Privacy Policy
Version 1.0 · Effective 14 July 2026 · Text correction: 27 August 2026
SaQura Messenger is a local-first, end-to-end-encrypted messenger. This policy explains what little information the app and our delivery server process. It describes the standard service operated by KyotoTech (“Hosted”, relay.saqura.de); where an organisation runs SaQura on its own server (“self-hosting”), that organisation is the controller for the communication passing through its server.
1. Controller and EU representative
KyotoTech LLC (合同会社KyotoTech), Kyō-machi 2-237-202, Fushimi-ku, Kyoto 612-8083, Japan. Managing Director: Christopher Batsch. Privacy contact: saqura@kyototech.jp.Our representative under Art. 27 GDPR is DataRep. You may contact DataRep in any EU/EEA member state or the UK/Switzerland at datarequest@datarep.com (please reference “KyotoTech; SaQura”) or via www.datarep.com/data-request.
SaQura can be run on an organisation’s own server (“self-hosting”). In that case the operating organisation is the controller for the communication passing through its server; this policy describes the standard service operated by KyotoTech (“Hosted”, relay.saqura.de).
2. Our principle: data minimisation, local-first and end-to-end encryption
SaQura Messenger is a local-first messenger: your messages, contacts and media live primarily and end-to-end encrypted on your device. We built the service so that KyotoTech is technically unable to read the content of your communication.
- End-to-end encryption (E2EE):all messages, media and calls are encrypted with the MLS standard (RFC 9420) combined with a quantum-safe hybrid scheme. Keys are generated and stay on the participants’ devices.
- Local encryption (at rest):the local data store is encrypted with AES-256-GCM; the device key resides in the device’s Secure Enclave / keychain.
- No account, no mandatory details: no e-mail address, phone number or registration is required to use the app. Your identity is a key pair generated on your device.
3. What data is processed
3.1 On your device (not with us)
Your identity (device key), messages, chats, contacts, media and settings are stored locally and encrypted. We have no access to them.
3.2 On the delivery server (relay relay.saqura.de)
To deliver messages, our relay processes only the data technically necessary for this:
- Encrypted message envelopes: stored opaquely (unreadable to us) and deleted after delivery (transient queue). We do not store message content permanently and cannot decrypt it.
- Encrypted large media (photos, videos, files over 256 KB): unlike text messages, large attachments cannot travel inside the message itself. They are cached on the relay end-to-end encrypted so that the recipient devices can fetch them — even if those devices only come online days later. The key for them travels solely inside the encrypted message and never reaches our server; to us the data is an undecryptable block of bytes. These caches are deleted automatically after 30 days (self-hosted organisations may set different periods; the app shows you the period actually in force under Profile → Data & storage).
- Routing / delivery metadata: a pseudonymous device fingerprint (public-key hash) and a push token, so that incoming messages can be delivered to and announced on the right device. We keep no plaintext address book and no social graph of your contacts.
- Aggregated usage counters (organisations only): for billable organisations the server counts message count / byte volume / deliveries per month (without content), for capacity and licence management.
3.3 Push notifications
For notifications we use the Apple Push Notification service (APNs). A push token for your device is transmitted to Apple and to our relay. Push messages are content-free wake signals (silent push) or carry no decryptable content; the app fetches the actual message encrypted and decides locally what to display.
3.4 Diagnostics / crash reports (only with your consent)
Error / diagnostic logs stay on your device by default. They are sent to KyotoTech support only when you explicitly trigger it. Such reports are redacted (technical events; no message content, contact / display names or location coordinates) and transmitted to support encrypted (only support can open them with its private key). Retention: up to 90 days, then automatic deletion.
3.5 Location data
A location is processed only when you actively start live location sharing in a chat. The location is transmitted end-to-end encrypted to the recipients you choose and ends automatically or as soon as you stop sharing.
3.6 In-app purchases (SaQura Pro)
Payments for optional Pro features are handled by Apple (App Store in-app purchase). From Apple we receive only a cryptographic proof of purchase (transaction identifier) to verify the unlock. We do not receive payment data (card details or similar).
3.7 What we do NOT do
- No tracking, no advertising, no third-party advertising / analytics SDKs.
- No sale and no disclosure of your data for advertising purposes.
- No access to message content — technically excluded by E2EE.
- No address-book upload.
4. Legal bases (Art. 6 GDPR)
- Performance of a contract (Art. 6(1)(b)): delivery of your messages, provision of the core functions.
- Consent (Art. 6(1)(a)): sending diagnostic reports, live location sharing, push notifications. Consent can be withdrawn at any time with effect for the future.
- Legitimate interest (Art. 6(1)(f)): operational security, abuse / spam prevention, service stability (in a data-minimising, pseudonymous form).
5. Recipients / processors
- Hosting: the relay server is operated at Hetzner Online GmbH, Germany (server location EU/Germany).
- Apple: APNs (push) and App Store in-app purchases (Apple Inc. / Apple Distribution International).
- There is no disclosure to advertising or data-broker networks.
Where required, data-processing agreements are in place (Art. 28 GDPR). Any transfer to third countries occurs only within Apple’s push / store infrastructure on the basis of the applicable safeguards (Standard Contractual Clauses).
6. Retention
- Message envelopes at the relay: transient — deleted immediately after delivery (or after a configurable retention period for organisations).
- Encrypted large media at the relay (over 256 KB): 30 days from upload, then automatic deletion (configurable differently for organisations).
- Local data:until you delete it. “Delete identity & all data” performs a cryptographic erase (the local key is destroyed; the ciphertext is irrecoverable).
- Diagnostic reports: up to 90 days.
- Routing metadata / push token: as long as your device is registered, or until you sign out / the token becomes invalid.
7. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21), as well as the right to withdraw consent you have given (Art. 7(3)). Because of the local-first / E2EE architecture, most personal data lives only on your device and can be viewed and deleted there directly. For matters concerning server-side data, contact saqura@kyototech.jp or our EU representative (Section 1).
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR) in the EU/EEA member state of your habitual residence, place of work or the place of the alleged infringement.
8. Children
SaQura is not directed to children under the age of 16. We do not knowingly collect data from children under that age.
9. Changes to this policy
We update this privacy policy when the service or the legal situation changes. The current version is available in the app and at saqura.de/messenger/privacy.
10. Contact
Privacy enquiries: saqura@kyototech.jp · Controller: KyotoTech LLC, Kyō-machi 2-237-202, Fushimi-ku, Kyoto 612-8083, Japan.