Informativa sulla privacy
Versione 2026-07-30
In vigore dal 2026-07-30
Questa è la versione vigente. Indirizzo permanente di questa versione
1. Introduction
Welcome to Trusted Codes. We are committed to protecting your privacy and ensuring transparency about how we handle your data. Trusted Codes is operated by:
Stefan Sonntag
Trading as: Trusted Codes (Sole Proprietor / Einzelunternehmer)
Leonrodstr. 14b, 80634 Munich, Germany
Contact:
- Privacy: privacy@trusted.codes
- Legal: legal@trusted.codes
Jurisdiction: German law, courts of Munich
About the Service:
Trusted Codes is an identity verification solution designed to protect against impersonation, deepfakes, and AI-based voice cloning. The service generates rotating three-word verification codes, enabling users to confirm contact consistency across any communication channel. The app works 100% offline after initial setup and is available on iOS and Android.
Pricing Tiers:
- Free: Personal use, limited connections
- Pro: Paid subscription with expanded features
- Business: Paid subscription for organisations (B2B only), governed additionally by the Data Processing Agreement
2. Two-Tier Data Protection Architecture
Trusted Codes uses a two-tier data protection model, designed to balance security, privacy, and operational needs. We are transparent about what we can and cannot access.
2.1 Tier 1 – True Zero-Knowledge (Core Security)
The "zero-knowledge" properties described in this section apply only to the data types listed below (together, "Tier 1 Data") and mean Trusted Codes cannot access the plaintext of such Tier 1 Data, including under legal compulsion. This does not mean Trusted Codes does not process personal data generally; Trusted Codes continues to process certain account, device, and operational data described elsewhere in this Privacy Policy as a data controller.
| Data Type | Storage Location | Access |
|---|---|---|
| Codeword derivation secrets | Encrypted on server + device | Only user devices can decrypt |
| Verification codes | Generated locally on device | Never transmitted |
| Private cryptographic keys | Device secure enclave (Keychain / Keystore) | Never leaves device |
Implications:
- Trusted Codes cannot generate verification codes for users.
- Trusted Codes cannot impersonate your contacts.
- Even in a server breach, core verification functionality cannot be compromised.
2.2 Tier 2 – Encrypted Metadata (Decryptable for Legitimate Operations)
Other data is encrypted at rest using AES-256. The encryption keys are held by a dedicated key custody service in the European Union, separate from the databases, so that access to one system does not yield the other.
| Data Type | Encryption Status | Who Can Decrypt |
|---|---|---|
| Email addresses | AES-256 encrypted | Trusted Codes (via the key custody service) |
| Display names | AES-256 encrypted | Trusted Codes (via the key custody service) |
| Device names | AES-256 encrypted | Trusted Codes (via the key custody service) |
| Contact names (user-assigned) | AES-256 encrypted | Trusted Codes (via the key custody service) |
| Connection metadata | AES-256 encrypted | Trusted Codes (via the key custody service) |
Database administrators do not have access to decryption keys.
Decryption occurs only for:
- User support requests
- Account recovery procedures
- Responding to valid legal orders
- Fraud investigation and prevention
- Sending transactional emails
Important: Metadata decryption is not zero-knowledge. Trusted Codes can access email and display name if operationally required.
3. Information We Collect
Trusted Codes collects minimal data to operate and secure the service. Data is divided into the following categories:
3.1 Account Information (Encrypted – Decryptable)
- Email address
- Display name
- Preferred language (plaintext for service delivery)
- Account creation date
3.2 Device Information
- Platform type (iOS / Android)
- Push notification token
- Public cryptographic key
- Device fingerprint (hash of public key + device metadata)
3.3 Connection Information
- Contact names you assign (encrypted – decryptable)
- Encrypted cryptographic secrets (TRUE ZERO-KNOWLEDGE)
- Connection metadata (timestamps, connection status)
3.4 Activity Logs (Auto-deleted after 90 days)
- Login events
- Account actions (connection creation, member management)
- Trust ratings given
- AI chat questions
Not logged: IP addresses, user agent strings
3.5 Analytics (Truly Anonymized)
- Aggregated event counts (account created, connection created, verification success/failure)
- No user or device identifiers
- No IP addresses
- Cannot be reverse-engineered
- Retained indefinitely as non-personal data
3.6 Marketing Attribution (Optional)
- UTM parameters (source, medium, campaign)
- Referral codes
3.7 Fraud Prevention Data (MaxMind)
- IP address processed to derive geolocation (country, region, city, timezone)
- IP itself is never stored
- Used for fraud detection and prevention
4. Information We Cannot Access (True Zero-Knowledge)
- Core verification secrets and keys
- Verification codes generated on device
- Private cryptographic keys stored in device Keychain / Keystore
- Device information such as name, model, or serial numbers
This ensures:
- Trusted Codes cannot impersonate any user or their contacts
- Verification remains secure even in server compromise
5. Information We Can Decrypt (Encrypted Metadata)
Data encrypted at rest can be decrypted only for legitimate operational purposes:
- Email, display name, group or contact names
- Connection metadata
- Transactional email processing
6. How We Use Your Information
Trusted Codes uses collected information for:
- Account creation and authentication
- Multi-device synchronization
- Sending connection invitations and alerts
