GDPR (EU and UK) compliance
How Private.Ki meets the EU GDPR and the UK GDPR — data minimisation, encryption, your rights as a data subject and how to exercise them.
Private.Ki is designed to comply with the EU General Data Protection Regulation (GDPR) and with the UK GDPR together with the UK Data Protection Act 2018. Private.Ki is not based in the European Union or the United Kingdom, but the service and its policies were built around the GDPR's requirements from the start, and the same standard is applied to every user regardless of where they live.
The UK GDPR is, in practice, near-identical to the EU GDPR; the main difference is that it is enforced by the UK Information Commissioner's Office (ICO) rather than by EU authorities. Everything below applies to both.
How Private.Ki meets the requirements
Privacy by design and data minimisation. You can sign up with a username, a display name and a password. We do not ask for a phone number, a real name or a postal address. A recovery email address is optional and is stored only as an Argon2 hash. Because the password is handled with the OPAQUE protocol and the passphrase never leaves your device, the identifying information we actually hold about you is close to the minimum: your username and the metadata needed to deliver your mail. The full inventory is in What our server can and cannot see.
Encryption as a technical measure. The GDPR calls for appropriate technical and organisational measures, and names encryption explicitly. All message content — bodies, attachments, voice messages, subject lines — is end-to-end encrypted between Private.Ki users and stored only as ciphertext. In the event of a data breach, message content would be unintelligible to anyone without the recipient's private key and passphrase.
Purpose limitation and lawful basis. We process your data to provide the service you signed up for: encrypted email and chat. That is the lawful basis. We do not profile you, do not serve advertising, and do not process your data for any other purpose. If that ever changed, we would ask for your consent first.
No sale of data. Private.Ki does not monetise personal data. Our users, not advertisers, are our customers.
Breach notification. If a breach involving personal data were to occur, affected users would be informed as the GDPR requires.
Your rights as a data subject
Under both regulations you have the right to:
| Right | What it means at Private.Ki |
|---|---|
| Access | Ask what personal data we hold about you. Because most data is encrypted to your key, the readable part is the account information listed in What our server can and cannot see — and your messages are already accessible to you in the app. |
| Rectification | Correct inaccurate data. You can change your display name yourself; a username change is possible in limited cases. |
| Erasure | Have your data deleted. There is no self-service delete button in the app yet; contact support from your account and we will delete the account and everything stored under it. |
| Restriction and objection | Ask us to limit processing. Since the only processing is delivering your mail and chats, this in practice means suspending or closing the account. |
| Portability | Receive your data in a usable form. You can view the original of any email and download it, and export your public key. |
| Withdraw consent | Remove optional data at any time — for example, remove your recovery email in Settings. |
We cannot decrypt your messages, so we cannot hand you a readable export from the server side, recover a lost passphrase, or restore mail you deleted. Everything readable lives on your device, unlocked by you.
How to exercise your rights
- Write to support from the Private.Ki account the request concerns — see Contact support. Writing from the account is how we verify that the request comes from its owner; we hold no name or ID document to check against.
- State which right you are exercising and, for erasure, confirm that you understand all data under the account will be deleted and cannot be recovered.
- We respond within the one-month period the GDPR sets, and tell you if we need longer for a complex request.
If you believe we have not handled your data lawfully, you have the right to lodge a complaint with your national data-protection authority — in the UK, the ICO.
Common questions
Where is my data stored?
On servers operated by Private.Ki. Private.Ki is not based in the EU or the UK; the safeguard that makes cross-border storage acceptable is that message content is encrypted to your key and cannot be read on those servers.
Do you use cookies or trackers subject to consent rules?
The app uses only the storage it needs to keep you signed in. The public website and help center use Matomo for page-view statistics — see Third-party services for how to avoid it.
Is a message from me to someone else "their" personal data too?
Yes, and it is protected the same way: encrypted to their key on your device, unreadable to us.