KKoine

Koine Privacy Policy

Pending legal review. The company details below are final; the effective

date is set at publication, and this document is undergoing review by a

qualified attorney before it is relied upon.

Effective date: to be set at publication
Last updated: 2026-07-15

Koine is a messenger that delivers what you mean, not just what you type. To do that, it processes some of your messages with AI translation services. This policy explains — plainly and specifically — what data we collect, why, who processes it, how long we keep it, and the rights you have. We wrote it to match what the product actually does, not what a template says.

1. Who is responsible for your data (Data Controller)

Controller: Koine
Address: Konstantinou Kanari 10, Greece

Contact: info@koineapp.com

The controller is established in Greece (European Union). The EU General Data Protection Regulation (GDPR) applies to all processing described here. Our supervisory authority is the Hellenic Data Protection Authority (HDPA) — see Section 11 for how to lodge a complaint.

2. The most important thing to understand: two kinds of chats

Koine has two distinct conversation types, and they are treated completely differently:

Normal conversations (the default)

When you send a message in a normal conversation, the message text is processed on our servers so we can deliver your intention across languages. This means:

  • Your message text is sent to one or more third-party AI providers (see Section 5) to produce a translation.
  • The translated result is stored alongside the original message so recipients (and you) can view it.
  • Translations are cached temporarily so repeated identical requests don't require re-processing.

If you are not comfortable with server-side AI processing of a conversation, use a Private chat.

Private chats (end-to-end encrypted)

Private chats are end-to-end encrypted using the X3DH key-agreement and Double Ratchet protocols. For these:

  • Encryption keys are generated and held only on your devices. We publish only your public key material (identity key, signed prekey, one-time prekeys) so other users can start encrypted sessions with you.
  • Our servers route and temporarily store ciphertext only. We cannot read private chat content, and our database rejects any attempt to store plaintext in a private conversation.
  • Private chats are never sent to AI providers and are never translated by us.
  • Because we cannot read them, we also cannot recover private chat content if you lose your devices.

3. What we collect

CategoryWhat it isWhere it comes from
Phone numberYour phone number, verified by SMS one-time codeYou, at sign-up
Profile dataDisplay name, optional profile photo, preferred language, status/about textYou
Messages & translations (normal chats)Message text, media attachments, and the AI-generated translations we produce and store for deliveryYou and our translation pipeline
Private chat ciphertextEncrypted message payloads we cannot decrypt, plus your public key materialYour device (encrypted before it leaves)
Hashed contacts (optional)SHA-256 hashes of phone numbers from your address book — the raw numbers never leave your device. We compare hashes to registered users to tell you when a contact joinsYou, only if you enable contact sync
MediaPhotos, files, voice notes, and story content you uploadYou
StoriesStory media and its viewer list — automatically deleted after 24 hoursYou
Usage & entitlement dataSubscription/plan status, translation-credit balance, daily translation counts (free tier is capped at 40 outbound translations/day)Generated by your use of the service
Device push tokensTokens that let us deliver notifications via Expo, Apple (APNs), Google (FCM), or web pushYour device, if you enable notifications
Voice channel dataReal-time audio in voice channels transits LiveKit infrastructure (see Section 5); we do not record calls. Live captions, if enabled, are processed like normal messagesGenerated during voice sessions
Reports & blocksReports you file about other users/content, and your block listYou
Technical logsStandard server logs (timestamps, request metadata) for security and debugging. Our telemetry deliberately records message lengths, not message textGenerated automatically

We do not collect: your raw address book, your precise location, advertising identifiers, or payment card numbers (see Section 5 — Stripe/app stores handle payment details; we never see card numbers).

4. Why we process your data (lawful bases)

Under GDPR Article 6, every processing purpose needs a legal basis. Ours are:

PurposeLegal basis
Providing the messaging service itself — delivering messages, producing and storing translations for normal chats, routing private-chat ciphertext, hosting media, running voice channels, sending notificationsContract (Art. 6(1)(b)) — this is the service you signed up for
Verifying your phone number by SMS codeContract (Art. 6(1)(b))
Contact sync (uploading hashed numbers) and being discoverable to contacts who joinConsent (Art. 6(1)(a)) — off by default; you enable contact sync explicitly and control discoverability with the "Discoverable" privacy setting. You can withdraw consent at any time in Settings
Abuse prevention: rate limiting, blocking, processing reports, enforcing our TermsLegitimate interest (Art. 6(1)(f)) — keeping the service safe for everyone
Processing subscription and credit purchasesContract (Art. 6(1)(b)) and legal obligations (tax/accounting records)
Complying with valid legal requestsLegal obligation (Art. 6(1)(c))

We do not use your data for advertising, we do not sell it, and we do not build profiles for marketing.

