Privacy Policy
1. Controller
Dennis Bassy
Theodorstr.
58285 Gevelsberg, Deutschland
Email: kontakt@letheapp.de
For questions about data protection you can contact the address mentioned above at any time.
2. Overview of data processing
Lethe is an end-to-end encrypted messenger – privacy is not a coincidence but a core part of the product. Message content is encrypted and decrypted exclusively on the device. The server only stores encrypted data packets and cannot view the content of your communication.
3. Collected data & purposes
3.1 Visiting the website (letheapp.de)
When you access our website, the web server automatically logs the following data and stores it for a maximum of 7 days:
- IP address (anonymized after storage)
- Date and time of access
- Requested URL, HTTP status code
- Amount of data transferred, referrer URL
- Browser and operating system identifier (user agent)
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in the technically flawless provision of the service and defense against attacks).
3.2 User registration (app)
To use the Lethe app an account is created. The following is stored:
- Pseudonym (fake_number) – no real name required
- Password (bcrypt-hashed – the plaintext password is not accessible to us)
- Public key for end-to-end encryption
- Optional: profile picture (upload), biography, dating profile information
- Registration date and time of last login
Legal basis: Art. 6 (1) lit. b GDPR (performance of a contract).
3.3 Messages and media
All messages are transmitted and stored end-to-end encrypted. The server only receives an encrypted blob (content_blob) that it cannot read. Messages are stored until you or your contact deletes them.
3.4 Creator area
Creators can publish content (texts, images, videos) on the website. Depending on the setting, this content is public or only visible to paying subscribers. The terms of use of the creator area apply.
3.5 Location data (optional live location feature)
The "Share live location" feature sends your GPS location for the selected period (30 minutes to 8 hours) to selected contacts. Location data is not permanently stored on the server and is automatically deleted after the sharing period expires. Legal basis: Art. 6 (1) lit. a GDPR (consent).
3.6 Support requests
When you send a support request, the data provided (user ID, message, timestamp) is stored and used to process your request. Legal basis: Art. 6 (1) lit. b and f GDPR.
4. Cookies
This website uses cookies. You can adjust your settings at any time via the cookie settings link in the footer.
Essential (always active)
- Session cookie (PHPSESSID): Session management, login status. Deleted when the browser is closed.
- lethe_cookie_consent: Stores your cookie settings for 365 days (localStorage).
Statistics (disabled by default)
Currently no statistics services active.
Marketing (disabled by default)
Currently no marketing cookies active. Lethe does not run any advertising.
5. Hosting & infrastructure
The website and the API server are operated on a dedicated server in Germany. The server location is within the EU. No data is transferred to processors outside the EU.
We use Google Fonts for the "Inter" font. On the first page load the font is loaded from Google servers; your IP address is transmitted to Google LLC (USA). Legal basis: Art. 6 (1) lit. f GDPR. You can prevent the loading of external fonts using suitable browser extensions or DNS filters.
6. Disclosure of data
Your data is not sold to third parties or passed on for advertising purposes. Disclosure only occurs:
- Where legally required (e.g. upon official request)
- For the performance of a contract (hosting provider as processor)
7. Data security
The connection to the website and the API server is fully TLS-encrypted (HTTPS). Passwords are stored exclusively as a bcrypt hash. Message content is end-to-end encrypted – the server never possesses the decryption key.
8. Retention period
- Server logs: 7 days, then automatic deletion
- Account data: Until account deletion + commercial retention periods (max. 10 years if payment transactions)
- Messages: Until deleted by the user
- Support tickets: 2 years after closure
- Location data: Automatically after the sharing period expires (max. 8 hours)
9. Your rights (GDPR Art. 15–22)
You have the following rights towards us:
- Right of access (Art. 15 GDPR) – which data we store about you
- Right to rectification (Art. 16 GDPR) – correction of inaccurate data
- Right to erasure (Art. 17 GDPR) – "right to be forgotten"
- Right to restriction (Art. 18 GDPR) – restrict processing
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR) – against processing based on legitimate interest
- Withdrawal of consent (Art. 7 (3) GDPR) – at any time without giving reasons
To exercise your rights contact: kontakt@letheapp.de
In addition, you have the right to lodge a complaint with a data protection supervisory authority. You can find the responsible supervisory authority at www.bfdi.bund.de.
10. Changes to this privacy policy
We reserve the right to update this privacy policy in the event of changes in the legal situation or the service. The current version is published on this page. Significant changes are communicated to app users via push notification or in-app notice.
11. Contact & privacy requests
For questions, requests for information or deletion requests:
kontakt@letheapp.de