Effective date: 1 September 2026 • Version 2.0
At kryptem, privacy isn't a feature—it's our foundation. We've built the entire platform with zero-knowledge architecture, meaning we cannot access your private communications even if we wanted to. This policy explains what limited data we do process, why we process it, and the rights you have under the EU General Data Protection Regulation (GDPR) and the Law on Personal Data Protection of the Republic of North Macedonia.
The data controller responsible for your personal data is:
Криптем Лимитед увоз-извоз ДОО Скопје
(Latin: Kryptem Limited uvoz-izvoz DOO Skopje)
Bul. Partizanski Odredi br. 155/2-32, 1000 Skopje, Republic of North Macedonia
Company registration (EMBS): [registration number]
Tax number (EDB): [tax number]
Privacy & data requests: privacy@kryptem.net
Wherever this policy refers to "kryptem", "we", "us", or "our", it refers to the company named above.
We collect the minimum amount of data required to operate a secure communication service, and nothing more. We never sell your data, never serve ads, and never use your communications to train AI models.
kryptem uses end-to-end encryption with zero-knowledge architecture:
Under Article 6 of the GDPR, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Creating and managing your account; delivering the service | Performance of a contract (Art. 6(1)(b)) |
| Processing payments and subscriptions | Performance of a contract (Art. 6(1)(b)) |
| Security, fraud prevention, and abuse detection | Legitimate interests (Art. 6(1)(f)) |
| Keeping billing records for tax compliance | Legal obligation (Art. 6(1)(c)) |
| Optional features you enable (e.g. location sharing) | Consent (Art. 6(1)(a)) |
We do not sell or rent your data. We share the limited data described above only with vetted service providers ("sub-processors") strictly to operate the service. Each is bound by a data processing agreement:
| Provider | Purpose |
|---|---|
| Apple / Google | App distribution and in-app subscription billing |
| Stripe | Card payment processing (web billing) |
| Firebase Cloud Messaging (Google) | Delivery of push notifications to your devices |
| Twilio | SMS verification and SMS messaging features |
| Cloud hosting provider | Running our encrypted backend infrastructure |
Because of our zero-knowledge design, none of these providers can access your message content.
When you delete your account, your personal data is permanently removed within 30 days, except records we are legally required to keep.
Our production infrastructure is hosted in [data hosting region — to be finalized]. Where personal data is transferred outside North Macedonia or the European Economic Area, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. Due to zero-knowledge encryption, your message content remains protected regardless of where it is routed.
Under the GDPR and North Macedonian data protection law, you have the right to:
To exercise these rights, contact privacy@kryptem.net. We respond within 30 days. You also have the right to lodge a complaint with the Agency for Personal Data Protection of the Republic of North Macedonia (azlp.mk), or, if you are in the EU, with your local supervisory authority.
kryptem is designed for families, including children under parental supervision. Parents control child accounts through the Family tier. We do not knowingly collect data from children below the age of digital consent without verifiable parental consent. Child accounts have additional privacy protections and parental controls.
We may update this policy occasionally. Material changes will be announced via email and in-app notification. Your continued use after changes take effect constitutes acceptance. Previous versions are available on request.
Questions about privacy? We're happy to help:
Version 2.0 • Effective 1 September 2026
Join families protecting their communication with kryptem.
Start Your 14-Day Free Trial