Trusted Codes

Política de privacidad

Versión 2026-07-30

En vigor desde 2026-07-30

Esta es la dirección permanente de una versión. Seguirá mostrando exactamente este texto.

1. Introduction

Welcome to Trusted Codes. We are committed to protecting your privacy and ensuring transparency about how we handle your data. Trusted Codes is operated by:

Stefan Sonntag
Trading as: Trusted Codes (Sole Proprietor / Einzelunternehmer)
Leonrodstr. 14b, 80634 Munich, Germany

Contact:

Jurisdiction: German law, courts of Munich

About the Service:
Trusted Codes is an identity verification solution designed to protect against impersonation, deepfakes, and AI-based voice cloning. The service generates rotating three-word verification codes, enabling users to confirm contact consistency across any communication channel. The app works 100% offline after initial setup and is available on iOS and Android.

Pricing Tiers:

  • Free: Personal use, limited connections
  • Pro: Paid subscription with expanded features
  • Business: Paid subscription for organisations (B2B only), governed additionally by the Data Processing Agreement

2. Two-Tier Data Protection Architecture

Trusted Codes uses a two-tier data protection model, designed to balance security, privacy, and operational needs. We are transparent about what we can and cannot access.

2.1 Tier 1 – True Zero-Knowledge (Core Security)

The "zero-knowledge" properties described in this section apply only to the data types listed below (together, "Tier 1 Data") and mean Trusted Codes cannot access the plaintext of such Tier 1 Data, including under legal compulsion. This does not mean Trusted Codes does not process personal data generally; Trusted Codes continues to process certain account, device, and operational data described elsewhere in this Privacy Policy as a data controller.

Data TypeStorage LocationAccess
Codeword derivation secretsEncrypted on server + deviceOnly user devices can decrypt
Verification codesGenerated locally on deviceNever transmitted
Private cryptographic keysDevice secure enclave (Keychain / Keystore)Never leaves device

Implications:

  • Trusted Codes cannot generate verification codes for users.
  • Trusted Codes cannot impersonate your contacts.
  • Even in a server breach, core verification functionality cannot be compromised.

2.2 Tier 2 – Encrypted Metadata (Decryptable for Legitimate Operations)

Other data is encrypted at rest using AES-256. The encryption keys are held by a dedicated key custody service in the European Union, separate from the databases, so that access to one system does not yield the other.

Data TypeEncryption StatusWho Can Decrypt
Email addressesAES-256 encryptedTrusted Codes (via the key custody service)
Display namesAES-256 encryptedTrusted Codes (via the key custody service)
Device namesAES-256 encryptedTrusted Codes (via the key custody service)
Contact names (user-assigned)AES-256 encryptedTrusted Codes (via the key custody service)
Connection metadataAES-256 encryptedTrusted Codes (via the key custody service)

Database administrators do not have access to decryption keys.

Decryption occurs only for:

  • User support requests
  • Account recovery procedures
  • Responding to valid legal orders
  • Fraud investigation and prevention
  • Sending transactional emails

Important: Metadata decryption is not zero-knowledge. Trusted Codes can access email and display name if operationally required.

3. Information We Collect

Trusted Codes collects minimal data to operate and secure the service. Data is divided into the following categories:

3.1 Account Information (Encrypted – Decryptable)

  • Email address
  • Display name
  • Preferred language (plaintext for service delivery)
  • Account creation date

3.2 Device Information

  • Platform type (iOS / Android)
  • Push notification token
  • Public cryptographic key
  • Device fingerprint (hash of public key + device metadata)

3.3 Connection Information

  • Contact names you assign (encrypted – decryptable)
  • Encrypted cryptographic secrets (TRUE ZERO-KNOWLEDGE)
  • Connection metadata (timestamps, connection status)

3.4 Activity Logs (Auto-deleted after 90 days)

  • Login events
  • Account actions (connection creation, member management)
  • Trust ratings given
  • AI chat questions

Not logged: IP addresses, user agent strings

3.5 Analytics (Truly Anonymized)

  • Aggregated event counts (account created, connection created, verification success/failure)
  • No user or device identifiers
  • No IP addresses
  • Cannot be reverse-engineered
  • Retained indefinitely as non-personal data

3.6 Marketing Attribution (Optional)

  • UTM parameters (source, medium, campaign)
  • Referral codes

3.7 Fraud Prevention Data (MaxMind)

  • IP address processed to derive geolocation (country, region, city, timezone)
  • IP itself is never stored
  • Used for fraud detection and prevention

4. Information We Cannot Access (True Zero-Knowledge)

  • Core verification secrets and keys
  • Verification codes generated on device
  • Private cryptographic keys stored in device Keychain / Keystore
  • Device information such as name, model, or serial numbers

This ensures:

  • Trusted Codes cannot impersonate any user or their contacts
  • Verification remains secure even in server compromise

5. Information We Can Decrypt (Encrypted Metadata)

Data encrypted at rest can be decrypted only for legitimate operational purposes:

