Privacy Policy

Last updated: 10 September 2026

1. Who we are

GuardMessage is operated by Avacod s.r.o., a company registered in Slovakia, [registered office and company ID to be inserted]. We are the data controller for the personal data described in this policy.

Privacy contact: privacy@guardmessage.com

2. The short version

  • Your message content, files, voice notes, location and your guardians' contact details are encrypted before they are stored.
  • Some things are not encrypted, and section 4 says exactly which.
  • No advertising, no analytics, no behavioural tracking, no data brokers.
  • Servers and encryption keys are in the EU (Germany).

3. What GuardMessage does

You write a message, choose people you trust ("guardians") and set a check-in deadline. While you confirm you are fine, the message stays locked. If the deadline passes without a check-in, our servers send your guardians a link, which they open with a one-time code. Because delivery must work when your phone does not, this cannot be an end-to-end encrypted product: our servers necessarily hold the keys needed to reveal your message to a guardian at the right moment. We are telling you this plainly rather than implying stronger protection than we provide.

4. What we collect, and what is encrypted

Account data — not encrypted

Your e-mail address (required), and optionally a phone number, a display name and your language. Also sign-in and account-creation timestamps. Your display name is shown to guardians so a delivered message is not anonymous.

Switches

The title you give a switch is stored unencrypted, together with its deadline, check-in interval, channel settings and timestamps — we need these to run the countdown and show you your list.

Because of this, avoid putting sensitive information in the title. The message body itself, and everything attached to it, is encrypted.

The message text, documents, photos and voice notes are encrypted with a key that is unique per item and cryptographically bound to your account and that specific switch. Files are stored as ciphertext under a random identifier — your original filename is never used as the storage name, though the filename itself is kept unencrypted so it can be displayed.

Guardians

The phone number and/or e-mail address of each guardian is encrypted. The label you give them (for example "Brother") and a masked hint such as +421 *** 555 or j***@example.com are stored unencrypted so you can tell your guardians apart in the app.

Location — optional, off by default

If you switch it on, the app captures a single most recent position (latitude, longitude, accuracy and time) and stores it encrypted against your armed switches, so it can be shown to a guardian if a switch fires. We keep only the latest fix — there is no location history and no background tracking. You can delete it at any time, and turning the option off deletes it.

Technical and security data — not encrypted

We record an IP address and device/browser identification when you click a sign-in link, when a guardian opens a delivery link, and whenever encrypted content is decrypted. That last one is a security audit trail: it is how we could show who opened what, and when. Your active-sessions screen stores a readable device label derived from the same identification. If you enable push notifications, a per-device notification token is stored.

Codes and links — stored only as hashes

Sign-in links, guardian PINs, guardian verification links, account-deletion codes and step-up codes are stored only as irreversible cryptographic hashes. We cannot read them back, and a copy of our database does not let anyone reconstruct them.

Biometrics

Face ID, Touch ID and fingerprint checks happen on your device. We never receive biometric data. Passkeys store only a public key and an authenticator identifier.

5. What we do not do

  • No advertising, and no advertising identifiers.
  • No analytics, crash-reporting or behavioural-profiling SDKs in the app.
  • No selling or sharing of personal data with data brokers.
  • No automated decision-making that produces legal effects for you.
  • Plaintext message content is never written to our logs.

6. Who else processes your data

We use a small number of providers to run the service. They act on our instructions.

ProviderWhat it doesWhat it receives
Hetzner (Germany)Servers and encrypted file storage All stored data, in the form described above
Amazon Web Services — KMS (Frankfurt)Encryption key management Wrapped encryption keys and identifiers only. Never your message content, contacts or coordinates
TwilioSMS delivery The recipient's phone number and the text sent — a guardian notice with your display name and a link, a one-time code, or your own reminder containing a switch title
ResendE-mail delivery The recipient's e-mail address and the message sent (sign-in link, one-time code, guardian notice, reminder)
Google — Firebase Cloud MessagingPush notifications Your device notification token and the notification text. Using push also means Google receives a device installation identifier
Apple, GoogleSign in with Apple / Google, only if you choose it The sign-in happens with them; we receive a provider identifier and a verified e-mail address

7. What a guardian actually receives

When a switch fires, your guardian receives an SMS or e-mail containing your display name and a link — not the message itself. The content is revealed only after they enter a one-time code sent separately, and only through that link, which expires and can be opened a limited number of times.

8. Legal bases (GDPR Article 6)

  • Performance of a contract — running your account and delivering your switches as you configured them.
  • Consent — location, notifying a guardian that you added them, and push notifications. You can withdraw consent at any time in the app.
  • Legitimate interests — security, abuse and cost-abuse prevention, and the decryption audit trail that protects your content.
  • Legal obligation — where the law requires us to keep or disclose something.

9. How long we keep data

  • Account and switches — until you delete them, or delete your account.
  • Location — only the most recent fix, deleted when you turn the option off or delete it.
  • One-time codes and links — minutes to days, then purged automatically.
  • Sessions — 24 hours of inactivity, and 14 days maximum regardless of use.
  • Security audit records — kept after account deletion, but with the IP address and device identification erased, so they can no longer be connected to you.

Deleting your account in the app (confirmed with a code sent to your e-mail) permanently removes your profile, switches, message content, files, guardian records, devices and sessions. Deletion is immediate and cannot be undone.

10. Your rights

Under the GDPR you may request access to your data, correction, erasure, restriction of processing, portability, and you may object to processing based on legitimate interests. You can export your data yourself in the app, and delete your account yourself at any time.

Write to privacy@guardmessage.com to exercise any of these rights. If you are unhappy with how we handle it, you may complain to the Slovak supervisory authority, Úrad na ochranu osobných údajov Slovenskej republiky (dataprotection.gov.sk).

11. Security

Content is protected with envelope encryption: each item gets its own key, which is itself encrypted by a master key held in a hardware-backed key management service and never stored next to your data. Each key is cryptographically bound to your account, the specific switch and the purpose, so a key cannot be reused to decrypt something it was not issued for. Traffic is protected with TLS. Guardian links expire, are limited in how many times they can be opened, and require a one-time code.

No system is perfect. If we ever discover a breach affecting your personal data, we will notify the supervisory authority and, where the risk to you is high, you directly.

12. Transfers outside the EU

Our servers and encryption keys are in the European Union (Germany). Some providers named in section 6 may process data outside the European Economic Area; where they do, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision.

13. Children

GuardMessage is not intended for people under 18, and we do not knowingly collect their data.

14. Changes to this policy

We will update this page and change the date at the top. If a change materially affects how we handle your data, we will tell you in the app before it takes effect.

15. Contact

privacy@guardmessage.com
Avacod s.r.o., [registered office to be inserted]