Privacy Policy
for the “QGap” app (Android, Windows) and the website con2.net/qgap
Last updated: August 2026
1. Controller
Markus Mühlnickel
c/o ReAuTec GmbH
Kalteiche Ring 31
35708 Haiger, Germany
E-mail: paulprog@abwesend.de
2. Core principle: data minimisation
QGap is designed to process as little personal data as possible:
- There is no user account – no name, phone number or e-mail address is required.
- Messages are end-to-end encrypted on your device using a one-time pad. Plaintext never leaves the device.
- Key files are stored locally only and are never transmitted to us or to any third party.
- In pure offline/air-gap mode (QR-code or USB transfer) no data is transmitted over the internet at all.
3. Data stored locally on your device
Chats, messages, key files, settings and received files are stored exclusively on your device (Android: app data folder or a folder chosen by you; Windows: the data folder you selected). This data is under your sole control; we have no access to it. It is removed when you delete the app or the data folders.
4. Optional online feature (cloud transport)
Only if you actively use the online feature (online invitation / cloud sync), the app processes the following data through Google Firebase (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland):
- Anonymous authentication (Firebase Authentication): a random, anonymous user ID (UID) is created. No names, e-mail addresses or phone numbers are collected.
- Message transport (Cloud Firestore): only encrypted message content is transmitted and buffered (one-time-pad ciphertext, unreadable to the operator and to Google), plus technical metadata (anonymous UIDs of chat participants, timestamps, chat ID).
- Asymmetric/hybrid encryption: as an alternative to the one-time pad – when exchanging the key file in person is not possible or too much effort – a hybrid scheme is used: content is encrypted with AES-256 in GCM mode; the randomly generated AES key is encrypted with the recipient's public RSA key (2048 bit). The private RSA key never leaves the recipient's device; neither the operator nor Google can decrypt the content.
- File attachments (Firebase Storage): also transmitted in encrypted form only.
- Presentation feature (public screen): if you create and share a presentation (e.g. song lyrics, images), its content is transmitted to the display devices via Cloud Firestore and Firebase Storage. Unlike chat messages, this content is not encrypted, as it is meant to be visible to anyone with the display link or QR code. Therefore, do not put confidential or personal content into presentations. The content remains in the cloud until the session is deleted.
Legal basis: Art. 6(1)(b) GDPR (providing the feature you requested).
Third-country transfer: Firebase may process data on servers in the USA. Google LLC is certified under the EU-US Data Privacy Framework; EU Standard Contractual Clauses are additionally in place. Details: firebase.google.com/support/privacy.
Retention: encrypted messages remain in the cloud buffer until delivered or deleted by the user. The anonymous UID exists for as long as the app is installed.
5. App permissions
- Camera: only for scanning QR codes (messages, invitations). No photos are stored or transmitted.
- Microphone: only for voice messages you record yourself; they are end-to-end encrypted like text messages.
- Storage/files: for reading/writing key files and attachments in the folder you selected and on USB drives.
- Notifications: local alerts for new messages.
- Network state: detecting whether an internet connection is available for the optional cloud transport.
There is no advertising, no tracking and no analytics (no analytics, crash-reporting or advertising SDKs).
6. Website (con2.net/qgap)
When you visit this website, the hosting provider processes technically necessary server log data (IP address, time, page requested, user agent) to deliver and secure the service (Art. 6(1)(f) GDPR). This website sets no cookies and embeds no tracking services.
7. Your rights
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). Since QGap has no user accounts and only transports encrypted content, we can attribute stored cloud data to a person only if you provide us with your anonymous UID (shown in the app under chat info). You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).
8. Children
The app is not directed at children under 16. No data is collected that would allow age determination.
9. Changes
This privacy policy is updated when app functionality changes. The current version is always available at con2.net/qgap/privacy.html.