cd ~
$ cat ~/privacy.policy No Logs

Privacy Policy

Your conversations belong to you. We've designed Kursal so literally no one can access your messages.

Last updated: 27 July 2026

Our Commitment

Kursal is built with privacy as its foundation. We believe your conversations belong to you, and we've designed our system so that we literally cannot read your messages. What we cannot hide is described just as plainly further down: relays see some metadata, and the network stores encrypted messages for contacts who are offline.

Who Is Responsible

The data controller for everything described here is Erik L.P., also known as Kubik (a pseudonym), reachable at [email protected]. Kursal is a personal open source project, not a company.

You can reach us about anything in this policy, including any of the rights in section 11, at [email protected].

Data We Don't Collect

Because the Kursal app is peer-to-peer and fully decentralized and we do not want to invade your privacy, the app never sends us:

  • No access to encryption keys
  • No in-app analytics or usage tracking
  • No message content, ever
  • No account, phone number, or email to sign up

The network itself is the exception, and it is covered in sections 05 and 06 below.

Data We Collect

The Kursal app never collects anything in the background. The only data we ever hold is what you explicitly hand us, and in all three cases the legal basis is your consent under Article 6(1)(a) GDPR, which you can withdraw at any time:

  • + Your email address, only if you subscribe to our newsletter on this website
  • + Your email address, only if you subscribe to policy update announcements on our Terms of Service page
  • + Crash reports, only if you send one from the pop-up after a crash

A crash report tells us what went wrong, not who you are. It contains the error and the technical state of the app when it failed, the Kursal version, and your operating system and its version. It never contains messages, contacts, or encryption keys. The crash pop-up shows you the exact report before anything is sent, so you never have to take that on trust: read it, and send it only if you are happy with what is in it.

We never share, sell, or otherwise hand off any of this to anyone. Both mailing lists are separate from each other, and you can leave either at any time using the link in every email we send, or by writing to us.

One technical note for completeness: whenever you hand us any of this, subscribing or sending a crash report, the request itself carries your IP address to our server in Germany, as every request on the web does. We use it only to receive and answer that request, and do not log or keep it. The legal basis is our legitimate interest under Article 6(1)(f) GDPR in operating the endpoint securely.

What Relays Can See

Your encrypted messages travel through public relays. Some of these relays are operated by us, the rest are run by the community and by users who host their own. A relay only forwards traffic: it cannot decrypt anything it carries, and it stores none of it. But any relay can see some limited information about you while it is forwarding:

  • Your IP address (can be changed with a VPN or Tor)
  • When you send messages
  • Your Peer ID and the destination Peer ID (which periodically rotates and makes the 'when' harder to track)

This applies to every relay on the network, including our own. The relays we operate keep no logs at all: they forward traffic and retain nothing about who connected, or when. We have no control over what community-run relays log, which is why Kursal rotates Peer IDs and why we recommend a VPN or Tor if your IP address matters to you. Be aware that a relay actively carrying your traffic still sees a stable connection, so rotation alone does not hide you from it.

Handling this metadata is unavoidable if a message is to reach anyone at all, so the legal basis for it is our legitimate interest under Article 6(1)(f) GDPR in routing traffic and keeping the network running. The balance is deliberately tipped towards you: nothing is retained, nothing is decryptable, Peer IDs rotate on their own, and you can route around us entirely by picking different relays or running your own.

What the Network Stores

Two things do get stored, both encrypted, and neither on a server we control. They live in the distributed hash table carried by volunteer nodes, which includes some of ours:

  • Messages for a contact who is offline, held until they come back and collect them, and discarded automatically after at most 3 weeks
  • First-contact rendezvous bundles, published when you add someone with a one-time password, and discarded automatically after 10 minutes

A node holding one of these records sees an opaque, random-looking key and a block of ciphertext. It cannot decrypt the record, tell whose it is, tell that two records belong to the same conversation, or work out who published it. Offline bundles carry no signature and no sender key of any kind. Nothing needs to be deleted by hand, because every record expires by itself.

This storage exists so that two people are not required to be online at the same moment, and its legal basis is our legitimate interest under Article 6(1)(f) GDPR in delivering messages you asked us to deliver. As with relays, most nodes are not ours, and we cannot make promises on behalf of the people who run them. What we can promise is that the design leaves them nothing worth having.