  • Email, display name, group or contact names
  • Connection metadata
  • Transactional email processing

6. How We Use Your Information

Trusted Codes uses collected information for:

  • Account creation and authentication
  • Multi-device synchronization
  • Sending connection invitations and alerts
  • Fraud detection and security monitoring
  • Improving service quality through aggregated analytics
  • AI-powered in-app help

We do not:

  • Sell your personal information
  • Track your activity outside the app
  • Share decrypted personal data with third parties without legal basis

7. Legal Basis for Processing (Article 6 GDPR)

Data CategoryProcessing PurposeLegal Basis (Art. 6)
Email, Display NameAccount creation, authentication, supportArt. 6(1)(b)
Device InformationService delivery, synchronizationArt. 6(1)(b)
Connection Data (metadata)Core functionalityArt. 6(1)(b)
Codeword SecretsVerification code generationArt. 6(1)(b)
Push Notification TokensDelivering invitations and alertsArt. 6(1)(b)
Activity LogsSecurity monitoring, troubleshootingArt. 6(1)(f)
AI Chat QuestionsSupport and documentationArt. 6(1)(f)
Anonymized AnalyticsService improvementArt. 6(1)(f)
MaxMind Fraud Prevention & IP GeolocationFraud prevention & geolocationArt. 6(1)(f)
Marketing AttributionUnderstand acquisition channelsArt. 6(1)(f)

8. AI-Powered Help (Google Gemini)

Trusted Codes integrates Google Gemini to provide in-app help:

  • User submits question → sent to Google Gemini API
  • No user identifiers are shared
  • Data processing agreement ensures no model training with your data
  • Chat logs retained for 90 days, then auto-deleted
  • Aggregate analysis used to improve documentation

Legal basis: Art. 6(1)(f) GDPR – legitimate interest in user support

9. Data Security

  • AES-256 encryption at rest
  • TLS 1.3 encryption in transit
  • Key separation via a dedicated key custody service
  • Device-local secure storage for cryptographic keys
  • No plaintext sensitive data stored outside user device

10. Data Retention

Data TypeRetention PeriodDeletion MethodTrigger
Account infoUntil account deletionAutomaticUser deletes account
Device infoUntil device removedAutomaticDevice removal / account deletion
Connection dataUntil connection deletedAutomaticEither party deletes connection
Connection secretsUntil connection deletedAutomaticConnection deletion
Activity logs90 daysAutomaticTime-based
AI chat logs90 daysAutomaticTime-based
Push tokensUntil device removedAutomaticDevice removal
Anonymized analyticsIndefiniteN/ANot personal data
Stripe billing recordsPer Stripe policy (~7 years)Retained by StripeLegal/tax requirement

Account and connection data are retained for the duration of the user account and deleted or anonymised within a reasonable period following account deletion, unless legal obligations require longer retention.

11. Account Deletion

Users can delete their account at any time via app settings. This triggers:

  • Automatic deletion of account, device info, connections, and secrets
  • Removal from all operational metadata
  • Deletion of push notification tokens

12. Third-Party Services (Sub-Processor List)

The list below is versioned and dated in its own right, and is also published at trusted.codes/legal/subprocessors and as Annex 2 of the Data Processing Agreement. The three are rendered from one source, so they cannot disagree.

Actualizada a 2026-07-30

Servicio principal

Se emplean para todos los clientes del servicio alojado.

ProveedorFinalidadUbicaciónDatos compartidosBase de la transferencia
SupabaseBase de datos, autenticación, funciones de servidor y almacenamiento de archivosUnión Europea (Estocolmo); operador establecido en Estados UnidosTodos los datos de cuenta, verificación y facturación del servicioCláusulas contractuales tipo (2021/914)
VercelAlojamiento de los portales web y del sitio públicoEstados Unidos, con regiones perimetrales europeasMetadatos de la solicitud: dirección de origen, agente de usuario, ruta solicitadaCláusulas contractuales tipo (2021/914)
InfisicalCustodia de las claves que protegen los datos en reposoUnión EuropeaSolo claves de cifrado — ningún dato personalDentro del EEE
StripeProcesamiento de pagos y facturación de suscripcionesIrlanda y Estados UnidosNombre y dirección de facturación, número de identificación fiscal, estado de la suscripción. Los datos de la tarjeta nunca llegan a Trusted Codes.Cláusulas contractuales tipo (2021/914)
ResendEntrega de correo electrónico transaccionalEstados UnidosDirección de correo electrónico y contenido del mensaje, descifrado en el momento del envíoCláusulas contractuales tipo (2021/914)
ExpoRetransmisión de notificaciones push a los servicios de entrega de Apple y GoogleEstados UnidosToken push y contenido de la notificaciónCláusulas contractuales tipo (2021/914)
MaxMindPuntuación de fraude y ubicación aproximada al iniciar sesiónEstados UnidosDirección de origen, dirección de correo electrónico, señales del dispositivoCláusulas contractuales tipo (2021/914)
Google (Gemini)Generación de la respuesta del asistente de ayuda de la aplicaciónEstados UnidosLa pregunta formulada y los artículos de ayuda recuperados para ellaCláusulas contractuales tipo (2021/914)
OpenAIConversión de una pregunta de ayuda en un vector de búsqueda e indexación de los artículos de ayudaEstados UnidosLa pregunta formulada y el texto de los artículos de ayuda publicadosCláusulas contractuales tipo (2021/914)
MetabasePaneles de análisis dentro de la consola de administraciónInfraestructura operada por Trusted CodesCifras agregadas consultadas en la base de datos del servicioOperado por Trusted Codes

