Munkki
Download
Munkki
Download
Legal

Privacy Policy

1. An overview of data protection

We built Munkki to be a real alternative to existing social media apps. That means we have zero interest in your data. We use End-to-End Encryption (E2EE) to ensure your content remains strictly yours. The following policy provides a simple overview of what happens to your personal information when you visit our website or use our app, in accordance with the General Data Protection Regulation (GDPR / DSGVO).

2. Data Controller

The data processing on this website and within the app is carried out by the website operator. The responsible party (Controller) is the same entity listed in our Impressum.

Because of the nature and size of our operation, we are not legally required to appoint a dedicated Data Protection Officer (Datenschutzbeauftragter).

3. Hosting

Website Hosting: Our website is hosted by ZAP-Hosting GmbH, based in Frankfurt, Germany. When you visit our website, standard server log files are collected (e.g., IP address, browser type, time of access). These are kept for a maximum of 7 days for security and debugging purposes before being automatically deleted. The legal basis for this is Art. 6(1)(f) GDPR.

App Database: The backend infrastructure for the Munkki app is powered by Supabase, hosted on Amazon Web Services (AWS) in the Frankfurt, Germany region (eu-central-1) — so your data physically stays within the European Union. We have concluded an appropriate Data Processing Agreement (DPA/AVV) with our providers to ensure your data is processed strictly according to European privacy standards.

Fonts & Icons: All fonts and icons on this website are hosted on our own server. Your browser does not connect to Google Fonts or any other external font or icon service.

4. The Munkki App: Encryption & Metadata

The core philosophy of Munkki is privacy. We utilize the Signal Protocol to End-to-End Encrypt (E2EE) your messages, photos, notes, and lists. We physically cannot read your content.

Metadata: To route messages and make the app function, our server must process certain metadata in plaintext. In Munkki, your memories live in a huddle: a private group that up to 7 people can share. You can also use a huddle just for yourself. The server knows which User ID belongs to which huddle, so it can deliver the encrypted blobs to the correct devices. This processing is strictly necessary for the fulfillment of our contract with you (Art. 6(1)(b) GDPR).

Analytics & Crash Reports: The app contains no analytics, tracking or crash reporting tools. No usage data and no crash reports are sent to us or to anyone else.

5. Registration and Authentication

To use Munkki, you must create an account. You can do this via:

  • Email & Password: We store your email address securely to facilitate login and password recovery.
  • Apple / Google Sign-In: You can use third-party OAuth providers. If you do, we receive basic profile information (like your email address) to create your account.

The processing of this data is necessary to provide you with a user account (Art. 6(1)(b) GDPR).

6. In-App Purchases (Munkki+)

If you choose to upgrade to Munkki+ for more storage, the payment is processed entirely through Apple (App Store) or Google (Play Store) In-App Purchases. We do not collect, process, or store any of your financial data (like credit card numbers). We only receive a secure token confirming your purchase so we can unlock the additional storage. The processing of this status is necessary for the performance of a contract (Art. 6(1)(b) GDPR).

7. Third-Party APIs & Services

To power certain in-app features, Munkki connects to a small number of external service providers. Only the minimum data required for a given feature is transmitted, and — because your content is End-to-End Encrypted — none of these providers ever receive the content of your memories, messages, notes, or journal entries.

Where data goes: In the app, every source shows where its data goes. European means the app talks directly to a service run in Europe. Relayed means the request goes through our own server in Frankfurt (eu-central-1). Our server asks the service for you. The service never gets your IP address or any identifier. On this device means the data is read on your phone and nothing is sent. Direct to Apple / Google means your device talks straight to Apple or Google. This is only for maps, and only if you switch it on. Like any request to our server, relayed requests can briefly appear in our hosting provider's technical logs.

Weather (Open-Meteo) — European: When you add a memory, the app can automatically attach the local weather. To do this, the approximate coordinates of the memory are sent to Open-Meteo (open-meteo.com), a European open-source weather service, which returns the weather for that location. Open-Meteo does not require an account and states that it does not track users or store personal request data.

Place names (Nominatim / OpenStreetMap): To turn GPS coordinates into a readable place name (e.g. "Munich, Germany"), the app sends those coordinates to the Nominatim geocoding service operated by the OpenStreetMap Foundation. Only the coordinates you attach to a memory are transmitted for this lookup.

Address search (Photon / komoot) — European: When you search for a place to attach to a memory, the words you type and an approximate position (to rank nearby results first) are sent to Photon (photon.komoot.io), an open-source search service based on OpenStreetMap data and operated by komoot GmbH in Berlin. This only happens while you search.

Maps (OpenFreeMap) — European: When the app shows a map, the map tiles for the visible area load from OpenFreeMap (openfreemap.org). It is run by Hyperknot Software Kft. in Hungary. There are no accounts and no tracking. Your device sends its IP address and the map area. OpenFreeMap says its access logs contain no IP addresses. It may use Cloudflare to deliver the tiles. This is the default map on iOS and Android.

Apple Maps — direct (optional, iOS): If you switch on Apple Maps, the maps load from Apple's servers. Your device sends its IP address and the map area to Apple. This applies to every map in the app, also for places other members shared. Apple says it does not link this data to your Apple ID. Apple Maps is off by default.

Google Maps — direct (optional, Android): If you switch on Google Maps, the maps load from Google's servers. Your device sends its IP address and the map area to Google. Google's privacy policy applies. Google Maps is off by default.

Sunrise, sunset and moon phase: These are calculated directly on your device from the memory's place and date. No data is sent anywhere for this.

