Legal

Privacy policy

Website, custom number shop and the Q-Tel app.

Q

As of 19 Sep 2026. This text is currently under legal review and may still change; the version in force at the time of your purchase applies.

English translation for convenience. In case of any discrepancy, the German version prevails.

1. Controller

HBI – Hansestadt Bremen Innovations GmbH
Geschäftsführer: Nils Johanning
Albersstrasse 11, 28209 Bremen
E-Mail: info@hansestadt-bremen-innovations.de
Tel.: +49 172-4630364
Amtsgericht Bremen, HRB 36672

2. Principle

Q-Tel is built so that we know as little about you as possible: there is no sign-up with a phone number, email address or name. Messages, calls, voice messages, photos and Vault contents are end-to-end encrypted; we cannot read them. We do not analyse who you communicate with or how often.

3. This website

  • Server logs: When you visit, our web server processes your IP address, time, requested page and browser identifier in order to deliver the page and fend off attacks (Art. 6(1)(f) GDPR). The logs are deleted after 14 days.
  • No cookies, no tracking: We do not use cookies or any analytics or advertising services. Fonts are loaded from our own server.
  • Language choice: If you choose German or English or dismiss the language hint, your browser remembers this locally (entry "qtel_lang" in browser storage). It is not transmitted to us; you can delete it in your browser settings.
  • Hosting: The servers are located in Germany at Hetzner Online GmbH, which acts as our processor.

4. Custom number shop

  • Reservation: We store the selected number, price, timestamps, a pairing code and a hash of your IP address to limit reservations per connection (abuse prevention, Art. 6(1)(f) GDPR). The website only keeps the reservation in the session storage of your browser tab.
  • Linking to your account: When you confirm in the app, we store which account is to receive the number and your signed confirmation (performance of contract, Art. 6(1)(b) GDPR).
  • Consent to waive the right of withdrawal: We store the version and checksum of the consent text, the time and the IP hash as evidence (Art. 6(1)(c) and (f) GDPR).
  • Payment: Payment is processed by Stripe Payments Europe Ltd. (Ireland). You enter card details, email address and billing address directly with Stripe; Stripe is an independent controller for this (privacy at Stripe). We only receive payment IDs, amount, status and the country of the billing address – never your email address or card details.
  • Storage period: We delete reservations without a purchase after 90 days. We retain purchase data in accordance with commercial and tax retention periods (up to 10 years).

5. The Q-Tel app

  • Account: internal account ID, Q-ID, public device keys, device type (iOS/Android), times of registration and sign-in. The private keys never leave your device.
  • Contacts: We store which accounts are connected and whether someone has been blocked, so that only contacts can reach each other. Names you give your contacts stay on your device only.
  • Messages: Chats run via our own Matrix server without any connection to third-party servers. It only stores messages in encrypted form plus the metadata needed for delivery (sender, room, time). Messages deleted for everyone are permanently removed after 5 minutes.
  • Calls: Call setup runs via our server (signed). Call content is encrypted and flows directly between the devices or via our relay server, which cannot decrypt it.
  • Push notifications: We store a push token and send only "New message" (or "Neue Nachricht", depending on the app language) and the number of unread messages via Apple or Google – never content or senders.
  • Vault: Contents are stored only in encrypted form on your device. Vault files sent securely are kept encrypted on our server until accepted, for at most 7 days.
  • Recovery: We store an envelope encrypted with your recovery code, which we cannot open ourselves.
  • Invitations and Q-Points: If a new account is created via your invitation, we store the link until confirmation and delete it 90 days afterwards. The points ledger only contains points, type and date.
  • Q-ID change: If you buy a custom number, we store the old and new Q-ID so that the old one is never reassigned.

The legal basis is the performance of the user agreement (Art. 6(1)(b) GDPR) and, for security and abuse prevention, our legitimate interest (Art. 6(1)(f) GDPR).

6. Recipients

Hetzner Online GmbH (hosting, Germany), Apple Inc. and Google LLC (content-free push notifications only), Stripe Payments Europe Ltd. (payment). Data may be transferred to third countries in the case of Apple and Google; this is based on the EU-US Data Privacy Framework or standard contractual clauses.

7. Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR). Since we don't know any names or contact details, we need your Q-ID and a confirmation from the app for requests about your account. You can also lodge a complaint with a supervisory authority, for example the State Commissioner for Data Protection and Freedom of Information of the Free Hanseatic City of Bremen.