hitodor

Privacy Policy

Last updated 29 August 2026 · Hitodor is currently in beta

This Privacy Policy explains what personal data Hitodor processes, for what purposes, on what legal basis, how long it is retained, and what rights you have. It applies to the Hitodor mobile application and the hitodor.com and hitodor.app websites.

1. Controller

The controller responsible for the processing of personal data described in this Policy is:

Hitodor

Munich, Germany

Email: hitodorprivacy@outlook.com (also for account deletion and data-subject requests)

2. Summary of key points

3. Categories of personal data and purposes of processing

CategoryDataPurpose Legal basis (GDPR Art. 6(1))
Account identifier Your mobile phone number, stored as a salted, keyed hash (HMAC). The plaintext number is not stored in our database. Account identification; enabling others who know your number to address content to you (b) performance of a contract
Email address Only where you provide one: for email sign-in, or when applying for the beta programme Authentication; delivery of beta invitations (TestFlight / Google Play) (b) contract; (a) consent for beta applications
Public handle Your @name, if you claim one Allowing others to address you by a handle instead of a number (b) performance of a contract
Content metadata Sender, recipient, the coordinates and time at which a Hito was left, its expiry, and its delivery state (waiting, collected, expired) Delivering the service: routing content, enforcing the location-based unlock, informing sender and recipient of status (b) performance of a contract
Message content Text, photos, video and voice recordings, in end-to-end encrypted form only Storage and delivery of ciphertext to the intended recipient. Hitodor cannot decrypt this content (b) performance of a contract
Location, Group and Event data Names and descriptions of the Locations, Trails, Groups and Events you create — encrypted on your device and readable only by their members; membership lists (stored as hashed phone numbers); coordinates, schedules, RSVPs and polls Providing the organisational features of the service (b) performance of a contract
Push notification token A device token issued by Apple/Google Notifying you that content or an event is waiting. Notification payloads contain no message content (b) performance of a contract
Technical and security data Request timestamps, rate-limiting counters, aggregate lookup statistics, denied-claim records (distance and accuracy values, without stored coordinates) Preventing abuse, enumeration and fraud; securing the service (f) legitimate interests (service security)
Beta programme data Email address and device platform provided in the beta application Sending the store invitation (a) consent
Support and reports Reports you submit, including any content you choose to attach from your own device Trust and safety; handling abuse reports; legal compliance (f) legitimate interests; (c) legal obligation where applicable

What we do not process: your address book (never uploaded, in any form, including hashes); background or continuous location data; advertising identifiers; analytics or behavioural profiles. We do not sell personal data and do not engage in automated decision-making producing legal effects.

4. End-to-end encryption

Message content is encrypted on your device with keys held only on your device and the recipient's device. Hitodor's servers store ciphertext and an encrypted key envelope that only the recipient's device can open. We are technically unable to read message content, and this inability also applies to our hosting providers.

The same applies to the names and descriptions of Locations, Trails, Groups and Events. Each is encrypted with a key held by that group's members and delivered to them sealed to their own devices; we hold ciphertext and cannot read it. When somebody leaves a group, a new key is issued to the rest, so what is written afterwards is closed to them.

What remains visible to us, and cannot be encrypted without breaking the service: coordinates, times and status. The server enforces that a Hito only opens where it was left, that a gathering's chat is live only near its place, and that content is destroyed at its expiry — none of which it could do with data it cannot read. It is also necessarily visible who sent something to whom, and which hashed numbers belong to which group. Encrypting the words does not hide the shape of the network, and we do not claim it does.

5. Location data

Your device's position is read in exactly two situations: when you create a Hito (to record where it is left) and when you attempt to open one (to verify you are at the right place). Position checks for opening are evaluated server-side; denied attempts are logged with distance and accuracy values only — the coordinates themselves are not retained. The app has no background location permission and maintains no history of your movements.

6. Retention

DataRetention
Encrypted message content and key envelopes Deleted automatically at the expiry the sender chose (1, 3 or 7 days), enforced by a scheduled server process
Content metadata (that a Hito existed, between whom, and its outcome) Retained as part of each party's history until account deletion
Account data (hashed number, email, handle) Until account deletion
Locations, Trails, Groups, Events Until deleted by their owner or upon account deletion as applicable
Beta application data Deleted at the end of the beta programme, or earlier on request
Security and rate-limiting records Retained for a limited period proportionate to their security purpose, then deleted or aggregated

Content you have already collected is stored on your own device, under your control; deleting it there removes the last copy. Content another person has already collected resides on their device and is outside our control — as with any delivered message.

7. Recipients and processors

We use the following processors under data-processing agreements pursuant to Art. 28 GDPR:

Map tiles and place-name data are served from infrastructure we operate; place-name information is derived from OpenStreetMap (© OpenStreetMap contributors, ODbL) and, in limited cases, Google Places.

Personal data is not shared with other third parties except where required by law or necessary to establish, exercise or defend legal claims.

8. Your rights

Under the GDPR you have the right to:

To exercise any of these rights, contact hitodorprivacy@outlook.com. We will respond within the statutory time limits. Note that erasure cannot extend to content already delivered to another person's device.

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR) — in Germany, the data protection authority of your federal state; for Bavaria, the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA).

9. Permissions

The app requests location, camera, microphone, contacts and notification permissions. All except location are optional and can be declined or revoked in your device settings; the service cannot function without location access, as physical presence is its core mechanism. The contacts permission is used solely for local name resolution on your device.

10. Children

Hitodor is not directed at, and may not be used by, persons under 16 years of age. We do not knowingly process personal data of children under 16; if you believe a child has created an account, please contact us and it will be deleted.

11. Data security

Data in transit is protected by TLS; message content, and the names and descriptions of Locations, Trails, Groups and Events, are additionally end-to-end encrypted as described in Section 4. Data at rest on your device is stored in an encrypted local database whose key is held in your device's secure hardware keystore and excluded from platform backups.

12. Changes to this Policy

We will update this Policy when our processing changes and revise the date above. Because this Policy describes how the application is built, material changes to the Policy reflect corresponding changes to the application. For significant changes we will inform you within the app.