Privacy
What data Quokkie processes, where it is stored and what rights you have. Last updated: 10 October 2026. This is a translation; in case of doubt, the German version applies.
- End-to-end encrypted. Only you and the other person can read or hear messages, voice messages and reactions, not even we can. Exception: you send them to us yourself in a report.
- Phone number instead of a password. It is used to sign in and so that friends can find you.
- Address book only if you want. Matching does not store your contacts. It only remembers who on the waitlist already has friends here.
- No ads, no tracking, no analytics tools.
- Delete any time. In the app or as described under Delete account.
Daniel Steyer
Walddörferstraße 276
22047 Hamburg, Germany
Email: team@quokkie.app
No data protection officer has been appointed, as there is no legal obligation to do so.
Sign-in with your phone number
To sign in, you enter your phone number. Google (Firebase Authentication) sends you a code by SMS and creates a sign-in account with a random user ID. In doing so, Google processes your phone number, your IP address and technical device data, also to prevent abuse. Legal basis: performance of a contract, Art. 6(1)(b) GDPR.
Waitlist
Quokkie lets new users in step by step. Before the SMS is sent, our server in Frankfurt checks whether an account already exists for your number. If not, your number is put on the waitlist. For this we store the number, when you signed up, whether and how you were let in and, if you choose “Let me know”, the device ID for push notifications. To limit abuse, we also store a hash of your IP address for at most two hours and use it to count requests. Legal basis: steps taken at your request prior to entering into a contract, Art. 6(1)(b) GDPR.
People are let in in a certain order: whoever is saved in the address books of more Quokkie users gets in earlier. To do this, we count how many users had your number in their address book during contact matching, and show you this number on the waitlist. We do not show you who these users are. This association is stored only for numbers on the waitlist and only until the entry is deleted. Legal basis: our legitimate interest in an order that gives new users people to talk to right away, Art. 6(1)(f) GDPR.
We delete the entry as soon as you have created your account, at the latest 30 days after you were let in, or 90 days after signing up if you were not let in.
Invitations
Every account gets a personal invitation link with a code that is valid for five people. Whoever comes via the link does not have to wait. We store who owns the code, how often it was used and hashes of the numbers that redeemed it, so that the same number can only use it once. The invitation page shows the first name of the person who sent the invitation. If you install the app from Google Play via the link, Google Play passes the code to the app (Install Referrer) so you don't have to type it in. Legal basis: Art. 6(1)(b) GDPR.
Profile
We store your phone number, the name you enter, the profile picture you chose (one of the quokka motifs), whether you are online right now, when you were last active, which chat is currently open, your public encryption key and when you created your account. Name, profile picture, number, online status and key are visible to people you chat with. Legal basis: Art. 6(1)(b) GDPR.
Contact matching (optional)
If you allow access to your contacts, the app sends the phone numbers from your address book to our server in Frankfurt. There they are converted into an irreversible hash (HMAC-SHA-256 with a secret key) and compared with the hashes of Quokkie users. Only matches come back, i.e. the name, profile picture and number of people who already use Quokkie. The transmitted numbers are not stored. If a number from your address book is on the waitlist, we note on that entry that you know it (see “Waitlist”). The person only sees the count, not your name. Of you yourself, we only store the hash of your own number so that others can find you. The app repeats the matching on its own at most once a day so that new contacts show up. Legal basis: your consent, Art. 6(1)(a) GDPR. You can withdraw it at any time via the “Contacts” permission in the Android settings.
Messages and voice messages
Texts, voice recordings, emoji reactions and the preview while typing are encrypted on your device with AES-256-GCM before they are sent. Only the devices of the two chat participants have the key. Our servers therefore only hold encrypted content. We process unencrypted only the information needed for delivery: who to whom, time, type of message, length of voice messages, delivery and read status. Legal basis: Art. 6(1)(b) GDPR.
Support chat and news
Via “Help & feedback” you can write to us in the app. This support chat is not end-to-end encrypted: we store your messages and our replies unencrypted in our database so that the Quokkie team can read and answer them. If you wish (on by default, can be turned off), the app also sends the app version, device manufacturer and model and the Android version so that we can trace errors. Please do not send passwords or codes there. Legal basis: Art. 6(1)(b) GDPR.
In the “Quokkie” chat we inform all users about what's new in the app. These announcements are public to all users and are therefore not encrypted; you also receive a notification for them. You can turn them off in the Android settings under “News”. Legal basis: legitimate interest in informing users about the service, Art. 6(1)(f) GDPR.
Blocking and reporting
When you block someone, we store this in a list that only you can read. The blocked person isn't told; their messages, reactions and live conversations to you are rejected, and vice versa. Legal basis: Art. 6(1)(b) GDPR.
When you report someone, the report goes to our server: who reports, who is reported, the reason, your note and, if you report from a chat, up to the 15 most recent messages of that chat in plain text plus up to two voice messages from the reported person. Your device decrypts this content specifically for the report; it also includes messages from the other person. With the report we also store the reported person's name and phone number. Only admins of the Quokkie team can read reports, to review them and to suspend accounts that violate the terms of use. The reported person isn't told who reported them. When we suspend an account, we disable the sign-in account and remove the number from contact matching. We pass on indications of child sexual abuse to the competent authorities (see Child safety). Legal basis: legitimate interest in a safe service and in enforcing the terms of use, Art. 6(1)(f) GDPR; for disclosure to authorities Art. 6(1)(c) and (f) GDPR.
