Skip to content
ZERO SAYZERO SAY

Legal

Privacy Policy


Version 1.0 · Effective 2026-09-09

This policy explains what Wasted Penguinz AB (“we”) does with personal data when you visit zerosay.com and when you use the Zero Say app. It is written to be read, not skimmed past. The short version: the website stores an email address only if you ask it to, the app is designed so that we cannot read your messages, and we do not run analytics, advertising or tracking of any kind.

We are the data controller under the EU General Data Protection Regulation (GDPR) and the Swedish Data Protection Act (2018:218).

1.The website (zerosay.com)

Visiting the site creates no account, sets no cookies and loads nothing from third parties. Fonts, images and scripts are served from our own server.

DataWhyLegal basisKept for
Server access logs: your IP address, the page requested, time, browser typeRunning the server, defending against abuse, diagnosing errorsLegitimate interest (Art. 6(1)(f))14 days, then deleted
Waitlist: your email address and, if you chose one, the platform you wantSending you one email when that platform is releasedConsent (Art. 6(1)(a)), given by clicking the confirmation link we email youUntil the release email is sent or you unsubscribe, whichever comes first, plus 30 days
A salted hash of your IP address when you submit the waitlist formLimiting how many signups one connection can make per hourLegitimate interest (Art. 6(1)(f))Deleted when you confirm; the hash itself rotates every 24 hours

An address that is never confirmed stays as a pending row for at most 30 days and is then deleted. Every email we send contains an unsubscribe link that works with one click and needs no login.

2.The Zero Say app

Zero Say is built as a zero-knowledge system. Your encryption keys are generated on your device and never sent to us. Messages are encrypted for the recipient’s devices before they leave yours. Our servers relay sealed envelopes and cannot open them. This section describes the little that remains.

DataWhyLegal basisKept for
Account identifier: a random ID and the public half of your key pairRouting messages to you and letting others verify your identityContract (Art. 6(1)(b))Until you delete your account
Handle (a name you choose, optional)Letting people find you without a phone numberContract (Art. 6(1)(b))Until you change it or delete your account
Push notification token issued by Apple or GoogleWaking the app when a message arrives. The notification itself is empty; the app fetches and decrypts the message locally.Contract (Art. 6(1)(b))Until you sign out or the platform invalidates it
Message envelopes in transit: ciphertext, recipient ID, size, timestampDelivering the messageContract (Art. 6(1)(b))Deleted the moment the recipient’s device confirms delivery; undelivered envelopes are deleted after 30 days
Abuse reports you send us (the reported message, decrypted by you and attached by your choice)Enforcing the Terms of Use and legal obligationsLegitimate interest (Art. 6(1)(f)); legal obligation (Art. 6(1)(c))90 days after the report is closed
Crash reports (off by default, opt-in in Settings)Fixing bugsConsent (Art. 6(1)(a))90 days

What we deliberately do not collect

  • No phone number, no email address, no real name.
  • No upload of your address book. Discovery works by handle or QR code.
  • No message content. We could not read it if we wanted to.
  • No analytics, advertising identifiers, or third-party SDKs of any kind.
  • No location data.
  • No record of who talks to whom beyond the envelopes described above, which are deleted on delivery.

Your keys and your responsibility

Because we never hold your keys, we cannot reset them, recover them or decrypt anything on your behalf. If you lose every device and your recovery phrase, your message history is gone. That is not a bug; it is the design.

3.Who else touches the data

We use a small number of service providers, all bound by data-processing agreements under Art. 28 GDPR:

ProviderPurposeLocation
Hetzner Online GmbHServers for the website and the message relayGermany (EU)
Resend, Inc.Sending the waitlist and release emailsProcessing region EU (Ireland); provider incorporated in the USA, covered by the EU-US Data Privacy Framework and Standard Contractual Clauses
Apple Inc. / Google LLCApp distribution and push notification deliveryEU and USA, under their own terms and the Data Privacy Framework

We do not sell, rent or share personal data with anyone else. We do not use data brokers. We do not run ads.

4.International transfers

Our own servers are in the EU. The only data that can leave the EU is the empty push token exchanged with Apple or Google, and email delivery through Resend’s EU region. Where a provider is established outside the EU we rely on an adequacy decision (the EU-US Data Privacy Framework) or Standard Contractual Clauses.

5.Your rights

Under the GDPR you can ask us to:

  • tell you what personal data we hold about you (access, Art. 15);
  • correct it (rectification, Art. 16);
  • delete it (erasure, Art. 17): in the app this is the “Delete account” button in Settings, which works immediately and needs no email to us;
  • restrict or object to processing (Art. 18 and 21);
  • receive a copy in a machine-readable format (portability, Art. 20);
  • withdraw consent at any time, for example by using the unsubscribe link in any email (Art. 7(3)).

Write to hello@zerosay.com. We answer within 30 days. Because the app does not collect identifying data, we may need you to prove control of an account by signing a challenge from within the app before we act on a request about it.

You can also complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), Box 8114, 104 20 Stockholm, imy.se, or to the supervisory authority where you live.

6.Children

Zero Say is not directed at children under 13, and under Swedish law a child must be 13 to consent to an information-society service on their own. If you believe a child under 13 has created an account, email us and we will delete it.

7.Security

  • End-to-end encryption with per-message keys and forward secrecy in the app.
  • TLS on every connection to our servers; HSTS on the website.
  • Servers hardened and patched automatically; SSH by key only; disk encryption at rest.
  • Minimal data by design: the best protection for data is not to have it.
  • Security researchers: email hello@zerosay.com with “security” in the subject. We will not take legal action against good-faith research.

8.Requests from authorities

We comply with valid legal orders under Swedish law. Because of the design described above, the most we can provide about an account is its random identifier, its public key, the date it was created, and any undelivered ciphertext envelopes waiting for it. We cannot provide message content, contact lists, phone numbers or names, because we do not have them. We will publish a transparency summary at least once a year.

9.Changes to this policy

When we change this policy we update the version and date at the top and describe the change in the log below. If a change reduces your privacy in any way we will announce it inside the app before it takes effect. We will never quietly widen what we collect.

Change log

VersionDateChange
1.02026-09-09First version, published with the website and ahead of the first app release.

Contact

Wasted Penguinz AB
[street address]
267 75 Ekeby, Sweden
Org. nr 559447-4859
hello@zerosay.com