Privacy Policy
In force since 28 September 2026 (first published 8 September 2026). This is the whole of it — there is no longer version.
Logos collects nothing about you. There is no account, no registration, no phone number, no email. We — the people who make Logos — cannot read your messages and cannot see your contacts, and we keep no record of who you talk to or when. The rest of this page explains why that is true rather than merely stated.
What stays on your device and never leaves it
Everything Logos remembers is stored locally — in your browser's storage, or on Android in the app's own private storage:
- the cryptographic key pair that is your identity; the private half is created so it cannot be exported by any code, including ours;
- the name you chose to display, and your address or addresses;
- contacts you saved, and the three security words for each;
- your message history, and photos or files you received;
- your settings.
None of this is ever sent to us or to anyone else. Clearing the app's data, or uninstalling it, erases all of it. On your device this history is stored without additional encryption: someone with access to your unlocked phone can read it, as with most messengers.
What passes through the relay, and what the relay can see
To help two devices find each other at the start of a conversation, Logos uses a small relay — a Cloudflare Worker we operate. Once the two devices are connected the relay is out of the picture, and nothing either side says passes through it. No server we run can read anything you say, at any point.
While it is involved, the relay handles:
- Sealed envelopes — encrypted with AES-256-GCM before they reach the relay. The relay holds no key and cannot read them. The recipient deletes each one once it has read it, and in any case they expire within two minutes (a call being set up) or seven days (a letter left for someone who did not answer).
- Public keys — published so someone can dial your address. These are public by design. They expire after one year.
- Wake-up subscriptions — encrypted. They expire after 24 hours.
- Your IP address — seen by the relay only in passing, to limit abuse. It is held in memory, never written to storage, and discarded when the process recycles. We do not log it and it is not linked to anything.
On networks that block direct connections — some offices, some mobile operators — or when you switch on Hide where you are in the settings, the conversation goes through Cloudflare's TURN service instead of directly between the two devices; with that switch on, the other person never sees your internet address. It forwards the connection still end-to-end encrypted: it cannot read it, but like any network service it sees the two network addresses it connects.
Other companies involved
- Cloudflare operates the servers the relay runs on, and also hosts the promotional site at digitalvalut-logos.org. As the network operator, Cloudflare processes the requests that reach it and may log IP addresses at its edge, as any internet host does.
- GitHub hosts the application, the source code and this page (GitHub Pages). Standard web-server access applies on GitHub's side when you load a page.
- Your browser's push service — Google for Chrome, Mozilla for Firefox, Apple for Safari — is involved only if you switch on the optional wake-up notification in the browser version, and only to deliver a nudge with no content in it. The Android app does not use this: it contains no Google Play Services and no Firebase, and rings by reading its own encrypted mailbox directly.
There are no analytics, no telemetry, no crash reporting, no advertising identifiers and no tracking code anywhere in Logos. The app, and these pages on digitalvalut.github.io, load no third-party script or library at any point.
The promotional site digitalvalut-logos.org is a separate page, built with an external site builder (ChatLLM, by Abacus.AI). As of 28 September 2026 it loads a script from abacus.ai, the builder's own editing helper, and it collects anonymous, aggregated usage statistics, as its own privacy page states. We are having both removed. The app never depends on that site.
Photos
Before a JPEG or PNG is sent, Logos removes its embedded location, device model and software metadata on your device, without re-encoding the image.
Who is responsible (data controller)
Associazione di Promozione Sociale DigitalValut, an Italian non-profit association (Ente del Terzo Settore), C.F. 90036980846, is the controller of the little personal data described on this page. Contact: burbeng78@gmail.com; certified e-mail (PEC): digitalvalut@messaggipec.it. No Data Protection Officer has been appointed: the processing described here does not require one.
Legal basis and how long data is kept
Under the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679):
- Operating the relay — sealed envelopes, public keys, wake-up subscriptions, and the TURN connection on restrictive networks — is necessary to provide the service you choose to use (Art. 6(1)(b)). Kept only for the times stated above: two minutes, seven days, twenty-four hours, one year for a public key.
- Looking at your IP address to limit abuse rests on our legitimate interest in keeping the relay available and safe for everyone (Art. 6(1)(f)). It is held in memory only and never stored. You may object to it (Art. 21) by writing to us.
- The optional wake-up notification in the browser version rests on your consent (Art. 6(1)(a)), given by switching it on and withdrawn at any time by switching it off.
Using Logos does not require you to give us any personal data, and no decision about you is ever taken by automated means (Art. 22).
