Privacy policy
Effective: 3 August 2026 · Last updated: 3 August 2026
The short version
- No advertising — none at allNo banners, no partner offers, no personalisation. You are not the product.
- Zero third-party trackersNot in the app, not on this site. This page loads nothing from anyone else — opening it told no one about you but us.
- We do not sell or share your dataNot to ad networks, not to data brokers, not to anyone else for commercial gain.
- We collect only what is neededAn email address to sign in, your profile, and the conversation itself. Your IP address is not stored — only a one-way hash of it.
- You delete your account from the appNo support tickets and no attempts to talk you out of it.
- There is no end-to-end encryption — and we say so Conversations are stored on the server and are technically reachable by the Service. We put that here in plain sight instead of hiding it in fine print.
1. General
This policy explains what personal data is processed when you use Conbetwo, why it is needed, who can access it, how long it is kept, and how to delete it or exercise your other rights.
It covers the Conbetwo app, the Conbetwo website and the features connected to them — together, the "Service". "We", "us" and "our" refer to the owner of the Service.
2. What data we process
Account data
The email address you provide when signing up or signing in. It is used to create your account, confirm sign-ins, restore access and protect the account from unauthorised use.
Profile data
Depending on which features you use: username, display name, profile picture, and anything else you choose to add yourself.
Conversations and content
Text messages, photos and other uploaded files, answers to shared tasks, and related details such as the time a message was sent. This is stored on the server so the conversation is available to both participants across devices.
You decide what you send. Please do not use the Service to pass on material whose distribution breaks the law or other people's rights.
Technical data
Sign-up and sign-in events, information about active sessions, technical identifiers for devices and sessions, error and crash information, and the time technical events occurred.
Your IP address is not stored as such. Before being written to a technical log it is put through a one-way hash; the original address cannot be recovered from it. The resulting value is still a technical identifier and is protected like the rest of the technical data.
3. Where the data comes from
Most of it you provide yourself — when signing in, filling in your profile or sending messages. Technical data is produced automatically as you use the Service.
We do not read other apps' notifications and we do not collect arbitrary content from your device.
4. What we use the data for
Only for purposes connected with running the Service:
- creating and maintaining your account;
- confirming who you are at sign-in and syncing data across your devices;
- giving you access to conversations and other features;
- sending verification codes;
- keeping accounts secure and preventing abuse;
- finding and fixing technical faults;
- responding to your enquiries;
- meeting legal requirements and lawful requests from authorities;
- protecting the rights and legitimate interests of users and of the Service.
We do not use personal data to show personalised advertising — or any advertising at all.
5. Legal bases
Depending on the data and the applicable law, processing may rest on any of the following:
- the need to provide you with the Service's features;
- performing the user agreement, or taking steps at your request before entering it;
- a legitimate interest in keeping the Service secure and stable;
- compliance with obligations set by law;
- your consent, where the law requires it.
Where processing rests on consent you may withdraw it. Withdrawal does not affect the lawfulness of processing carried out beforehand.
6. Who can access the data
The people in the conversation
Messages and shared material are available to you and to the person you are talking to. They can save a message, take a screenshot or otherwise use what they received — Conbetwo cannot control what the other participant does once the information has reached them.
Authorised Conbetwo staff
Conversations are not end-to-end encrypted. They are stored on the server in a form the Service can technically read.
A limited number of authorised staff or representatives may access conversation content where it is reasonably necessary:
- to handle a user's complaint;
- to investigate a suspected violation;
- to prevent security threats;
- to fix a technical fault;
- to comply with a lawful order from a court or competent authority;
- to protect the rights and safety of users or of the Service.
Access is granted only to the extent the specific task requires, and every such action is recorded in an internal log.
We state the absence of end-to-end encryption openly, because we think it is wrong to leave people with a false impression of how private their conversations technically are.
Technical providers
Running the Service involves infrastructure and hosting providers, and a provider that delivers email. They process only the data needed to supply that service and may not use it for their own advertising or other independent purposes.
Public authorities
We may disclose data where necessary to comply with a binding and lawful demand from a court, a law-enforcement body or another competent authority. Before disclosing we may verify the legality and scope of the demand, where the applicable law permits us to.