Music (Apple iTunes Search) — relayed: If you enable the optional music integration and search for a song, your search words go to Apple's public iTunes Search API (itunes.apple.com). They go through our server, so Apple gets the search words but not your IP address. No Apple account is involved. Covers and the optional 30-second previews also load through our server when you or a member of your huddle view the memory. So Apple cannot see who looks at which song. If you open a song in Apple Music, your device connects to Apple directly.

Films, series & books (Wikidata, Wikipedia, Open Library) — relayed: If you enable the optional films, series & books integration and search for a title, your search words go to Wikidata and Wikipedia (run by the Wikimedia Foundation) and to Open Library (run by the Internet Archive). Both are non-profit, open projects without accounts or advertising. The searches go through our server, so these services do not get your IP address. Posters and book covers also load through our server when you or a member of your huddle view the memory. If you open a title, your device connects to Wikipedia or Open Library directly.

On this day (Wikipedia) — relayed: If a memory's author switches on “On this day” (an optional integration), the memory only stores that switch. When the memory is viewed, the app asks Wikipedia (run by the non-profit Wikimedia Foundation) what happened on that calendar date in history. It also loads the pictures for these events. Only the month and day are sent, never the year, the place or any content of the memory. The request and the pictures go through our server, so Wikimedia does not get the viewing device's IP address. If you open an event, your device connects to Wikipedia directly.

GIFs & stickers (KLIPY) — relayed: When you search for a GIF or sticker, your search words and your phone's country setting (e.g. “de”) go to KLIPY (klipy.com). Searches and the GIFs themselves go through our server. KLIPY gets neither your IP address nor any identifier, and shows no ads.

Push Notifications (Firebase Cloud Messaging & Apple Push Notification service): To notify you about new activity in your huddles, we use Google's Firebase Cloud Messaging (Android) and Apple's Push Notification service (iOS). These services process a device-specific push token and your IP address in order to deliver the notification. The notification payload is kept minimal and never exposes the encrypted content of your messages.

This processing is necessary to provide the features you use (Art. 6(1)(b) GDPR) or is based on our legitimate interest in a functional, reliable app (Art. 6(1)(f) GDPR).

8. Device Permissions (Access)

Munkki only asks for a permission at the moment you use the feature that needs it. Every permission is optional: if you decline, only that feature is unavailable. You can revoke any permission at any time in your device settings. Whatever the app reads through these permissions is End-to-End Encrypted before it leaves your device.

  • Location: to attach a place to a memory (optionally automatically for new memories), to look up the weather there, and to share your position with the members of your huddle.
  • Camera: to take photos and videos for your memories and updates.
  • Photos & media: to choose existing photos, videos and audio files, and to save media to your gallery when you ask for it. Only the items you pick are read.
  • Microphone: to record voice messages. Recording only happens while you actively record.
  • Calendar (read only): to pick a calendar event and attach it to a memory. Munkki never changes or creates calendar entries.
  • Health & fitness (read only, iOS): to attach a workout to a memory. See Section 9.
  • Journaling Suggestions (iOS): Apple's system picker suggests moments from your device. Munkki only receives the one suggestion you choose.
  • Notifications: to tell you about new activity in your huddles (see Section 7).
  • Face ID / fingerprint: to unlock your encrypted data. The check happens entirely in your device's operating system. Munkki never receives any biometric data.
  • Technical permissions (Android): network state (to detect whether you are online), vibration (for haptic feedback), and starting after a reboot (to keep scheduled reminders).

The legal basis is your consent, given through the permission prompt of your device (Art. 6(1)(a) GDPR), and the provision of the feature you use (Art. 6(1)(b) GDPR).

9. Health & Fitness Data

Munkki includes an optional feature that lets you bring your workouts into your shared timeline — for example a run, walk, ride, or other activity — so you and the members of your huddle can see what you did and how far you went (the distance you walked, drove, or otherwise travelled). This feature is only available on iOS.

What we access: With your explicit permission, and only after you enable this feature, Munkki reads two types of data from Apple Health: (1) your workout / exercise records (e.g. activity type, duration, distance) and (2) the location / route data associated with those workouts. We do not access any other health data (such as heart rate, sleep, nutrition, or medical information).

How we use it: This data is used solely to display your workouts and their routes inside the app, for you and the members of your huddle. Like all your other content, it is protected with End-to-End Encryption before it leaves your device, so we cannot read it.

What we never do: We never sell your health or fitness data, never use it for advertising or profiling, and never share it with third parties. You can revoke the health permission at any time in your device settings, and deleting the data (or your account) removes it in line with your rights under Section 10. The legal basis for processing this data is your explicit consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR), which you may withdraw at any time.

10. Your Rights (DSGVO)

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access (Art. 15): Request information about your stored data.
  • Right to rectification (Art. 16): Request correction of inaccurate data.
  • Right to erasure (Art. 17): Request the deletion of your data (The "No Hostage" guarantee).
  • Right to data portability (Art. 20): Receive your data in a machine-readable format.

To exercise these rights, simply contact us via the email address provided in our Impressum. You also have the right to lodge a complaint with the competent supervisory authority.

Munkki

Ein privater Ort für deine Erinnerungen. Nur für dich oder für die Menschen, die dir wichtig sind. Ende-zu-Ende-verschlüsselt. Keine Werbung, kein Tracking.

Made in Unterhaching, Deutschland · © Munkki

Rechtliches

Datenschutz Impressum Kinderschutz
Munkki

A private place for your memories. Just for you, or for the people who matter to you. End-to-end encrypted. No ads, no tracking.

Made in Unterhaching, Germany · © Munkki

Legal

Privacy Legal Notice Child Protection