Privacy Policy

Last updated: 13 August 2026

Who we are

KEIBIDROP is developed by KEIBISOFT S.R.L., registered in Romania (CIF: RO48339304, Reg. Com.: J22/1888/2023). Contact: marius@keibisoft.com.

Our position on data collection

We do not want to collect information about people. We collect the absolute minimum required for the software to function and for the servers to operate. Nothing else.

What KEIBIDROP does

KEIBIDROP transfers files directly between two devices over an encrypted peer-to-peer connection. Files never touch a server. The encryption key is negotiated between the two peers using ML-KEM-1024 + X25519 hybrid key exchange. No third party, including KEIBISOFT, can decrypt the transfer.

Data we collect

The application itself collects no personal data. No accounts, no sign-up, no email addresses, no analytics, no tracking, no telemetry. No cookies on this website.

Buying a relay pack is different, because a payment cannot be anonymous. See If you buy a relay pack below.

Server logs

Our web servers and relay servers produce standard access logs (nginx) that may contain IP addresses and timestamps. These logs exist for anti-abuse prevention and infrastructure operation. They are periodically rotated and deleted. We do not use these logs to identify or track users.

Relay server

When two peers cannot connect directly, KEIBIDROP uses a relay for signaling and optionally a bridge for data forwarding.

Diagnostic logs (user-initiated)

The mobile apps include a "Send Logs" button that lets users share application logs with us for troubleshooting. This is entirely optional and user-initiated. Logs are never sent automatically. Before export, logs are sanitized to remove file paths, home directory names, and other personally identifiable information.

On-device storage

Users may opt into persistent identity and contacts. Both are stored encrypted on the device using keys from the OS keychain (macOS Keychain, Windows Credential Manager, Linux Secret Service, iOS Keychain, or Android Keystore). No identity or contact data is ever sent to KEIBISOFT or any third party.

Presence

When persistent identity is enabled, KEIBIDROP sends periodic heartbeats to the relay to indicate online status. The heartbeat contains a cryptographic token derived from the contact fingerprint. The relay cannot reverse the token to a fingerprint or identify the user. Presence data expires after 60 seconds.

Children

KEIBIDROP is not directed at children under 13. We do not knowingly collect data from children.

If you buy a relay pack

Stripe handles the payment. Stripe collects your card details and a billing address, which the law requires so the correct VAT rate applies. Stripe is a separate controller for that data. Read their privacy policy at stripe.com/privacy.

We never see your card details. We do not receive or store your name or your email address. You still do not need an account.

From Stripe we receive only the checkout session ID, the amount, the currency and the payment status. We keep that to mint your code and to meet Romanian accounting and VAT law.

When we hand you your code we also write one delivery record. It holds:

We keep delivery records for 200 days. That covers the period in which a bank can reverse a payment, so we can show that a paid code was delivered. The legal basis is our legitimate interest in preventing fraud and defending payment disputes, GDPR Art. 6(1)(f), and our legal obligation to keep accounting records, Art. 6(1)(c).

The code itself is deleted from our servers 24 hours after the purchase.

Third-party services

KEIBIDROP does not integrate with any third-party analytics, advertising, or tracking services. Stripe is used only for payments, as described above.

Your rights (GDPR)

The application collects no personal data, so for normal use there is nothing to access, correct, or delete.

If you bought a relay pack, we hold the purchase and delivery records described above. You can ask us for a copy, for a correction, or for erasure. Erasure has a limit: Romanian accounting and VAT law requires us to keep records of a sale, and we keep a delivery record while a payment can still be reversed. We will explain which part we must keep and why.

Server logs containing IP addresses are covered by our legitimate interest in operating the infrastructure and preventing abuse (GDPR Art. 6(1)(f)).

Write to marius@keibisoft.com for any request. You can also complain to ANPDCP, the Romanian data protection authority, at dataprotection.ro.

Changes

We may update this policy when adding new features. The date at the top of this page indicates the last revision.

Contact

KEIBISOFT S.R.L.
Strada Costache Negri, Nr. 60, Bloc C1, Scara B, Et. 7, Ap. 25
Iași, Romania
CIF: RO48339304 | Reg. Com.: J22/1888/2023
Email: marius@keibisoft.com