Opcionales y elegidos por el usuario

Se emplean solo cuando el usuario final elige la función o cuando el componente está configurado.

ProveedorFinalidadUbicaciónDatos compartidosBase de la transferencia
AppleInicio de sesión, cuando el usuario final lo eligeEstados UnidosNombre y dirección de correo electrónico, o la dirección de reenvío que emite AppleCláusulas contractuales tipo (2021/914)
GoogleInicio de sesión, cuando el usuario final lo eligeEstados UnidosNombre y dirección de correo electrónicoCláusulas contractuales tipo (2021/914)
SentrySupervisión de errores en la aplicación móvilUnión Europea (región alemana)Informes de error: traza de la pila, versión de la aplicación, modelo del dispositivoDentro del EEE

Solo sitio web público

Afectan a las visitas de trusted.codes, no a los usuarios del servicio.

ProveedorFinalidadUbicaciónDatos compartidosBase de la transferencia
Plausible AnalyticsEstadísticas de visitas del sitio públicoInfraestructura operada por Trusted CodesPágina solicitada y referente, sin cookies ni identificadoresOperado por Trusted Codes
Google (Sheets and Apps Script)Recepción del formulario de contacto y del formulario de lista de esperaEstados UnidosLo que el remitente escribió en el formularioCláusulas contractuales tipo (2021/914)
SentrySupervisión de errores del sitio web, cuando está configuradaUnión Europea (región alemana)Informes de error: traza de la pila, navegador, páginaDentro del EEE

Note: List may change; material changes notified with 30-day notice.

13. International Data Transfers

Wherever possible, we have chosen Europe as the deployment region for our sub-processors to minimize international data transfers.

Safeguards:

  • Standard Contractual Clauses (2021 SCCs) with all US sub-processors
  • Data Processing Agreements (DPAs) in place
  • AES-256 encryption at rest, TLS 1.3 in transit
  • Separation of encryption keys from data

For SCCs or details: privacy@trusted.codes

14. Cookies and Local Storage

We do not use:

  • Cookies (session, tracking, analytics)
  • Tracking pixels or web beacons
  • Browser fingerprinting or cross-site tracking
  • Advertising identifiers

Mobile apps store locally:

  • Private cryptographic keys
  • Encrypted connection secrets
  • User settings

Security:

  • Protected by device PIN or biometrics
  • Never transmitted to servers
  • Deleted on uninstall or account deletion

Website: Uses Plausible Analytics (cookie-free, anonymous)

15. Your Rights (GDPR + CCPA)

GDPR Rights (EU/EEA)

  • Right of Access (Art. 15)
  • Right to Rectification (Art. 16)
  • Right to Erasure (Art. 17)
  • Right to Restriction (Art. 18)
  • Right to Data Portability (Art. 20)
  • Right to Object (Art. 21)
  • Right to Withdraw Consent

Exercise rights: privacy@trusted.codes, 30-day response. ID verification may be requested.

Complaint: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)

CCPA Rights (California)

  • Right to know collected information
  • Right to know if info is sold (we do not sell)
  • Right to deletion
  • Right to non-discrimination

Requests may be submitted via email to privacy@trusted.codes. Trusted Codes may need to verify the requester's identity before fulfilling a request.

16. Data Breach Notification

In case of personal data breach posing risk to rights/freedoms:

  • Notify BayLDA within 72 hours
  • Notify affected users if high risk
  • Include breach nature, likely consequences, measures taken

Contact: privacy@trusted.codes

17. Children's Privacy

Trusted Codes does not knowingly process personal data of children under the age of 16. If such processing becomes known, the data will be deleted without undue delay.

In any event, parents may request deletion via privacy@trusted.codes.

18. Data Protection Officer Status

No DPO appointed because:

  • Core activity is verification, not monitoring
  • True zero-knowledge for core data
  • No special category data processed
  • Limited personal data collected

Privacy inquiries: privacy@trusted.codes

19. Changes to This Policy

Updates may occur. Notification via:

  • Updating 'Last Updated' date
  • Email for significant changes
  • App notice for material changes

Changes effective 30 days after posting unless legally required otherwise.

20. Contact Us

Trusted Codes