Privacy Policy
Beta notice. Maiora is currently in closed beta, distributed to a limited group of family and friends for testing. The operator is an individual; a registered company will be set up before public release, and this policy will be updated accordingly.
1. At a glance
- Maiora is a messaging app for children, supervised by their parents or guardians (called "tutors" in the app).
- Messages and reactions are end-to-end encrypted. The server cannot read message content. Tutors cannot read message content either.
- An on-device safety check scans outgoing and incoming messages for harmful patterns. If it detects something concerning, an alert is sent to the child's tutor — but never the message content itself.
- We do not sell or share your personal data with advertisers or any third party for marketing.
- Messages are retained briefly on the server — only until they are delivered to all recipients, and at most for 14 days. After that, they are deleted automatically.
- You can delete your account at any time from the app's Settings. Account deletion removes all data we hold about you. How to delete your account.
2. Who can use Maiora
- Adults can register directly using a phone number.
- Children can use Maiora only if at least one adult ("tutor") manages their account. Tutors approve every contact, every group invitation, and control which media types (images, audio, video, links, group chats) the child can use.
- Parents and legal guardians are responsible for obtaining any consent required under their jurisdiction's law (for example, GDPR Article 8 for European Economic Area children under 16, COPPA in the United States for children under 13) before letting a child use Maiora. By creating a child account, the tutor confirms they have the authority to do so.
3. Information we collect
We collect only what is necessary to operate the app. Each data category below is listed with its purpose.
3.1 Account information
- Phone number — used for sign-up, OTP verification, and account recovery.
- Username, display name, profile picture URL — visible to your contacts inside the app.
- Email address — required for tutor accounts; optional for adult accounts; used only for account recovery and security notifications.
- Hashed password — stored using bcrypt; the plain password is never stored.
- Account type — adult, tutor, or protected (child).
- Tutor relationships — the link between a tutor and the child accounts they supervise.
- Per-account permissions — flags controlling what media types a child can send and receive.
3.2 Communications data
- Encrypted messages — every message is encrypted on the sender's device with the Signal protocol before transmission. The server stores the encrypted payload only as long as needed to deliver it (and at most 14 days). The server cannot decrypt this data.
- Message metadata — the participants in a conversation, message timestamps, delivery status, and reactions.
- Reactions — emoji reactions on messages.
- Contact requests — pending invitations between users.
- Cryptographic keys — Signal-protocol identity keys, signed prekeys, and one-time prekeys, uploaded so other users can start an encrypted session with you.
3.3 Device and connection data
- Push notification token (FCM on Android, APNs on iOS) — used to alert you of new messages.
- Online / last-seen status — broadcast to your contacts.
3.4 Address-book data (only if you grant permission)
If you grant the app permission to access your phone's contact list, Maiora reads contact entries locally on your device to suggest matches against existing Maiora users. Phone numbers from your address book are not uploaded in bulk. The only case in which a phone number is sent to the server is when you explicitly invite a specific contact who is not yet on Maiora.
3.5 Safety alerts
If the on-device moderation engine flags a message you send or receive as potentially harmful, an alert containing the alert category and severity — but not the message text — is sent to the server and forwarded to the relevant tutor account. This applies only to children's accounts where the tutor has enabled moderation.
3.6 Operational logs
The server keeps minimal operational logs (request paths, status codes, anonymous error traces) for up to 30 days for debugging. These logs do not contain message content or identifiable personal data beyond user IDs.
3.7 Waiting-list sign-up (website)
If you join the waiting list on our website, we store the email address you provide and, optionally, your self-selected interest ("myself", "my kids", or "both") and your browser language. We use it for one purpose only: to email you once, when Maiora becomes available. We do not add you to any other mailing list and we do not share it. Legal basis: your consent. You can be removed at any time by emailing support@maiora.chat.
3.8 Website visit counting
On our public website we keep an approximate count of unique visitors and page views. We do not use cookies or third-party analytics. We compute a one-way, salted hash of your IP address and add it to an aggregate counter โ your IP address itself is never stored, and individual visits cannot be identified or reconstructed. The count exists only to measure interest.
4. How we use this information
- Operating the service — authenticating you, routing messages, delivering notifications.
- Safety and moderation — protecting children via on-device screening and tutor alerts.
- Account security — detecting suspicious activity, enforcing rate limits.
- Service improvement — fixing bugs based on operational logs and crash reports.
We do not use your data for advertising, profiling, or sale to third parties.
5. End-to-end encryption — what we can and cannot see
Maiora implements the Signal protocol for all message content.
