This policy explains what Wasted Penguinz AB (“we”) does with personal data when you visit zerosay.com and when you use the Zero Say app. It is written to be read, not skimmed past. The short version: the website stores an email address only if you ask it to, the app is designed so that we cannot read your messages, and we do not run analytics, advertising or tracking of any kind.
We are the data controller under the EU General Data Protection Regulation (GDPR) and the Swedish Data Protection Act (2018:218).
1.The website (zerosay.com)
Visiting the site creates no account, sets no cookies and loads nothing from third parties. Fonts, images and scripts are served from our own server.
| Data | Why | Legal basis | Kept for |
|---|---|---|---|
| Server access logs: your IP address, the page requested, time, browser type | Running the server, defending against abuse, diagnosing errors | Legitimate interest (Art. 6(1)(f)) | 14 days, then deleted |
| Waitlist: your email address and, if you chose one, the platform you want | Sending you one email when that platform is released | Consent (Art. 6(1)(a)), given by clicking the confirmation link we email you | Until the release email is sent or you unsubscribe, whichever comes first, plus 30 days |
| A salted hash of your IP address when you submit the waitlist form | Limiting how many signups one connection can make per hour | Legitimate interest (Art. 6(1)(f)) | Deleted when you confirm; the hash itself rotates every 24 hours |
An address that is never confirmed stays as a pending row for at most 30 days and is then deleted. Every email we send contains an unsubscribe link that works with one click and needs no login.
2.The Zero Say app
Zero Say is built as a zero-knowledge system. Your encryption keys are generated on your device and never sent to us. Messages are encrypted for the recipient’s devices before they leave yours. Our servers relay sealed envelopes and cannot open them. This section describes the little that remains.
| Data | Why | Legal basis | Kept for |
|---|---|---|---|
| Account identifier: a random ID and the public half of your key pair | Routing messages to you and letting others verify your identity | Contract (Art. 6(1)(b)) | Until you delete your account |
| Handle (a name you choose, optional) | Letting people find you without a phone number | Contract (Art. 6(1)(b)) | Until you change it or delete your account |
| Push notification token issued by Apple or Google | Waking the app when a message arrives. The notification itself is empty; the app fetches and decrypts the message locally. | Contract (Art. 6(1)(b)) | Until you sign out or the platform invalidates it |
| Message envelopes in transit: ciphertext, recipient ID, size, timestamp | Delivering the message | Contract (Art. 6(1)(b)) | Deleted the moment the recipient’s device confirms delivery; undelivered envelopes are deleted after 30 days |
| Abuse reports you send us (the reported message, decrypted by you and attached by your choice) | Enforcing the Terms of Use and legal obligations | Legitimate interest (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) | 90 days after the report is closed |
| Crash reports (off by default, opt-in in Settings) | Fixing bugs | Consent (Art. 6(1)(a)) | 90 days |
What we deliberately do not collect
- No phone number, no email address, no real name.
- No upload of your address book. Discovery works by handle or QR code.
- No message content. We could not read it if we wanted to.
- No analytics, advertising identifiers, or third-party SDKs of any kind.
- No location data.
- No record of who talks to whom beyond the envelopes described above, which are deleted on delivery.
Your keys and your responsibility
Because we never hold your keys, we cannot reset them, recover them or decrypt anything on your behalf. If you lose every device and your recovery phrase, your message history is gone. That is not a bug; it is the design.
3.Who else touches the data
We use a small number of service providers, all bound by data-processing agreements under Art. 28 GDPR:
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Servers for the website and the message relay | Germany (EU) |
| Resend, Inc. | Sending the waitlist and release emails | Processing region EU (Ireland); provider incorporated in the USA, covered by the EU-US Data Privacy Framework and Standard Contractual Clauses |
| Apple Inc. / Google LLC | App distribution and push notification delivery | EU and USA, under their own terms and the Data Privacy Framework |
We do not sell, rent or share personal data with anyone else. We do not use data brokers. We do not run ads.
4.International transfers
Our own servers are in the EU. The only data that can leave the EU is the empty push token exchanged with Apple or Google, and email delivery through Resend’s EU region. Where a provider is established outside the EU we rely on an adequacy decision (the EU-US Data Privacy Framework) or Standard Contractual Clauses.
5.Your rights
Under the GDPR you can ask us to:
- tell you what personal data we hold about you (access, Art. 15);
- correct it (rectification, Art. 16);
- delete it (erasure, Art. 17): in the app this is the “Delete account” button in Settings, which works immediately and needs no email to us;
- restrict or object to processing (Art. 18 and 21);
- receive a copy in a machine-readable format (portability, Art. 20);
- withdraw consent at any time, for example by using the unsubscribe link in any email (Art. 7(3)).
Write to hello@zerosay.com. We answer within 30 days. Because the app does not collect identifying data, we may need you to prove control of an account by signing a challenge from within the app before we act on a request about it.
You can also complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), Box 8114, 104 20 Stockholm, imy.se, or to the supervisory authority where you live.
6.Children
Zero Say is not directed at children under 13, and under Swedish law a child must be 13 to consent to an information-society service on their own. If you believe a child under 13 has created an account, email us and we will delete it.
7.Security
- End-to-end encryption with per-message keys and forward secrecy in the app.
- TLS on every connection to our servers; HSTS on the website.
- Servers hardened and patched automatically; SSH by key only; disk encryption at rest.
- Minimal data by design: the best protection for data is not to have it.
- Security researchers: email hello@zerosay.com with “security” in the subject. We will not take legal action against good-faith research.
8.Requests from authorities
We comply with valid legal orders under Swedish law. Because of the design described above, the most we can provide about an account is its random identifier, its public key, the date it was created, and any undelivered ciphertext envelopes waiting for it. We cannot provide message content, contact lists, phone numbers or names, because we do not have them. We will publish a transparency summary at least once a year.
9.Changes to this policy
When we change this policy we update the version and date at the top and describe the change in the log below. If a change reduces your privacy in any way we will announce it inside the app before it takes effect. We will never quietly widen what we collect.
Change log
| Version | Date | Change |
|---|---|---|
| 1.0 | 2026-09-09 | First version, published with the website and ahead of the first app release. |
Contact
Wasted Penguinz AB
[street address]
267 75 Ekeby, Sweden
Org. nr 559447-4859
hello@zerosay.com