Transfers outside the European Union
Cloudflare, Inc. and GitHub, Inc. are based in the United States. Cloudflare processes relay traffic on our behalf under its customer Data Processing Addendum; GitHub serves these pages under its own privacy statement. Both companies are certified under the EU–U.S. Data Privacy Framework, and both also rely on the European Commission's Standard Contractual Clauses.
Your rights
You have the right to access, rectify and erase personal data about you, to restrict or object to its processing, and to data portability (Articles 15–22 GDPR). Because we hold no data that identifies you, there is normally nothing for us to show you, correct or delete — there is nothing there; if you believe otherwise, write to the address above and we will answer within one month. You can erase everything Logos has stored at any time by clearing the app's data or uninstalling it. You may lodge a complaint with a supervisory authority — in Italy, the Garante per la protezione dei dati personali (garanteprivacy.it), or the authority of the EU country where you live.
Children
Logos has no content feed, no discovery and no profiling, and it collects nothing. It is a communication tool, and a parent should supervise its use as with any messenger.
Changes
Any change to this policy is posted on this page with a new date. There is no mailing list to notify you through, because we do not have your email.
Informativa sulla privacy
In vigore dal 28 settembre 2026 (prima pubblicazione: 8 settembre 2026). Questo è tutto — non esiste una versione più lunga.
Logos non raccoglie nulla su di te. Non c'è un account, non c'è registrazione, non c'è numero di telefono, non c'è email. Noi — le persone che fanno Logos — non possiamo leggere i tuoi messaggi, non possiamo vedere i tuoi contatti, e non teniamo traccia di con chi parli né di quando. Il resto di questa pagina spiega perché è vero, non solo dichiarato.
Cosa resta sul tuo dispositivo e non lo lascia mai
Tutto ciò che Logos ricorda è salvato in locale — nella memoria del browser, o su Android nella memoria privata dell'app:
- la coppia di chiavi crittografiche che è la tua identità; la parte privata è creata in modo da non poter essere esportata da nessun codice, nemmeno il nostro;
- il nome che hai scelto di mostrare, e il tuo indirizzo o i tuoi indirizzi;
- i contatti che hai salvato, e le tre parole di sicurezza di ciascuno;
- la cronologia dei messaggi, e le foto o i file che hai ricevuto;
- le tue impostazioni.
Niente di tutto questo viene mai mandato a noi o a chiunque altro. Cancellare i dati dell'app, o disinstallarla, elimina tutto. Sul dispositivo questa cronologia è salvata senza cifratura aggiuntiva: chi ha accesso al tuo telefono sbloccato può leggerla, come nella maggior parte dei messenger.
Cosa passa dal relay, e cosa il relay può vedere
Per aiutare due dispositivi a trovarsi all'inizio di una conversazione, Logos usa un piccolo relay — un Cloudflare Worker che gestiamo noi. Appena i due dispositivi sono connessi, il relay esce di scena e niente di ciò che le due parti si dicono passa da lì. Nessun server che gestiamo può leggere niente di ciò che dici, in nessun momento.
Finché è coinvolto, il relay gestisce:
- Buste sigillate — cifrate con AES-256-GCM prima di arrivare al relay. Il relay non ha nessuna chiave e non può leggerle. Chi le riceve le cancella appena le ha lette, e comunque scadono entro due minuti (una chiamata in fase di apertura) o sette giorni (una lettera lasciata a chi non ha risposto).
- Chiavi pubbliche — pubblicate perché qualcuno possa chiamare il tuo indirizzo. Sono pubbliche per progetto. Scadono dopo un anno.
- Iscrizioni al risveglio — cifrate. Scadono dopo 24 ore.
- Il tuo indirizzo IP — visto dal relay solo di passaggio, per limitare gli abusi. È tenuto in memoria, mai scritto su disco, e scartato quando il processo si ricicla. Non lo registriamo e non è collegato a nulla.
Sulle reti che bloccano i collegamenti diretti — alcuni uffici, alcuni operatori mobili — oppure quando accendi Nascondi dove sei nelle impostazioni, la conversazione passa dal servizio TURN di Cloudflare invece che direttamente fra i due dispositivi; con l'interruttore acceso, l'altra persona non vede mai il tuo indirizzo internet. Lo inoltra ancora cifrato da capo a capo: non può leggerlo, ma come ogni servizio di rete vede i due indirizzi di rete che mette in contatto.
Altre aziende coinvolte
- Cloudflare gestisce i server su cui gira il relay, e ospita anche il sito promozionale digitalvalut-logos.org. Come gestore della rete, Cloudflare elabora le richieste che le arrivano e può registrare indirizzi IP ai suoi margini, come qualsiasi host internet.
- GitHub ospita l'applicazione, il codice sorgente e questa pagina (GitHub Pages). Quando carichi una pagina, dal lato di GitHub si applica il normale accesso a un server web.