How Kursal Works

All encryption happens locally on your device. Messages are transmitted directly between peers using end-to-end encryption. There is no central server that processes or stores your communications. Even when your messages transit through public relays or wait in the distributed hash table, no one but the receiver can decrypt them.

This Website

This website sets no tracking or advertising cookies. The only cookies that may be set are the strictly necessary security cookies Cloudflare uses to tell humans apart from bots, which need no consent. We count visitors using Plausible, a privacy-friendly analytics platform which we self-host. Plausible stores no cookies and no IP addresses: it derives a daily rotating hash to count unique visits and discards the address itself. What we see is aggregate, and cannot be traced back to you.

If you support us through Ko-Fi, that donation is handled entirely by Ko-Fi as its own data controller, under their own privacy policy, and processed in the United States outside the EU under the safeguards Ko-Fi puts in place. We never see your payment details, only the name and message you choose to leave.

Where Your Data Lives

The newsletter service, the analytics, and the crash reports all run on hardware we own, keep, and administer ourselves, in Germany. It is not rented, not colocated, and not managed by anyone else. No hosting provider or datacenter operator sits between us and those machines, and nobody other than the maintainer holds credentials for them.

This website and our inbound email are served through Cloudflare, which acts as a processor for delivery, spam filtering, and protection against attacks. Cloudflare is based in the United States and may process this traffic outside the EU, covered by the EU-US Data Privacy Framework and the European Commission's standard contractual clauses. Nothing else leaves the EU.

How Long We Keep Things

  • Newsletter emails: until you unsubscribe, or until the stable release announcement is sent, whichever comes first. That list is then deleted.
  • Policy update emails: until you unsubscribe, or until we stop running the list.
  • Crash reports: until the bug is fixed, and never longer than 6 months.
  • Analytics: aggregate counts only, with nothing tied to a person to retain.
  • Relay traffic: forwarded and not stored, so there is nothing to keep.
  • Offline messages in the distributed hash table: at most 3 weeks, then discarded automatically.
  • First-contact rendezvous bundles: 10 minutes, then discarded automatically.

Your Rights

Under the GDPR you have the right to access your data, correct it, have it deleted, restrict or object to how we use it, receive it in a portable form, and withdraw your consent at any time. For most of this there is simply nothing to hand over, because we hold nothing about you. Where we do hold something, the mailing lists and crash reports, write to [email protected].

We answer within one month, free of charge. If a request turns out to be genuinely complex we may take up to two months more, and in that case we will tell you inside the first month why. In practice this is one student and two small mailing lists, so it will almost always be far quicker than that.

If you think we have handled your data badly, you can complain to the French data protection authority, the CNIL, or to the supervisory authority of the country where you live or work. You do not need to talk to us first, though we would rather you did, and we will help either way.

Security and Breaches

Messages are end-to-end encrypted on your device and we never hold the keys. Everything else travels over TLS, our machines are accessible only to the maintainer, and we keep the amount of data we hold as close to zero as we can, which is the most effective security measure available to us.

If a breach ever affects personal data we hold, we will notify the CNIL within 72 hours as required by Article 33 GDPR, and tell you directly if it puts you at real risk. Given that our entire holdings amount to two lists of email addresses and some crash logs, the blast radius is small by design.

Children

Kursal is not directed at children. You must meet the age of digital consent in your country to subscribe to either of our mailing lists or send us a crash report. We do not knowingly collect anything from anyone younger, and if you believe we have, tell us and we will delete it.

Changes to This Policy

If this policy changes, the date at the top of this page changes with it. Anything significant, and in particular any new purpose we would ever use your data for, is announced here before it takes effect, shown to you in the app, and emailed to anyone subscribed to policy updates, which you can sign up for on our Terms of Service page. Since the whole history of this file is public, you can always see exactly what changed and when.

Open Source

Kursal is fully open source. You can audit our code at any time to verify our privacy claims. We encourage security researchers to review our implementation.

siGithub view source on GitHub

we don't collect your data because we can't. That's how Kursal is designed.