publicego

Privacy

Privacy Policy

This policy explains what personal data publicego processes, why we process it, and the rights available to you.

Last updated: 15 July 2026 · Version 2026-07-15

The controller within the meaning of the General Data Protection Regulation (GDPR) is: Kai Wersich c/o GAM Pappelallee 64 10437 Berlin Germany Email: datenschutz@publicego.com

No data protection officer has been appointed because there is currently no statutory obligation to do so.

This Privacy Policy applies to the publicego web application, mobile app, and related services. We process personal data only where necessary to provide, communicate about, secure, and improve the service.

publicego currently uses no advertising or audience analytics, no advertising profiling, and no tracking cookies. Technically necessary information is stored in the browser or on the device, including session tokens, language and appearance preferences, the active ego, push tokens, and locally required key material.

  • Account and registration data: email address, display name, hashed password, selected language, acceptances, and account creation and update timestamps
  • Authentication and session data: session tokens, login timestamps, and Apple or Google account links used for social login
  • Ego, profile, and relationship data: egos, handles, profile attributes, circles, memberships, contacts, invitations, blocks, and permissions
  • Content and interactions: encrypted posts, moments, comments, chats, media, calendar events, and poll text, plus required metadata, reactions, votes, attendance responses, and read status
  • Report and moderation data: reporting ego, reported target, report timestamp, report content encrypted for the moderation team, and processing status
  • Device and encryption data: device identifiers, public device keys, encrypted key envelopes, key versions, and recovery information
  • Communication and notification data: email address, registration, password or deletion confirmation messages, push tokens, platform, and notification preferences
  • Technical data: IP address, date and time, requested resource, status code, client and device information, and security and error logs

We process account, profile, relationship, content, communication, and feature data to register and authenticate users and provide requested features. The legal basis is Article 6(1)(b) GDPR.

We process technical logs, rate limits, blocks, reports, moderation data, and audit data for system security, abuse prevention, enforcement, and reliability. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is operating a safe and reliable service. Where processing is necessary to comply with the law, Article 6(1)(c) GDPR applies.

We send push notifications only after activation or the relevant system permission has been granted. Depending on the implementation, the legal basis is Article 6(1)(a) or (b) GDPR. Consent may be withdrawn at any time through the device or app settings with future effect.

Content in circles and chats—including related media, profile information within encrypted contexts, event descriptions, and poll options—is generally encrypted on the device and decrypted only on authorised recipients’ devices. The server stores encrypted payloads and the metadata required for delivery, permissions, synchronisation, and abuse prevention.

publicego does not possess private device keys and ordinarily cannot read encrypted content or reconstruct lost keys. You are therefore responsible for recovery keys and device approvals. When reporting content, the reporting user deliberately creates a separate snapshot encrypted for the moderation team so that the report can be reviewed.

For email registration, we store passwords only as cryptographic hashes. Verification, password-reset, and account-deletion codes are time-limited and are likewise stored only in hashed form.

When you sign in with Apple or Google, we receive in particular a unique provider identifier, email address, and, where available, a display name. The provider’s own privacy terms also apply. Account-related emails are sent through our email service provider.

We use Google Firebase Cloud Messaging for web push and the Apple Push Notification service for iOS push. The relevant provider receives the push token, platform, technical delivery data, and necessary notification content. Push can be disabled at any time in the system or app settings.

If you voluntarily add an invitation as an Apple Wallet pass, Apple Wallet processes the invitation and pass data contained in it. This feature is optional, and Apple’s terms and privacy information additionally apply to Apple’s processing.

The application, database, and core infrastructure are hosted by Hetzner Online GmbH in Germany. Transactional email is delivered through Strato GmbH. We use Amazon S3 in EU region eu-west-1 (Ireland) for encrypted media and Amazon CloudFront for delivery.

Other recipients may include Apple and Google for social login and push services. Within publicego, other users receive access only in accordance with the circles, relationships, and permissions you select. The moderation team receives access to report data where required to review a report. We otherwise disclose data only where legally required or with your consent.

For Amazon, Apple, and Google, processing or support access outside the EU or EEA cannot be ruled out. Where required, we rely on a European Commission adequacy decision, including the EU–US Data Privacy Framework for certified US recipients, or on Standard Contractual Clauses and supplementary safeguards under Articles 44 et seq. GDPR.

  • Account data and associated content: generally for the life of the account; following confirmed account deletion, the account and associated data are removed from the active system unless legal duties or overriding claims require retention
  • Sessions and push tokens: until expiry, revocation, logout, device removal, or deactivation of the feature
  • Verification, reset, and deletion codes: until expiry or completion of the process, generally ten minutes
  • Moments, invitations, and other time-limited features: according to their duration and afterwards only where technically or legally necessary
  • Report, moderation, and audit data: for as long as required to review the matter, prevent abuse, or document action taken
  • Server and security logs: generally up to 30 days, or longer where required for a security incident or legal evidence
  • Backups: until routinely overwritten; they remain blocked from ordinary access in the meantime

Subject to the statutory requirements, you have rights of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20), and objection (Article 21). You may withdraw consent at any time with future effect. To exercise your rights, email datenschutz@publicego.com.

You may also lodge a complaint with a data protection authority, in particular the Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59–61, 10555 Berlin, Germany, mailbox@datenschutz-berlin.de, or the authority at your habitual residence.

Data marked as required for registration, authentication, and core features is necessary for the contract. Without it, publicego cannot be provided or can be provided only in a limited form. We do not use solely automated decision-making, including profiling, within the meaning of Article 22 GDPR.

We update this policy when features, providers, or legal requirements change. We will provide appropriate notice of material changes. The version published at the relevant time applies.