Privacy policy

Last updated: 24 August 2026

This is an English translation. The original is the German Datenschutzerklärung.

Draft. This text truthfully describes what the app does today. It has not yet been reviewed by a lawyer, and must be checked by someone qualified in data protection law before the app is published in the App Store or on Google Play.

In short

Calyvro doesn't ask for your name. To sign up, we need an email address and a password; in the app you appear under a pseudonym you choose yourself. You can also upload a profile picture: it's voluntary, you can remove it at any time, and you should know that a photo of you undoes the pseudonymity that everything else in this app protects. There is no advertising, there are no analytics tools, and no data is sold. All servers are in Germany and all files are kept in the European Union, with one exception, described below: the delivery of push notifications.

Who is responsible

The controller responsible for processing is named in the legal notice (Impressum). Questions about data protection: privacy@calyvro.app.

Specially protected data

Calyvro is for people recovering from addiction and compulsive behaviour. The mere fact that somebody uses this app allows conclusions about their health. On top of that come the things you can choose to enter yourself: mood entries, progress, posts in groups and, if you want, a profile picture.

The profile picture deserves a sentence of its own, because it is the only piece of information that makes you directly recognisable: anybody who sees your photo knows you are in this group. That is why it is voluntary, why you can remove it without being asked anything, and why a pseudonym alone is the default.

This is health data within the meaning of Article 9 GDPR. Processing it is based on your explicit consent, which you give when you sign up and can withdraw at any time by deleting your account. The whole design of the app follows from this: pseudonymous use, no analysis, no sharing.

What data is processed

For signing in

DataWhat for
Email addressSigning in, confirming your registration, resetting your password. Other users never see it.
PasswordNever stored in plain text, only as a cryptographic hash.
PseudonymThe name you appear under in groups. Your choice.
Profile pictureVoluntary. If you upload one, all members of your groups see it. You can remove it yourself at any time; moderation can remove it if it is reported. Without a picture, initials are made from your pseudonym. No picture of you is created in the process.
Time zoneSo that quiet hours for notifications fit your day.

From using the app

DataWhat for
Posts in groupsText, pictures and voice messages you send. Visible only to members of the group in question.
MembershipsWhich groups you are in, since when, and in what role.
ReactionsEmoji reactions to posts.
Check-ins and progressMood entries and milestones you create yourself. Visible only to you.
Trusted circleWhom you have added as a trusted person.
BlocksWhom you have blocked. Not visible to the person concerned.
Calls for helpWhen you use the urgent support feature, and who responded.
ReportsIf you report a post, an excerpt of it is stored so that moderation can assess it.

Technically necessary

DataWhat for
Your device's push tokenSo that notifications reach your device. Deleted when you sign out.
Notification settingsWhich kinds of notice you want to receive, and when not.
Security logSecurity-relevant events, such as an account deletion or a moderation decision. Never contains the content of messages.

What explicitly does not happen

Where the data is kept

ServicePurposeLocation
Hetzner Online GmbHServer and databaseGermany
CloudflarePictures, voice messages, profile pictures, encrypted backupsEuropean Union
Amazon Web Services (SES)Sending confirmation and password emailsFrankfurt am Main
Google (Firebase Cloud Messaging)Delivering push notifications to Android devicesalso outside the EU

About the exception for push notifications

On Android, push notifications are delivered through a service run by Google. On this platform there is no way around it. That is why the notification itself is built to give nothing away: it contains none of the text of your posts, only a key such as "new messages", which only your own device turns into readable words. Google therefore learns that a device was notified, not what it was about.

For the same reason, no content appears on the lock screen by default. You can change this in the settings if you want to.

If you don't allow notifications, no token is sent and Google learns nothing.

How long

Your rights

You have the rights under Articles 15 to 21 GDPR. You can exercise two of them directly in the app, without having to ask anyone:

For rectification, restriction, objection or withdrawing your consent, a message to privacy@calyvro.app is enough. You also have the right to lodge a complaint with a data protection supervisory authority.

This website

This site sets no cookies, loads no fonts or scripts from anybody else's servers, and doesn't measure visits. Requesting a page creates server logs at the hosting provider that are technically unavoidable; they are not analysed and not combined with accounts in the app.

Changes

If anything in this policy changes, the date at the top is updated. For significant changes, you will also be told in the app.