1. Controller
The controller responsible for the processing described in this Privacy Policy is: Ugur Maman · Hauptstraße 412, 53639 Königswinter, Germany · [email protected].
Last updated: 27 September 2026
The controller responsible for the processing described in this Privacy Policy is: Ugur Maman · Hauptstraße 412, 53639 Königswinter, Germany · [email protected].
This Privacy Policy describes the current data practices of the HoodApp website and the HoodApp messaging service.
It covers the account information, public cryptographic information, encrypted message transport data, block relationships, temporary message retention, local device data and technical information currently required to operate HoodApp.
If a user selects a language, the HoodApp website stores that preference locally in the browser under the key "hoodapp.locale" so the selected language can be remembered on later visits.
The current HoodApp website does not use advertising, analytics or marketing cookies and does not intentionally deploy behavioral advertising trackers, analytics pixels or third-party advertising-network scripts.
The language preference is functional browser storage. It is not used for advertising, analytics, profiling or cross-site tracking and remains on the user's device until it is changed, cleared or otherwise removed by the browser or device.
Cloudflare may use strictly necessary cookies when particular security, challenge or traffic-management features are enabled or triggered. HoodApp does not use such cookies for advertising or behavioral analytics.
The applicability of the strictly-necessary storage exception under Section 25(2) no. 2 TDDDG to the language-preference storage should be reviewed if the website functionality changes.
HoodApp processes an account identifier in the form of a HoodApp ID and technical information required to provide the messaging service.
An email address and a real name are not required to create or use the current HoodApp account model.
Information that is technically necessary for the account and messaging functions must be processed in order to provide those functions.
HoodApp processes public cryptographic information required for the current encrypted messaging and identity architecture.
Public cryptographic information is used to support the technical operation of HoodApp conversations and related account functions.
The service processes encrypted message transport data and account identifiers that are necessary to operate conversations and deliver messages between HoodApp IDs.
HoodApp is built around encrypted conversations. No communication system can guarantee absolute security, and this Privacy Policy does not make such a guarantee.
Every message has a maximum lifetime of five minutes under the current HoodApp design.
Expired messages are designed to become unavailable and to be removed from active message storage.
The five-minute lifetime is intended to reduce unnecessary persistence of message data.
Temporary conversation content may exist locally on the user's device while it remains valid.
HoodApp also uses local cryptographic state as part of its security architecture.
Local data handling may differ from server-side processing because some information is stored and processed directly on the user's device.
HoodApp processes block relationships where a user blocks another HoodApp ID.
This information is required to operate the blocking function and enforce the resulting communication restriction.
Under the current HoodApp design, accounts are intended to be automatically removed after five days of inactivity.
This short inactivity period forms part of HoodApp's data-minimization approach.
Users can initiate account deletion through the HoodApp application.
The deletion flow is designed to remove server account data and local cryptographic state associated with the HoodApp account.
Infrastructure-specific logs, backups and legally required retention are handled according to the current provider configuration and applicable legal requirements. Known retention periods for the current configuration are described below.
HoodApp requires technical infrastructure to provide the website and messaging service. Infrastructure providers may process network, request or infrastructure information that is necessary to deliver, secure and operate those services.
The HoodApp website is delivered through Cloudflare Pages and Cloudflare's network. In connection with website delivery and security, Cloudflare may process technical request information such as IP addresses, traffic-routing data and system-configuration information.
HoodApp's production backend currently uses infrastructure provided by Railway Corporation. Railway processes personal data on HoodApp's behalf as a processor where applicable. The current HoodApp backend deployment runs in Railway's US West region (region identifier: sfo).
The current HoodApp application does not require access to the camera, microphone, photos, location, contacts, calendar, speech or health data.
If the application later introduces a feature that changes these permissions, the privacy information must be reviewed and updated before that feature is released.
HoodApp is designed around data minimization, short message retention and encrypted conversations.
Technical and organizational safeguards are intended to reduce unnecessary exposure of data. However, no communication or information-security system can provide an absolute guarantee of security.
Security measures and this Privacy Policy are reviewed when HoodApp's technical architecture, providers or processing activities materially change.
Where processing is necessary to create and operate a HoodApp account, provide messaging functions, deliver messages, apply blocks or process an account deletion requested by the user, the intended legal basis is Article 6(1)(b) GDPR, to the extent the processing is necessary to provide the service requested by the user.
Where processing is necessary to protect the security and integrity of HoodApp and those interests are not overridden by the rights and freedoms of the user, processing may be based on Article 6(1)(f) GDPR.
Where HoodApp is required to process or retain information in order to comply with a legal obligation, Article 6(1)(c) GDPR may apply.
If HoodApp later introduces optional processing for which consent is legally required, that processing and the corresponding consent mechanism must be documented separately before it is introduced.
Encrypted messages: maximum lifetime of five minutes under the current design.
Inactive accounts: designed to be automatically removed after five days of inactivity.
Website language preference: stored locally under "hoodapp.locale" until the user changes the selection, clears the relevant browser/site storage or the storage is otherwise removed by the browser or device.
Under the current Railway Trial hosting configuration, Railway platform logs are retained for up to 7 days. The persistent volume attached to the HoodApp backend currently has no Railway volume backups configured. These infrastructure settings may be updated if the production hosting configuration changes.
Because HoodApp uses infrastructure providers that operate internationally, technical or service data may be processed outside the European Economic Area depending on the provider and service path involved.
Railway states in its Data Processing Addendum that its primary processing operations take place in the United States. Where personal data protected by the GDPR is transferred outside the European Economic Area to a jurisdiction without an applicable adequacy decision, Railway provides for transfers under the EU-U.S. Data Privacy Framework where applicable or the European Commission's Standard Contractual Clauses, together with the safeguards described in Railway's Data Processing Addendum.
Subject to the conditions of the GDPR, users may have rights including access to their personal data, rectification of inaccurate data, erasure, restriction of processing, data portability and objection to certain processing.
Where processing is based on consent, consent may generally be withdrawn for the future without affecting the lawfulness of processing carried out before the withdrawal.
Some rights depend on the legal basis and circumstances of the processing and therefore may not apply in every situation.
Users have the right to lodge a complaint with a competent data-protection supervisory authority if they consider that the processing of their personal data infringes the GDPR.
A complaint may in particular be made to a supervisory authority in the Member State of the user's habitual residence, place of work or the place of the alleged infringement.
The competent data protection supervisory authority is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.
HoodApp is intended for users who are at least 16 years old. Persons under the age of 16 may not create or use a HoodApp account.
This Privacy Policy may be updated when HoodApp's technical architecture, processing activities, providers or legal obligations change.
Material changes should be reflected in the published policy together with an updated effective date.
Questions about privacy or the exercise of data-protection rights may be directed to: [email protected].