- Il servizio di notifiche del tuo browser — Google per Chrome, Mozilla per Firefox, Apple per Safari — è coinvolto solo se accendi la notifica di risveglio opzionale nella versione browser, e solo per consegnare un colpetto senza contenuto. L'app Android non lo usa: non contiene Google Play Services né Firebase, e squilla leggendo direttamente la propria casella cifrata.
Non ci sono analytics, né telemetria, né segnalazione di crash, né identificatori pubblicitari, né codice di tracciamento da nessuna parte in Logos. L'app, e queste pagine su digitalvalut.github.io, non caricano mai nessuno script o libreria di terze parti.
Il sito promozionale digitalvalut-logos.org è una pagina a parte, costruita con uno strumento esterno (ChatLLM, di Abacus.AI). Al 28 settembre 2026 carica uno script da abacus.ai, l'aiuto alla modifica dello strumento stesso, e raccoglie statistiche d'uso anonime e aggregate, come dice la sua informativa. Stiamo facendo togliere entrambe le cose. L'app non dipende mai da quel sito.
Foto
Prima che un JPEG o un PNG venga inviato, Logos rimuove sul tuo dispositivo la posizione, il modello del telefono e i metadati del software incorporati, senza ricomprimere l'immagine.
Chi è il titolare del trattamento
Associazione di Promozione Sociale DigitalValut, associazione italiana senza scopo di lucro (Ente del Terzo Settore), C.F. 90036980846, è titolare del trattamento dei pochi dati personali descritti in questa pagina. Contatto: burbeng78@gmail.com; posta certificata (PEC): digitalvalut@messaggipec.it. Non è stato nominato un Responsabile della protezione dei dati (RPD/DPO): il trattamento descritto qui non lo richiede.
Base giuridica e tempi di conservazione
Ai sensi del Regolamento generale sulla protezione dei dati (GDPR, Regolamento (UE) 2016/679):
- Il funzionamento del relay — buste sigillate, chiavi pubbliche, iscrizioni al risveglio, e il collegamento TURN sulle reti chiuse — è necessario per fornirti il servizio che scegli di usare (art. 6, par. 1, lett. b). I dati restano solo per i tempi indicati sopra: due minuti, sette giorni, ventiquattro ore, un anno per una chiave pubblica.
- Guardare il tuo indirizzo IP per limitare gli abusi si basa sul nostro legittimo interesse a mantenere il relay disponibile e sicuro per tutti (art. 6, par. 1, lett. f). È tenuto solo in memoria e mai salvato. Puoi opporti (art. 21) scrivendoci.
- La notifica di risveglio opzionale nella versione browser si basa sul tuo consenso (art. 6, par. 1, lett. a), che dai accendendola e revochi in qualsiasi momento spegnendola.
Per usare Logos non devi fornirci alcun dato personale, e nessuna decisione che ti riguarda viene mai presa in modo automatizzato (art. 22).
Trasferimenti fuori dall'Unione europea
Cloudflare, Inc. e GitHub, Inc. hanno sede negli Stati Uniti. Cloudflare tratta il traffico del relay per nostro conto in base al proprio accordo sul trattamento dei dati per i clienti (Data Processing Addendum); GitHub serve queste pagine in base alla propria informativa. Entrambe le società sono certificate secondo il Data Privacy Framework UE–USA, ed entrambe si basano anche sulle clausole contrattuali standard della Commissione europea.
I tuoi diritti
Hai diritto di accesso, rettifica e cancellazione dei dati personali che ti riguardano, di limitazione e di opposizione al trattamento, e alla portabilità dei dati (articoli 15–22 del GDPR). Poiché non deteniamo alcun dato che ti identifichi, di norma non c'è nulla da mostrarti, correggere o cancellare — non c'è niente; se pensi il contrario, scrivi agli indirizzi qui sopra e ti risponderemo entro un mese. Puoi cancellare tutto ciò che Logos ha salvato in qualsiasi momento svuotando i dati dell'app o disinstallandola. Puoi presentare reclamo a un'autorità di controllo — in Italia il Garante per la protezione dei dati personali (garanteprivacy.it), oppure l'autorità del Paese dell'UE in cui vivi.
Minori
Logos non ha un feed di contenuti, non ha scoperta e non fa profilazione, e non raccoglie nulla. È uno strumento di comunicazione, e un genitore dovrebbe vigilare sul suo uso come per qualsiasi messenger.
Modifiche
Ogni modifica a questa informativa viene pubblicata su questa pagina con una nuova data. Non c'è una lista a cui avvisarti, perché non abbiamo la tua email.