- Fraud detection and security monitoring
- Improving service quality through aggregated analytics
- AI-powered in-app help
We do not:
- Sell your personal information
- Track your activity outside the app
- Share decrypted personal data with third parties without legal basis
7. Legal Basis for Processing (Article 6 GDPR)
| Data Category | Processing Purpose | Legal Basis (Art. 6) |
|---|---|---|
| Email, Display Name | Account creation, authentication, support | Art. 6(1)(b) |
| Device Information | Service delivery, synchronization | Art. 6(1)(b) |
| Connection Data (metadata) | Core functionality | Art. 6(1)(b) |
| Codeword Secrets | Verification code generation | Art. 6(1)(b) |
| Push Notification Tokens | Delivering invitations and alerts | Art. 6(1)(b) |
| Activity Logs | Security monitoring, troubleshooting | Art. 6(1)(f) |
| AI Chat Questions | Support and documentation | Art. 6(1)(f) |
| Anonymized Analytics | Service improvement | Art. 6(1)(f) |
| MaxMind Fraud Prevention & IP Geolocation | Fraud prevention & geolocation | Art. 6(1)(f) |
| Marketing Attribution | Understand acquisition channels | Art. 6(1)(f) |
8. AI-Powered Help (Google Gemini)
Trusted Codes integrates Google Gemini to provide in-app help:
- User submits question → sent to Google Gemini API
- No user identifiers are shared
- Data processing agreement ensures no model training with your data
- Chat logs retained for 90 days, then auto-deleted
- Aggregate analysis used to improve documentation
Legal basis: Art. 6(1)(f) GDPR – legitimate interest in user support
9. Data Security
- AES-256 encryption at rest
- TLS 1.3 encryption in transit
- Key separation via a dedicated key custody service
- Device-local secure storage for cryptographic keys
- No plaintext sensitive data stored outside user device
10. Data Retention
| Data Type | Retention Period | Deletion Method | Trigger |
|---|---|---|---|
| Account info | Until account deletion | Automatic | User deletes account |
| Device info | Until device removed | Automatic | Device removal / account deletion |
| Connection data | Until connection deleted | Automatic | Either party deletes connection |
| Connection secrets | Until connection deleted | Automatic | Connection deletion |
| Activity logs | 90 days | Automatic | Time-based |
| AI chat logs | 90 days | Automatic | Time-based |
| Push tokens | Until device removed | Automatic | Device removal |
| Anonymized analytics | Indefinite | N/A | Not personal data |
| Stripe billing records | Per Stripe policy (~7 years) | Retained by Stripe | Legal/tax requirement |
Account and connection data are retained for the duration of the user account and deleted or anonymised within a reasonable period following account deletion, unless legal obligations require longer retention.
11. Account Deletion
Users can delete their account at any time via app settings. This triggers:
- Automatic deletion of account, device info, connections, and secrets
- Removal from all operational metadata
- Deletion of push notification tokens
12. Third-Party Services (Sub-Processor List)
The list below is versioned and dated in its own right, and is also published at trusted.codes/legal/subprocessors and as Annex 2 of the Data Processing Agreement. The three are rendered from one source, so they cannot disagree.
Aggiornata al 2026-07-30
Servizio principale
Impiegati per ogni cliente del servizio ospitato.
| Fornitore | Finalità | Luogo | Dati condivisi | Base del trasferimento |
|---|---|---|---|---|
| Supabase | Base di dati, autenticazione, funzioni server e archiviazione di file | Unione europea (Stoccolma); gestore stabilito negli Stati Uniti | Tutti i dati di account, verifica e fatturazione del servizio | Clausole contrattuali tipo (2021/914) |
| Vercel | Hosting dei portali web e del sito pubblico | Stati Uniti, con regioni perimetrali europee | Metadati della richiesta: indirizzo di origine, agente utente, percorso richiesto | Clausole contrattuali tipo (2021/914) |
| Infisical | Custodia delle chiavi che proteggono i dati a riposo | Unione europea | Solo chiavi di cifratura — nessun dato personale | All’interno del SEE |
| Stripe | Elaborazione dei pagamenti e fatturazione degli abbonamenti | Irlanda e Stati Uniti | Nome e indirizzo di fatturazione, numero di identificazione fiscale, stato dell’abbonamento. I dati della carta non raggiungono mai Trusted Codes. | Clausole contrattuali tipo (2021/914) |
| Resend | Consegna della posta elettronica transazionale | Stati Uniti | Indirizzo di posta elettronica e contenuto del messaggio, decifrato al momento dell’invio | Clausole contrattuali tipo (2021/914) |
| Expo | Inoltro delle notifiche push ai servizi di consegna di Apple e Google | Stati Uniti | Token push e contenuto della notifica | Clausole contrattuali tipo (2021/914) |
| MaxMind | Punteggio antifrode e posizione approssimativa all’accesso | Stati Uniti | Indirizzo di origine, indirizzo di posta elettronica, segnali del dispositivo | Clausole contrattuali tipo (2021/914) |
| Google (Gemini) | Generazione della risposta dell’assistente di aiuto nell’app | Stati Uniti | La domanda posta e gli articoli di aiuto recuperati per rispondervi | Clausole contrattuali tipo (2021/914) |
| OpenAI | Trasformazione di una domanda di aiuto in un vettore di ricerca e indicizzazione degli articoli di aiuto | Stati Uniti | La domanda posta e il testo degli articoli di aiuto pubblicati | Clausole contrattuali tipo (2021/914) |
| Metabase | Cruscotti analitici nella console di amministrazione | Infrastruttura gestita da Trusted Codes | Dati aggregati interrogati dalla base di dati del servizio | Gestito da Trusted Codes |
Opzionali e scelti dall’utente
Impiegati solo quando l’utente finale sceglie la funzione o quando il componente è configurato.
