Privacy & transparency · Compliance & policies

GDPR data request (EU and UK)

Exercise your data-protection rights at Private.Ki. Almost every right is a control in the app, under Settings → Security and privacy → Privacy and data.

WiA·6 min·Updated 9 Oct 2026·Verified against app release 2026.09

Most data-protection rights are controls in the app, not requests you have to send anyone. They sit in one place: Settings → Security and privacy → Privacy and data. You can see every category of data held under your account, download a copy of what the server can read, pause the account, delete it, and withdraw the two consents we store.

This page says which control answers which right, and what to do in the cases the app cannot settle by itself.

Use this page if
  • you have a Private.Ki account, or we hold data about you, and
  • you want to exercise a right under the EU GDPR or the UK GDPR.
Do not use this page if
  • you have a support question — contact support;
  • you want to report abuse or a security issue — report abuse;
  • your account is locked or suspended — start here;
  • your request is not about data protection at all.

Start in the app

  1. Open Settings. Click your name at the bottom-left of the app, then Settings.
  2. Go to Security and privacy. Privacy and data is the last row.
  3. Pick what you need. The screen has three groups: Your data, Your account and What you have agreed to.

Everything you do there is recorded as the request it is — opening What we hold about you is an access request, pausing is a restriction of processing — so you do not have to tell us separately that you exercised a right.

You need to be able to sign in

The controls act on the account you are signed in to, which is how we know the request comes from its owner. We hold no name and no identity document to check you against. If you cannot sign in, see Delete your account for the route that does not need a session, or write to support.

Choose your right

I want to know what you hold about meRight of access — Article 15

Open What we hold about you. It lists every category stored under your account and counts each one at the moment you open it — messages and threads, attachments, Drive files, signatures, the people you have written to, your keys, devices signed in, security keys, push registrations, sending limits and the operator records that mention your account.

Each row says how long that category is kept, and rows we cannot read are labelled as encrypted. The list is generated from the database, not written down in advance, so it cannot drift from what is actually there.

In the app: Settings → Security and privacy → Privacy and data → What we hold about you

I want a copy of my dataRight to data portability — Article 20

Open Download my data and press Prepare the file. The server assembles one small JSON file: your email address, display name, settings, receiving aliases, devices signed in, what you have agreed to, and the operator records that mention you. The prepared file is removed from the server again after the number of hours the screen states.

Your mail, chats, attachments and Drive files are not in it, and not because they were left out. They are encrypted with your key, so the server holds ciphertext it cannot assemble into anything readable. Each message can be saved from the app itself with Show original, which gives you the message as a file — see Show original.

In the app: Settings → Security and privacy → Privacy and data → Download my data

Something you hold about me is wrongRight to rectification — Article 16

Nearly everything we hold is something you entered yourself, so you can correct it in Settings:

If something you cannot reach is wrong, write to support from the account and say what is incorrect.

I want everything to stop, but not be deletedRight to restriction of processing — Article 18

Use Pause my account. Nothing goes out while it is paused: no mail, no chat messages, no calls, no invitations, and your public key stops being published, so nobody can look it up to write to you encrypted.

Mail addressed to you still arrives and is stored, and you can read your mailbox as before. Nothing is deleted, and you can switch the account back on from the same screen at any time.

In the app: Settings → Security and privacy → Privacy and data → Pause my account

I want my account and my data deletedRight to erasure — Article 17

Use Delete my account. It asks twice: the first screen says what deletion reaches, the second asks you to type your email address. Then everything stored for the account is wiped — mail, chats, attachments, Drive files, signatures, your keys, your devices and your settings — every device is signed out, and your email address stops working.

Two things it cannot reach, both stated on the screen itself:

  • Messages you already sent are in other people's mailboxes, encrypted to their keys. Deleting your account does not remove them and we cannot take them back.
  • Operator records that mention the account are kept for as long as the audit trail is kept, then deleted. They hold the account id and what was done — never an address and never message content.

Your email address is not released afterwards: the empty record stays so that the handle cannot be registered again, by you or by anyone else.

If you cannot sign in, see Delete your account for the route that works without a session.

In the app: Settings → Security and privacy → Privacy and data → Delete my account

I object to you processing my dataRight to object — Article 21

The only processing we do is running the service you signed up for: delivering and storing your encrypted mail and chats, and keeping the service free of abuse. We do not profile you, do not advertise and do not sell data, so there is no separate processing to object to.

In practice an objection means one of the two controls above: Pause my account stops everything going out and keeps your data, Delete my account removes it. If you mean something else, write to support and say what.

I want to withdraw a consentWithdrawal of consent — Article 7(3)

Two consents are stored on the server, and both are switches under What you have agreed to:

  • Publish my public key so others can encrypt to me. Turning it off removes your key from the public directory immediately; a lookup then answers exactly as it does for a name nobody holds. Mail inside Private.Ki stays encrypted either way.
  • Browser notifications. Turning it off here removes every browser you have registered, not only this one.

Your recovery email address is optional too and can be removed in Settings.

In the app: Settings → Security and privacy → Privacy and data → What you have agreed to

A decision about me was made automaticallyAutomated decisions — Article 22

We take no automated decisions that produce legal effects or anything similar. What is automated is abuse prevention: outgoing mail is checked against blocklists and a few link rules, and sending limits apply to new accounts. A check can refuse one message or put a strike on an account — see Why am I rate-limited?.

If one of those refusals affected you and you think it was wrong, write to support and ask for it to be looked at by a person. We record that as a request for human review.

If the app cannot settle it

Write to support from the Private.Ki account the request concerns. Writing from the account is how we check that the request comes from its owner. Say which right you are exercising and what you want. We answer within the one-month period both regulations set, and tell you if a complex request needs longer.

Our representatives under Article 27

Private.Ki is not established in the EU or the UK, and has appointed representatives in both.

EU representative (Article 27 GDPR) Europe Services, SE, Na Čečeličce 425/4, 150 00 Prague 5, Czech Republic [email protected]

UK representative (Article 27 UK GDPR) REP27 LTD, a company registered in England and Wales, no. 17385889 [email protected]

Data subjects and supervisory authorities may contact our representatives on any matter relating to the processing of personal data.

When to write to them, and when not

Please contact a representative only about data protection, and only when you could not settle the matter with the controls described above or by writing to support. They cannot help with support questions, abuse reports, locked accounts or anything else about the service.

Complaints

If you believe we have not handled your data lawfully, you may lodge a complaint with the supervisory authority of the country you live or work in — in the UK, the Information Commissioner's Office. You may do that whether or not you have contacted us first.

Common questions

Do I have to use this page to make a request?

No. The controls described above are the request. The page exists so you can find the right one, and so you know who to write to for the rest.

Why can you not send me my mail as a readable export?

Because we cannot read it. Message content is encrypted on your device with a key we do not hold, so a server-side export would be a pile of ciphertext. Everything readable is already in your app, and each message can be saved with Show original.

Does deleting my account delete the messages I sent other people?

No. Those copies are in their mailboxes, encrypted to their keys. Nothing on our side can take them back. The same is true in reverse for messages other people sent you.

How do you verify that a request is mine?

By the account. We hold no name, no phone number and no identity document, so the proof is being signed in — or, if you cannot sign in, writing from the recovery address set on the account. This is also what stops somebody else from deleting your account.

Article privacy/data-request