delete timer, deletion of the group, or the author’s account deletion
Encrypted attachmentsAs long as recipients need them to download; the server cannot decrypt them
Stories24 hours in the feed
One-time sign-in codesUntil used or expired (10 minutes)
Link-preview cacheUp to 1 hour, in memory
Server logs and diagnosticsRotated automatically, normally about a month
ReportsAs long as needed for moderation and to prevent repeated abuse

6. Deleting your account

Open Settings → Delete Account in the app and confirm by typing your username. We then delete from our servers your account and profile, profile photo, contact list, push tokens, public keys, stories, blocks, the files you uploaded, your group and channel posts, and messages waiting for you. A group you created passes to one of its admins or, if there is none, to its longest-standing member; a channel you created passes to one of its admins or is deleted. What remains: reports (see 2.8), server logs until they are rotated, and messages you already sent, which stay on the recipients’ devices. If you cannot use the app, email ajkzantokaev@gmail.com from your account’s email address and we will delete the account for you.

7. Your choices and rights

You can change your profile at any time, turn off link previews and the offline network, hide the sender in notifications, and withdraw access to Contacts, the camera, the microphone or Bluetooth in iOS Settings. Depending on where you live (for example under the EU/UK GDPR), you have the right to access your data, correct it, delete it, receive it in a portable format, restrict or object to its processing, and withdraw consent at any time. Write to ajkzantokaev@gmail.com; we answer within one month. You may also complain to your data protection authority.

Legal bases under the GDPR: providing the service you asked for (contract) — account, messaging, calls, notifications, contacts, stories; our legitimate interests — security, abuse prevention, moderation of reports, diagnostics and logs; your consent — access to your address book for “Find friends” and other optional permissions; and legal obligations where they apply.

8. Children

mr.enzo is not intended for children under 13, and we do not knowingly collect data from them. If you believe a child under 13 uses mr.enzo, contact us and we will delete the account.

9. Security and international transfers

All connections to our server use TLS, and content is end-to-end encrypted as described above. No system is perfectly secure, but we work to protect your data and limit what we store. Our servers are in the European Union (Germany). Apple and Google may process the data they handle for us (section 4) in other countries, including the United States, under their own safeguards.

10. Changes

If we change this policy, we will publish the new version on this page and update the date above. If a change significantly affects how we use your data, we will tell you in advance, for example by email.

11. Contact

Questions or requests: ajkzantokaev@gmail.com.