Privacy Policy

Effective date: 1 September 2026 • Version 2.0

Our Privacy Commitment

At kryptem, privacy isn't a feature—it's our foundation. We've built the entire platform with zero-knowledge architecture, meaning we cannot access your private communications even if we wanted to. This policy explains what limited data we do process, why we process it, and the rights you have under the EU General Data Protection Regulation (GDPR) and the Law on Personal Data Protection of the Republic of North Macedonia.

1. Who We Are (Data Controller)

The data controller responsible for your personal data is:

Криптем Лимитед увоз-извоз ДОО Скопје

(Latin: Kryptem Limited uvoz-izvoz DOO Skopje)

Bul. Partizanski Odredi br. 155/2-32, 1000 Skopje, Republic of North Macedonia

Company registration (EMBS): [registration number]

Tax number (EDB): [tax number]

Privacy & data requests: privacy@kryptem.net

Wherever this policy refers to "kryptem", "we", "us", or "our", it refers to the company named above.

2. Our Approach

We collect the minimum amount of data required to operate a secure communication service, and nothing more. We never sell your data, never serve ads, and never use your communications to train AI models.

3. Zero-Knowledge Architecture

kryptem uses end-to-end encryption with zero-knowledge architecture:

4. Information We Collect

Account Information

Device & Usage Information

Payment Information

5. What We Do NOT Collect

  • Message content – Encrypted end-to-end, invisible to us
  • Contact lists – Stored encrypted; we never see raw contact data
  • Location data – Unless explicitly shared by you with a contact
  • Metadata patterns – We don't profile who you talk to or when
  • Social graphs – Your relationships are your business
  • Advertising IDs – We don't use ads
  • Third-party trackers – No analytics SDKs, no tracking pixels

Under Article 6 of the GDPR, we rely on the following legal bases:

Purpose Legal basis
Creating and managing your account; delivering the servicePerformance of a contract (Art. 6(1)(b))
Processing payments and subscriptionsPerformance of a contract (Art. 6(1)(b))
Security, fraud prevention, and abuse detectionLegitimate interests (Art. 6(1)(f))
Keeping billing records for tax complianceLegal obligation (Art. 6(1)(c))
Optional features you enable (e.g. location sharing)Consent (Art. 6(1)(a))

7. How We Use Your Data

We NEVER:

  • Sell your data to third parties
  • Share data with advertisers
  • Use your messages for AI training
  • Build user profiles for marketing
  • Share data with governments, except non-content data where strictly required by a valid legal order

8. Sharing & Sub-processors

We do not sell or rent your data. We share the limited data described above only with vetted service providers ("sub-processors") strictly to operate the service. Each is bound by a data processing agreement:

Provider Purpose
Apple / GoogleApp distribution and in-app subscription billing
StripeCard payment processing (web billing)
Firebase Cloud Messaging (Google)Delivery of push notifications to your devices
TwilioSMS verification and SMS messaging features
Cloud hosting providerRunning our encrypted backend infrastructure

Because of our zero-knowledge design, none of these providers can access your message content.

9. Data Retention

When you delete your account, your personal data is permanently removed within 30 days, except records we are legally required to keep.

10. International Data Transfers

Our production infrastructure is hosted in [data hosting region — to be finalized]. Where personal data is transferred outside North Macedonia or the European Economic Area, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. Due to zero-knowledge encryption, your message content remains protected regardless of where it is routed.

11. Your Rights

Under the GDPR and North Macedonian data protection law, you have the right to:

To exercise these rights, contact privacy@kryptem.net. We respond within 30 days. You also have the right to lodge a complaint with the Agency for Personal Data Protection of the Republic of North Macedonia (azlp.mk), or, if you are in the EU, with your local supervisory authority.

12. Security

13. Children's Privacy

kryptem is designed for families, including children under parental supervision. Parents control child accounts through the Family tier. We do not knowingly collect data from children below the age of digital consent without verifiable parental consent. Child accounts have additional privacy protections and parental controls.

14. Changes to This Policy

We may update this policy occasionally. Material changes will be announced via email and in-app notification. Your continued use after changes take effect constitutes acceptance. Previous versions are available on request.

15. Contact Us

Questions about privacy? We're happy to help:

Version 2.0 • Effective 1 September 2026

Experience True Privacy

Join families protecting their communication with kryptem.

Start Your 14-Day Free Trial