Privacy
The short version
No trackers, no analytics, no advertising, no cookies for tracking. We collect as little as possible, and we cannot read your messages.
What we collect
- Request form: your atproto handle only. We resolve it to your public identifier (a DID) to add you to the invite list. No email, no name, no password.
- This website: nothing beyond ordinary server request logs. No cookies, analytics, or third-party scripts.
- The demo (app.didcomm.at):
- Your messaging keys are generated and stored in your browser; they never reach our servers.
- Your keyPackage record is written to your own data repository (PDS), which you control — not to us.
- Sign-in uses your existing account's authorization (OAuth); no password reaches us.
- Our mediators relay messages and can see routing metadata — which messaging keys exchange messages, and roughly when — but not message content, which is end-to-end encrypted.
What we do not have
Message content (it is end-to-end encrypted), your email, your password, and any tracking or advertising profile.
Retention & your control
- Waitlist handles are kept until reviewed; ask us to remove yours at any time.
- You can remove your published keyPackage from your repository at any time (the demo's un-enroll action), which stops others from discovering you.
- This is a proof of concept; demo data may be reset without notice.
Where we operate
The service is operated in the European Union, and EU data protection law (GDPR) applies.
The .at domain is wordplay on "atproto", not a location.
Contact
Marat Shakirov, marat@minbash.com. See the imprint.