Skip to content
Convivia

Legal

App Privacy Policy

Last updated: September 18, 2026 · applies to the “Convivia” app on iPhone, iPad and Mac

This is an English translation provided for convenience. In case of doubt, the German version is authoritative.

Responsible party

Mohamadreza Khostevan · Miroo Media
Stettiner Str. 9, 28870 Ottersberg, Germany
Email: convivia@miroo-media.de
Phone: +49 4205 6354726

1. The most important things first

Convivia works without an account and without registration. The app contains no analytics, tracking, or advertising services, no third-party code, and sends no crash reports to third parties. We operate no servers of our own: the only service through which the app exchanges data is Apple's iCloud (CloudKit). Posts live there in the iCloud storage of the person who put them up — not with us.

All content is encrypted on your device before upload (end-to-end encryption). The keys exist only on the devices of the respective group. We cannot read the content and could not hand it over.

2. What data the app processes

The following categories of data arise during use:

  • Your display name, which you choose freely on first launch. It is not verified and not linked to any account; its sole purpose is that the others in the group know who a post is from.
  • Photos and Live Photos that you post — as unmodified originals including their capture metadata (see section 6).
  • Group data: group name, occasion names, member list, and the information of who posted what when and who reported “done” when.
  • Technical data: randomly generated device, member, and group identifiers as well as cryptographic keys.

The legal basis for processing is the fulfillment of the usage contract (Art. 6(1)(b) GDPR) or your consent (Art. 6(1)(a) GDPR), which you give via the system dialogs. For the photos that members of a group share with each other, the members themselves are responsible within the scope of their personal and family use.

3. End-to-end encryption

Every post is encrypted on your device with AES-256 before it leaves it. The group key is handed over individually encrypted for each member device and exists only in the devices' keychains — on devices with a Secure Enclave, the private device key never leaves the security chip. The group key itself is not synchronized via the iCloud keychain.

There is one exception, and it is deliberate: on first launch the app also creates a key pair for you, the recovery key. It lives in the iCloud keychain and therefore travels between your devices. Alongside the envelopes for the individual devices, every group gets an envelope for this key. If you reinstall Convivia, the app fetches it back, knows from it who you are, and opens your groups again — without anyone having to approve it. Without it, a reinstall would mean losing your data: even your own posts would stay behind as unreadable ciphertext in your iCloud storage.

The iCloud keychain is end-to-end encrypted even without Apple's Advanced Data Protection — Apple cannot read it, and we certainly cannot. The trade-off is out in the open all the same: whoever takes over your Apple account including your device passcode also gains access to your groups through this key. Without the passcode they get nothing.

Encrypted, and thus readable neither by Apple nor by us, are: the image content itself, the thumbnails, the file names, the capture metadata, the occasion names, and the content of the done reports. This holds regardless of whether you have enabled Apple's Advanced Data Protection for iCloud. Every group has a safety number with which you can — voluntarily — verify that nobody has swapped keys unnoticed.

4. iCloud (CloudKit) — storage and transfer

The app exchanges posts exclusively via Apple's CloudKit service, in the members' private and shared iCloud databases. There is no data store of our own: what you post lives encrypted in your iCloud storage and is made accessible to the other members via iCloud sharing. An iCloud account is required for use.

The provider of iCloud is Apple Inc., or for users in the EEA Apple Distribution International Ltd., Ireland; in addition, the Apple Privacy Policy applies.

5. What Apple can see — and what it can't

So that iCloud can deliver the data, some details remain unencrypted. Visible to Apple as the operator of the servers are:

  • your display name and the group name,
  • your iCloud user identifier and — for permanent groups — the Apple ID addresses of the invited people,
  • technical identifiers of groups, members, and posts,
  • the time, number, and file size of posts and who reported “done” when — but not what was reported or posted.

Not visible is the content itself — photos, thumbnails, file names, capture metadata, and occasion names (section 3).

6. Photo library

The app has no read access to your photo library. Picking photos happens in the system's own picker, which runs outside the app — the app receives only the shots you explicitly select, and only photos and Live Photos, no videos. The only photo permission the app asks for is adding: it is needed to place saved photos into your library, and can be revoked at any time under Settings → Privacy → Photos.

Convivia transfers the originals unmodified — including capture metadata such as camera details, capture time, and, where present, the capture location. In transit this data is encrypted; the members of your group, however, receive it with the saved photo. If you don't want to pass on the capture location, remove it in the Photos app before posting.

7. Groups, invitations, and joining

Joining a group happens via an invitation link or QR code — technically an iCloud share. For permanent groups, the person managing the group approves each member individually via their Apple ID address; this address is transmitted to Apple to match the share and remains stored on the managing person's device. For one-time groups, anyone who knows the link can join — so pass such links on only directly to the people who are meant to be there. The member list shows for each member whatever the iCloud share provides: the name, otherwise the email address or phone number of the Apple account.

8. Notifications

New posts reach your device via silent push signals from iCloud. They contain no content whatsoever — only the hint that there is something to fetch; only your device decrypts what it is about. Visible notifications (“… posted new photos”) are therefore generated by the app locally on your device, and only if you allowed that in the system dialog. You can revoke the permission at any time under Settings → Notifications.

9. Storage period and deletion

Nothing deletes itself — and nobody deletes other people's data. A post belongs to the person who put it up: if they delete it in the app, it disappears from their iCloud storage and thus from the app for all members. Photos that others saved before then live in their own photo libraries and are managed there by them.

The managing person can remove members (the group then receives new keys) and dissolve the group. Since there is no account, there is nothing to delete with us: deleting the app removes all local data and the device-bound keys from your device. The recovery key (section 3) stays in the iCloud keychain — otherwise it could not serve its purpose. On its own it is worthless: it only opens posts that are still in iCloud. Your own encrypted posts are therefore best deleted in the app beforehand; they can also be removed in the system settings under iCloud → Manage Storage.

10. Purchase via the App Store

Convivia is distributed through the Apple App Store. When you download and buy it, Apple processes your Apple ID as well as payment and device details; we receive none of it — neither your name nor your address, only anonymized sales figures. We receive crash reports only if you have allowed that in the system settings (Privacy & Security → Analytics & Improvements → Share with App Developers), and even then without any link to you as a person. Apple is responsible for the App Store; the Apple privacy policy linked above applies.

Your rights

You have the rights under Art. 15–21 GDPR: information, correction, deletion, restriction of processing, data portability, and objection. Since your data lives exclusively on your device and in your own iCloud storage, you largely exercise these rights yourself — you can view, save, and delete everything directly in the app. Consents you have given (photo library, notifications) can be revoked at any time with effect for the future. For data that arises with us (e.g. your email inquiries), contact convivia@miroo-media.de — the information is free of charge. You also have the right to complain to a data protection supervisory authority; the authority responsible for us is the State Commissioner for Data Protection of Lower Saxony (Landesbeauftragte für den Datenschutz Niedersachsen).

Changes

We update this policy when the app or the legal situation changes. The current version can always be found at this address; the date of the last update is at the top. For the website, the website privacy policy applies.