7. Email
Conbetwo sends service email containing a one-time verification code when you sign up or sign in. It goes only to the address just entered on the sign-in screen, and the code is valid for 10 minutes, after which it stops working.
We do not send advertising, marketing campaigns, third-party offers or newsletters you did not separately ask for.
Delivery uses a technical email provider, which receives only what is needed to send that particular message.
8. Advertising, analytics and third-party tracking
We show no advertising, do not sell personal data, do not pass it to third parties for commercial purposes, embed no third-party ad counters or trackers in the app or on this site, and do not use anything from your device beyond the data you gave the Service yourself.
This site loads no third-party resources at all — no fonts, no scripts, no counters. Everything the page needs comes from our own domain, so opening it tells nobody about you except us.
The Service does use its own technical mechanisms for sign-in, keeping your session and security. They are not used to track you across other sites or apps.
9. How long we keep data
We keep data no longer than the purposes described in this policy require.
- Account and profile data — for as long as the account exists.
- Conversations and content — for as long as the account exists, or as long as they are needed by the other participant.
- Active sessions — until you sign out, the session is revoked, or it expires, which happens after 30 days.
- Technical event and error logs — 30 days, after which they are deleted automatically.
Individual data may be kept longer where necessary to meet legal requirements, comply with an order from a competent authority, investigate a security incident, or resolve a dispute and defend legal claims.
If a backup copy existed at the moment of deletion, data may remain in it until that copy is replaced or deleted.
Once the applicable period ends, data is deleted, anonymised or reduced to an aggregate form that cannot reasonably be linked back to a person.
10. Deleting your account
You can delete your account from inside the app. When you do, we stop servicing it and delete or unlink from it your email address, profile data, device records, active sessions, personal settings, and files that belong to nobody else and are no longer needed for a shared conversation.
A shared conversation may remain in the other person's history. The link between those messages and the deleted account is removed, and a marker for a deleted user is shown in place of the name. This is so that one participant leaving does not erase history that belongs to the other.
Anonymising an account does not rewrite messages already sent. If you put your name, contact details or other identifying information into a message yourself, it may remain visible to the other person as part of that message.
11. Your rights
Depending on where you live and which law applies, you may have the right to:
- be informed about how your personal data is processed;
- request a copy of the data held about you;
- correct inaccurate or incomplete information;
- have data deleted;
- restrict processing, or object to certain kinds of it;
- receive the data you provided in a portable format;
- withdraw consent you gave earlier;
- lodge a complaint with a competent data protection authority.
To exercise any of these, write to support@conbetwo.com. Before acting on a request we may ask you to confirm that it comes from the account holder, and we will not ask for more information than that check requires.
Some rights may be limited in the cases the law provides for — including where keeping data is necessary to protect other users' rights or to meet a legal obligation.
12. Where data is stored
Data is stored and processed on the servers used to run the Service and in the infrastructure of the technical providers involved. Where data is transferred to another country and the applicable law requires additional safeguards, we use the transfer mechanisms the law provides.
13. Security
We take reasonable technical and organisational measures to protect data against unauthorised access, unlawful alteration, accidental loss, destruction and unlawful disclosure. These include separated access rights, session management, logging of administrative actions and protection of data in transit.
That said, no method of storing or transmitting data can guarantee absolute security. You are also responsible for the security of access to your email and your devices.
14. Children
The Service is not intended for people under 13. In some countries the minimum age for using an online service independently is higher; where that is the case, the age set by local law applies.
We do not knowingly collect data from children below the applicable minimum age. If a parent or guardian believes a child has given us personal data, they can write to support@conbetwo.com. After checking the request we will take the necessary steps, including deleting the data where the law does not require us to keep it.
15. Changes to this policy
We may update this policy when the Service's features, our data practices or legal requirements change. The current version is published on the site with the date it was last updated. For significant changes we may also tell you in the app or by another means that lets you read the new version before it takes effect.
16. Contact
For anything to do with personal data, deleting your account or exercising your rights, write to support@conbetwo.com.