Maiora
Last updated: 2026-05-10 ยท Effective: 2026-05-10

Privacy Policy

Beta notice. Maiora is currently in closed beta, distributed to a limited group of family and friends for testing. The operator is an individual; a registered company will be set up before public release, and this policy will be updated accordingly.

1. At a glance

2. Who can use Maiora

3. Information we collect

We collect only what is necessary to operate the app. Each data category below is listed with its purpose.

3.1 Account information

3.2 Communications data

3.3 Device and connection data

3.4 Address-book data (only if you grant permission)

If you grant the app permission to access your phone's contact list, Maiora reads contact entries locally on your device to suggest matches against existing Maiora users. Phone numbers from your address book are not uploaded in bulk. The only case in which a phone number is sent to the server is when you explicitly invite a specific contact who is not yet on Maiora.

3.5 Safety alerts

If the on-device moderation engine flags a message you send or receive as potentially harmful, an alert containing the alert category and severitybut not the message text — is sent to the server and forwarded to the relevant tutor account. This applies only to children's accounts where the tutor has enabled moderation.

3.6 Operational logs

The server keeps minimal operational logs (request paths, status codes, anonymous error traces) for up to 30 days for debugging. These logs do not contain message content or identifiable personal data beyond user IDs.

3.7 Waiting-list sign-up (website)

If you join the waiting list on our website, we store the email address you provide and, optionally, your self-selected interest ("myself", "my kids", or "both") and your browser language. We use it for one purpose only: to email you once, when Maiora becomes available. We do not add you to any other mailing list and we do not share it. Legal basis: your consent. You can be removed at any time by emailing support@maiora.chat.

3.8 Website visit counting

On our public website we keep an approximate count of unique visitors and page views. We do not use cookies or third-party analytics. We compute a one-way, salted hash of your IP address and add it to an aggregate counter โ€” your IP address itself is never stored, and individual visits cannot be identified or reconstructed. The count exists only to measure interest.

4. How we use this information

  1. Operating the service — authenticating you, routing messages, delivering notifications.
  2. Safety and moderation — protecting children via on-device screening and tutor alerts.
  3. Account security — detecting suspicious activity, enforcing rate limits.
  4. Service improvement — fixing bugs based on operational logs and crash reports.

We do not use your data for advertising, profiling, or sale to third parties.

5. End-to-end encryption — what we can and cannot see

Maiora implements the Signal protocol for all message content.

6. Children's accounts and tutor oversight

Maiora is designed around child safety. For every child account:

Tutors cannot read the child's messages but can see who the child is in contact with, which groups the child is in, the count of moderation alerts, and revoke any contact or remove the child from any group.

7. Sharing of data

We do not sell, rent, or share your personal data for advertising or any commercial purpose.

We use a small set of service providers ("subprocessors") to operate the app:

SubprocessorPurposeLocation
Hetzner Online GmbHHosting and databaseFrankfurt, Germany (EU)
Google Firebase Cloud MessagingPush notifications on AndroidUnited States
Apple Push Notification servicePush notifications on iOSUnited States
Google Play / Apple App StoreApp distribution and crash reportingUnited States

The primary data store is in the European Union. Push notifications routed via Google or Apple involve transfers to the United States; we rely on the providers' standard contractual clauses and only the encrypted notification envelope is sent (no plaintext message content ever transits FCM or APNs).

We may disclose data when required by law or to protect users from imminent harm.

8. Data retention

DataRetention
Encrypted message payloads on the serverAuto-deleted at most 14 days after creation.
Reactions, delivery recordsDeleted with their parent message.
Pending contact requests / group invitationsAuto-cancelled after 14 days if not actioned.
One-time prekeysConsumed on first use.
Operational server logsUp to 30 days.
Account recordUntil you delete your account.
Device push tokensUntil you uninstall the app or delete your account.

When you delete your account, all the above data we hold about you is removed. Encrypted message copies that were already delivered to other users remain on those users' devices.

9. Your rights

If you are in the European Economic Area, the United Kingdom, Switzerland, or any other jurisdiction granting equivalent rights, you have the right to:

To exercise any of these rights, email support@maiora.chat.

10. How to delete your account

See the dedicated account-deletion page for step-by-step instructions and the manual fallback if you can't access the app.

11. Security

If you become aware of a security issue, please email support@maiora.chat.

12. Permissions we ask for

PermissionWhy
ContactsTo suggest matches against existing Maiora users (read locally on device, not uploaded in bulk). Optional.
CameraTo take photos sent in chats. Optional.
MicrophoneTo record voice messages. Optional.
Photo libraryTo send images from your gallery. Optional.
Push notificationsTo alert you of new messages when the app is closed. Optional.
InternetRequired — the app cannot work offline.
BiometricOptional — to lock the app behind Face ID / Touch ID.

13. International data transfers

Our primary infrastructure is hosted in Frankfurt, Germany (European Union). The push notification subsystem (Google Firebase Cloud Messaging, Apple Push Notification service) and the app stores involve transfers to the United States. We rely on the providers' standard contractual clauses; only the minimum data needed to wake the device is sent through these channels.

14. Changes to this policy

We will update this policy when we change how the app handles data. The "Last updated" date at the top reflects the most recent change. Material changes (new data categories, new subprocessors, new sharing practices) will be announced in the app before they take effect.

15. Contact

For any privacy question, complaint, or rights request:

Email: support@maiora.chat

We aim to respond within 14 days during the beta period.