Live conversations and microphone
The microphone is only on while you are recording or speaking in a live conversation. Live conversations run directly between the devices (WebRTC, encrypted with DTLS-SRTP). To set up the connection, the devices exchange technical connection data via our database, including IP addresses. This data is deleted after the connection, automatically after about two days at the latest.
So that the devices know their public IP address, the app queries STUN servers from Cloudflare and Google. If no direct connection is possible, the encrypted conversation runs via a relay server (TURN) from Cloudflare (Cloudflare, Inc., USA). Cloudflare sees IP addresses and the amount of data, but not the content. The credentials for this are generated by our server and are valid for at most 24 hours. After the conversation, the recording is stored encrypted as a voice message in the chat. Legal basis: Art. 6(1)(b) GDPR.
Notifications
For push notifications we store a device ID from Firebase Cloud Messaging (Google). The content of a notification is transmitted encrypted and only decrypted on your device. Exception: notifications about news and the support chat contain their text unencrypted. Legal basis: Art. 6(1)(b) GDPR.
Operation and security
While running our servers, Google stores technical logs, for example time, user ID and errors. We only evaluate aggregated figures, such as the number of users and of SMS codes sent, to keep an eye on costs and stability. Legal basis: legitimate interest in secure and affordable operation, Art. 6(1)(f) GDPR.
So that only the genuine Quokkie app can access our servers, the app checks at startup via Google Play Integrity (Firebase App Check) whether it comes unmodified from Google Play and runs on a real device. Google processes technical device and app data for this; we only receive the result of the check. Legal basis: legitimate interest in protection against abuse, Art. 6(1)(f) GDPR.
So that we can see how many devices use Quokkie and which app versions are still in use, the app reports, at most once a day, a random installation ID (Firebase Installations), the app version, where the app was installed from (e.g. Google Play), device model, Android version, the time of installation and of last use and, if you are signed in, your user ID. This data is stored in our database in the EU and is visible only to the Quokkie team. Legal basis: legitimate interest in matching updates and errors to the right versions, Art. 6(1)(f) GDPR.
If the app crashes, it sends a crash report to Google (Firebase Crashlytics): the point in the code where the error occurred, device model, Android and app version, time and a random installation ID. Crash reports contain no messages, no voice messages, no phone number and no contacts. Google processes them on servers in the USA. We use them only to find and fix errors. Legal basis: legitimate interest in a stable app, Art. 6(1)(f) GDPR.
Backup on your device
If you have turned on Android backup with Google, Android also backs up the app's settings so that they are restored on a new device. Your private encryption key is excluded from this and never leaves your device. After switching devices, the app creates a new key; older messages can therefore no longer be opened there. You control backup in the Android settings.
- EU: database with profiles, chats and messages (Google Cloud Firestore, data centers in Belgium and the Netherlands) and our server functions (Frankfurt).
- USA: the encrypted audio files of voice messages (Google Cloud Storage, Iowa). Without the key they cannot be listened to. Also copies of voice messages sent along with a report; only the Quokkie team can access them.
- Worldwide: sign-in (SMS delivery) and push notifications at Google, relaying of live conversations at Cloudflare (nearest data center in each case).
Our service provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Firebase), acting as processor under Art. 28 GDPR. For transfers to the USA we rely on the EU-US Data Privacy Framework, under which Google is certified, and additionally on the European Commission's Standard Contractual Clauses. For connection help in live conversations we use Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA), also certified under the EU-US Data Privacy Framework, on the basis of Cloudflare's data processing agreement.
- Profile, messages and voice messages: until you delete your account.
- Connection data for live conversations: after the connection, at the latest after about two days.
- Waitlist: as soon as you create an account, at the latest 30 days after being let in or 90 days after signing up.
- Invitation link: until you delete your account.
- Support chat: until you delete your account. News: as long as it is shown in the app.
- Block list: until you unblock the person or delete your account.
- Reports including the messages sent with them: up to 180 days after the review is complete; if passed on to authorities, as long as necessary for that.
- Server logs at Google: according to Google Cloud's retention periods, usually 30 days.
- Device statistics: 90 days after the app was last used; your user ID is removed when you delete your account.
- Crash reports: 90 days.
In the app: profile picture → “Delete account”. Without the app: as described under Delete account. This deletes your profile, the messages and audio files you sent, the hash of your number, your push IDs, your support history, your block list and your sign-in account. Reports others have made about you are kept until the end of their review period.
- Microphone: for voice messages and live conversations.
- Contacts (optional): for contact matching.
- Notifications: for new messages and live conversations.
- Bluetooth: to talk via headphones.
- Foreground service: so that a live conversation continues when you leave the app.
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). You can withdraw consent at any time with effect for the future. To do so, write to team@quokkie.app.
You can also lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Hamburg Commissioner for Data Protection and Freedom of Information (Hamburgische Beauftragte für Datenschutz und Informationsfreiheit), Ludwig-Erhard-Straße 22, 20459 Hamburg, Germany.
Quokkie is not intended for children under 16. If the app changes, we will update this policy. The date at the top shows the current version.
This page loads no content from other providers, not even fonts, and sets no cookies.
End-to-end encrypted