- What we cannot see: the text of your messages, the contents of images / audio / video you send, your reactions to specific messages.
- What we can see (operational metadata required to route messages): who is talking to whom, when each message was sent, who is in each group chat, your online status, your phone number, your username, your display name, your profile picture URL.
- What tutors can see: the same operational metadata for the children they supervise, plus moderation alerts (without message text). Tutors cannot read children's message content.
6. Children's accounts and tutor oversight
Maiora is designed around child safety. For every child account:
- A tutor must be linked. Tutors are verified by phone number before they can supervise a child.
- The tutor approves every contact request before the child can communicate with the new contact.
- The tutor approves every group invitation before the child joins a group.
- The tutor can toggle media permissions per child at any time.
- If the tutor disables group chats for a child, the child is automatically removed from all current group chats.
- The tutor receives moderation alerts when the on-device safety check flags concerning content.
Tutors cannot read the child's messages but can see who the child is in contact with, which groups the child is in, the count of moderation alerts, and revoke any contact or remove the child from any group.
7. Sharing of data
We do not sell, rent, or share your personal data for advertising or any commercial purpose.
We use a small set of service providers ("subprocessors") to operate the app:
| Subprocessor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting and database | Frankfurt, Germany (EU) |
| Google Firebase Cloud Messaging | Push notifications on Android | United States |
| Apple Push Notification service | Push notifications on iOS | United States |
| Google Play / Apple App Store | App distribution and crash reporting | United States |
The primary data store is in the European Union. Push notifications routed via Google or Apple involve transfers to the United States; we rely on the providers' standard contractual clauses and only the encrypted notification envelope is sent (no plaintext message content ever transits FCM or APNs).
We may disclose data when required by law or to protect users from imminent harm.
8. Data retention
| Data | Retention |
|---|---|
| Encrypted message payloads on the server | Auto-deleted at most 14 days after creation. |
| Reactions, delivery records | Deleted with their parent message. |
| Pending contact requests / group invitations | Auto-cancelled after 14 days if not actioned. |
| One-time prekeys | Consumed on first use. |
| Operational server logs | Up to 30 days. |
| Account record | Until you delete your account. |
| Device push tokens | Until you uninstall the app or delete your account. |
When you delete your account, all the above data we hold about you is removed. Encrypted message copies that were already delivered to other users remain on those users' devices.
9. Your rights
If you are in the European Economic Area, the United Kingdom, Switzerland, or any other jurisdiction granting equivalent rights, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data — most fields are editable directly in the app.
- Delete your account and the data associated with it (see how to delete your account).
- Restrict or object to certain processing.
- Data portability — request a copy of your data in a structured format. (Beta limitation: we will fulfill requests manually during the beta period — email us.)
- Lodge a complaint with the data protection authority in your country.
To exercise any of these rights, email support@maiora.chat.
10. How to delete your account
See the dedicated account-deletion page for step-by-step instructions and the manual fallback if you can't access the app.
11. Security
- All connections between the app and our servers use TLS (HTTPS / WSS).
- Passwords are hashed with bcrypt.
- Message content is end-to-end encrypted with the Signal protocol.
- The auth server enforces rate limits on login and OTP requests.
- Push notifications carry only the minimum metadata needed for the device to wake the app — no message content.
If you become aware of a security issue, please email support@maiora.chat.
12. Permissions we ask for
| Permission | Why |
|---|---|
| Contacts | To suggest matches against existing Maiora users (read locally on device, not uploaded in bulk). Optional. |
| Camera | To take photos sent in chats. Optional. |
| Microphone | To record voice messages. Optional. |
| Photo library | To send images from your gallery. Optional. |
| Push notifications | To alert you of new messages when the app is closed. Optional. |
| Internet | Required — the app cannot work offline. |
| Biometric | Optional — to lock the app behind Face ID / Touch ID. |
13. International data transfers
Our primary infrastructure is hosted in Frankfurt, Germany (European Union). The push notification subsystem (Google Firebase Cloud Messaging, Apple Push Notification service) and the app stores involve transfers to the United States. We rely on the providers' standard contractual clauses; only the minimum data needed to wake the device is sent through these channels.
14. Changes to this policy
We will update this policy when we change how the app handles data. The "Last updated" date at the top reflects the most recent change. Material changes (new data categories, new subprocessors, new sharing practices) will be announced in the app before they take effect.
15. Contact
For any privacy question, complaint, or rights request:
Email: support@maiora.chat
We aim to respond within 14 days during the beta period.