5. Who processes your data on our behalf

We use a small set of processors, each for a specific job. They act under data-processing agreements and only on our instructions.

AI translation providers — this is the part to read carefully

For normal conversations only, the text of your messages is sent to one or more of the following AI providers to produce translations:

  • Anthropic (Claude models)
  • OpenAI
  • DeepL

Which providers are used depends on our current configuration; any given message may be processed by any of the configured providers. These providers receive the message text and return a translation. Private chats are never sent to any AI provider.

Whether these providers may use submitted content for model training depends on the specific data-processing agreement and API terms in force with each provider. Under the standard API terms of Anthropic, OpenAI, and DeepL, content submitted through their APIs is not used to train their models.

Other processors

ProcessorWhat they doWhat they receive
TwilioSends the SMS verification code at sign-inYour phone number
SupabaseStores uploaded media in a private bucket; files are served via short-lived signed URLsYour uploaded media; database hosting
LiveKitReal-time voice infrastructure — audio in voice channels transits their serversVoice audio streams (not recorded by us)
Expo / Apple APNs / Google FCM / web push servicesDeliver push notifications to your devicesDevice push tokens and notification payloads
Stripe (web)Payment processing for Premium and credit packsPayment details — entered directly with Stripe; we never see your card number
Apple App Store / Google Play via RevenueCat (mobile)In-app purchase processing and subscription managementPurchase and entitlement records; payment details stay with the app store
RenderRuns our servers and database (managed hosting)All server-side data described in Section 3

6. International transfers

Several processors listed above (including the AI providers, Twilio, Supabase, LiveKit, Expo, and Stripe) are established in or process data in the United States or other countries outside the EEA. Where personal data is transferred outside the EEA, we rely on the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the EU–US Data Privacy Framework.

7. How long we keep things (retention)

DataRetention
SMS one-time codes5 minutes (then expire)
Stories24 hours (then automatically deleted)
Translation cache30 days
Messages (normal and private) and stored translationsUntil you delete them or delete your account
Media attachmentsAs long as the message/story that references them
Hashed contactsUntil you disable contact sync or delete your account
Push tokensUntil the device unregisters or the account is deleted
Account data (profile, settings, entitlements)Until you delete your account
Payment/entitlement recordsAs required by tax and accounting law

Account deletion is available in-app (Settings → Account → Delete account) and performs a full erasure of your account data, messages, media, keys, hashed contacts, and tokens, subject only to records we are legally required to keep (e.g. payment records).

8. Your controls

You decide, in Settings:

  • Privacy settings: who sees your last-seen, profile photo, read receipts, and stories; whether you are Discoverable via contact-sync matching.
  • Blocking: blocked users cannot message you or see your presence.
  • Reporting: you can report users and content; reports are reviewed under our Terms of Service.
  • Contact sync: on/off at any time; turning it off stops hash uploads.
  • Notifications: per-device and per-conversation controls.

9. Your rights under GDPR

You have the right to:

  • Access & portability (Art. 15/20): use the in-app Data Export to download a machine-readable copy of your data, or contact us.
  • Erasure (Art. 17): delete individual messages, or delete your entire account in-app — no email required, no waiting on support.
  • Rectification (Art. 16): correct your profile data in-app, or ask us.
  • Objection (Art. 21): object to processing based on legitimate interest.
  • Restriction (Art. 18): ask us to restrict processing while a dispute is resolved.
  • Withdraw consent: for contact sync/discoverability, at any time in Settings, without affecting the rest of the service.

To exercise a right we can't satisfy in-app, contact info@koineapp.com. We respond within one month as required by GDPR.

10. Children

Koine is for users aged 16 or older. We ask you to confirm this at onboarding. We do not knowingly process data of anyone under 16; if we learn we have, we will delete the account. If you believe a child under 16 is using Koine, contact us at info@koineapp.com.

11. Complaints

If you believe we are processing your data unlawfully, you can lodge a complaint with the Hellenic Data Protection Authority (HDPA) — www.dpa.gr — or with the supervisory authority of your EU member state of residence. We'd appreciate the chance to resolve your concern first: info@koineapp.com.

12. Security

In addition to E2EE for private chats: media lives in a private storage bucket accessible only via short-lived signed URLs; all traffic is encrypted in transit (TLS); access to production systems is restricted; our logging deliberately avoids message content. No system is perfectly secure — if a breach affects your data, we will notify you and the HDPA as GDPR requires.

13. Changes to this policy

If we change this policy in a way that matters (new processors, new purposes, changed retention), we will notify you in-app before the change takes effect and give you a chance to review it. The current version is always available at https://koineapp.com/legal/privacy.

14. Contact

Koine
Konstantinou Kanari 10, Greece

info@koineapp.com

Koine · every language, your language