| Fornitore | Finalità | Luogo | Dati condivisi | Base del trasferimento |
|---|---|---|---|---|
| Apple | Accesso, quando l’utente finale lo sceglie | Stati Uniti | Nome e indirizzo di posta elettronica, oppure l’indirizzo di inoltro emesso da Apple | Clausole contrattuali tipo (2021/914) |
| Accesso, quando l’utente finale lo sceglie | Stati Uniti | Nome e indirizzo di posta elettronica | Clausole contrattuali tipo (2021/914) | |
| Sentry | Monitoraggio degli errori nell’applicazione mobile | Unione europea (regione tedesca) | Segnalazioni di errore: traccia dello stack, versione dell’applicazione, modello del dispositivo | All’interno del SEE |
Solo sito pubblico
Riguardano i visitatori di trusted.codes, non gli utenti del servizio.
| Fornitore | Finalità | Luogo | Dati condivisi | Base del trasferimento |
|---|---|---|---|---|
| Plausible Analytics | Statistiche dei visitatori del sito pubblico | Infrastruttura gestita da Trusted Codes | Pagina richiesta e referente, senza cookie e senza identificativi | Gestito da Trusted Codes |
| Google (Sheets and Apps Script) | Ricezione del modulo di contatto e del modulo della lista d’attesa | Stati Uniti | Ciò che il mittente ha scritto nel modulo | Clausole contrattuali tipo (2021/914) |
| Sentry | Monitoraggio degli errori del sito, quando configurato | Unione europea (regione tedesca) | Segnalazioni di errore: traccia dello stack, browser, pagina | All’interno del SEE |
Note: List may change; material changes notified with 30-day notice.
13. International Data Transfers
Wherever possible, we have chosen Europe as the deployment region for our sub-processors to minimize international data transfers.
Safeguards:
- Standard Contractual Clauses (2021 SCCs) with all US sub-processors
- Data Processing Agreements (DPAs) in place
- AES-256 encryption at rest, TLS 1.3 in transit
- Separation of encryption keys from data
For SCCs or details: privacy@trusted.codes
14. Cookies and Local Storage
We do not use:
- Cookies (session, tracking, analytics)
- Tracking pixels or web beacons
- Browser fingerprinting or cross-site tracking
- Advertising identifiers
Mobile apps store locally:
- Private cryptographic keys
- Encrypted connection secrets
- User settings
Security:
- Protected by device PIN or biometrics
- Never transmitted to servers
- Deleted on uninstall or account deletion
Website: Uses Plausible Analytics (cookie-free, anonymous)
15. Your Rights (GDPR + CCPA)
GDPR Rights (EU/EEA)
- Right of Access (Art. 15)
- Right to Rectification (Art. 16)
- Right to Erasure (Art. 17)
- Right to Restriction (Art. 18)
- Right to Data Portability (Art. 20)
- Right to Object (Art. 21)
- Right to Withdraw Consent
Exercise rights: privacy@trusted.codes, 30-day response. ID verification may be requested.
Complaint: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
CCPA Rights (California)
- Right to know collected information
- Right to know if info is sold (we do not sell)
- Right to deletion
- Right to non-discrimination
Requests may be submitted via email to privacy@trusted.codes. Trusted Codes may need to verify the requester's identity before fulfilling a request.
16. Data Breach Notification
In case of personal data breach posing risk to rights/freedoms:
- Notify BayLDA within 72 hours
- Notify affected users if high risk
- Include breach nature, likely consequences, measures taken
Contact: privacy@trusted.codes
17. Children's Privacy
Trusted Codes does not knowingly process personal data of children under the age of 16. If such processing becomes known, the data will be deleted without undue delay.
In any event, parents may request deletion via privacy@trusted.codes.
18. Data Protection Officer Status
No DPO appointed because:
- Core activity is verification, not monitoring
- True zero-knowledge for core data
- No special category data processed
- Limited personal data collected
Privacy inquiries: privacy@trusted.codes
19. Changes to This Policy
Updates may occur. Notification via:
- Updating 'Last Updated' date
- Email for significant changes
- App notice for material changes
Changes effective 30 days after posting unless legally required otherwise.
20. Contact Us
Trusted Codes
- Privacy: privacy@trusted.codes
- Legal: legal@trusted.codes