Kristik privacy notice
Kristik puts the messaging accounts you already have into one inbox. This notice explains what happens to your messages and your data, and who can read them. It describes the service as it runs today. Where something is not done yet, it says so.
Who runs Kristik
Kristik is operated by KRISTIK, Lithuania. For any question about this notice or your data, write to hello@kristik.online.
The one thing to understand
Kristik's bridges can read your messages. A merged inbox cannot exist otherwise. WhatsApp and Signal no longer go through a bridge: their messages reach Kristik's servers still encrypted, with the limits set out under WhatsApp and Signal.
To show your messages in Kristik, a Kristik server called a bridge signs in to your account as a linked device, the same way a desktop app does, and keeps that sign-in for as long as the account is connected. It reads each message, then encrypts it again for your Kristik app. For that moment the message is readable in memory on Kristik's server. Nothing that bridges networks can be end-to-end encrypted from the person writing to you all the way to you.
What the network itself can read depends on the network:
- Messenger's end-to-end encrypted chats are encrypted as far as the bridge.
- Telegram (whose Secret Chats Kristik does not carry), Instagram, and the Messenger chats Messenger does not encrypt end to end can be read by the network itself, as they can in its own app. With your sign-in, the bridge could also fetch the earlier messages of those chats from the network again.
You can connect WhatsApp, Telegram, Signal, Facebook Messenger and Instagram. Other networks are listed in the app with the reason they are unavailable.
Not done yet: Kristik plans to move this work from its servers onto your phone, one network at a time. WhatsApp and Signal have moved to Kristik's relay. Telegram, Messenger and Instagram still go through a bridge that can read them.
WhatsApp and Signal
WhatsApp is carried by Kristik's relay, not a bridge. You link it from the app: your phone becomes a WhatsApp linked device, hands the relay the connection key it needs to stay connected, and keeps the keys that open messages to itself. The relay receives each message still encrypted as WhatsApp sent it, keeps it until your phone has fetched it, and has no key to open it. Your phone decrypts it and encrypts it again before it is stored on Kristik's message server, as for every other conversation. Kristik's servers do not read your WhatsApp messages. What that does and does not cover:
- Who and when are still visible. The relay sees your WhatsApp number, who writes to whom, when, and how large each message is.
- A first message to someone new. To send a first message to someone you have never written to through Kristik, or to a group with someone new in it, your phone asks the relay for that person's keys, and the relay could hand it keys of its own. Until your phone can check them, that first message is not yet protected from Kristik. In a group, the relay could go on reading what you send there until the group's key changes; it would not read what others send.
- Not yet proven. Kristik has checked that its servers hold no WhatsApp message in readable form. It has not yet proven that the connection key the relay holds could never be used to obtain one, so it does not claim that it is unable to read them.
- Photos, files and history. These go straight between your phone and WhatsApp; Kristik's servers never see them, and WhatsApp sees your phone's internet address when they do. Your phone then stores an encrypted copy on Kristik's message server, kept like any attachment: the server's copy is removed two days after it was last opened, and your phone keeps what you open.
- What kind of message, and who read it. Kristik's servers see when a message is a photo, a reaction, an edit or a deletion, and who reads what, but not what any of it says.
- Names. WhatsApp sends group names, group members and people's WhatsApp names to the relay as it passes them on. The relay seals them to a key on your phone before storing them, and Kristik keeps them only on your phone. Names from your address book never reach the relay. Another device signed in to Kristik shows numbers.
- Earlier links. A link made before names and history came through keeps working with numbers only; linking again brings them.
- If someone took over the relay. Your phone gets the keys it encrypts with through the relay, and nothing yet checks them against WhatsApp's own. So whoever controlled Kristik's relay could try to read what you send, in any chat or group and not only a first message, or pose as one of your contacts. Your phone does not accept a contact's changed security code silently: it warns you, so you can check the code with them.
Accounts linked to WhatsApp's bridge before this change were signed out of it, which deleted the bridge's copy of their chats. Linking WhatsApp again goes through the relay.
Signal goes through the relay too, and works the same way: your phone links itself as a Signal linked device and decrypts, and the relay passes your messages on still encrypted, so Kristik's servers do not read them. The same limits apply: the relay sees your Signal number and who writes to whom and when, a first message to someone new is not yet protected from Kristik, it is not yet proven that the relay's link could never be used to read a message, and someone who took over the relay could try to read what you send. One more: the link the relay holds for Signal could be used to send messages as you and to ask Signal for the keys of people you write to. Kristik's servers use it only to pass on what your phone sends. Signal groups are received but cannot yet be written to, and files, edits and deletions are not carried yet. Signal accounts linked to the old bridge keep running there until they are moved.
What Kristik's message server stores
Every conversation becomes a room on Kristik's Matrix message server. Message text is stored there encrypted, and the server cannot read it. Some things around the messages are not encrypted:
| Stored on the server | Encrypted? |
|---|---|
| Message text | Yes. The server holds ciphertext it cannot read. |
| Reactions | Partly. A reaction that arrives from another network is encrypted. A reaction you send from Kristik, and the message a reply or edit of yours points to, are visible to the server: it can see which emoji you chose and which message it was for, but not what that message says. |
| A backup of your encryption keys | Yes, locked with your recovery key, which Kristik never receives. |
| Who is in each conversation, and when each message was sent | No. The server can see that you talked, to whom and when, but not what was said. |
| Chat and contact names, and profile photos | No. |
| Read receipts and typing indicators | No. |
| For each of your devices, its name and the internet address and app version it last connected with | No. |
Photos, videos and files
Attachments are encrypted by the bridge, or in a WhatsApp chat by your phone, before they reach Kristik's storage, and Kristik has no key to open them. They are kept in a Google Cloud Storage bucket only until your phone fetches them: the server's copy is removed two days after it was last opened, and a daily clean-up then deletes the file from the bucket within a few days. A contact's or a conversation's photo is kept while it is in use. Your phone keeps what you open, up to the storage limit you choose in Settings. A photo you never opened within those two days, or one your phone later removed to stay under its limit, cannot be downloaded again.
A network may expire old attachments on its own servers. An old message can then arrive without its photo, and Kristik cannot recover it.
Your history
When you connect an account, the network sends some of your recent history once, and Kristik takes part of it:
- WhatsApp: up to 1000 messages, as far back as WhatsApp sends, in each of your 1000 most recent chats. Your phone fetches it from WhatsApp and applies the limits itself. From history, only photos and files up to two weeks old and 5 MB come along.
- Telegram: up to 1000 conversations, one-to-one chats first, up to 1000 messages each.
- Messenger and Instagram: your most recent conversations, the first pages of your chat list, up to 1000 messages each. Messenger's end-to-end encrypted chats bring no history, only new messages.
- Signal: the messages in Signal's transfer, if you accept it when you link; your phone takes them. Photos and files from before the link stay in Signal.
What a first connection skips cannot be fetched later without connecting the account again.
What Kristik's account service stores
Kristik's account service stores none of your conversations. The one thing you write that it keeps is what you write to Kristik support and, if you test Kristik, your bug reports, below. It holds:
- your sign-in, kept by the sign-in service: your username, your email address, a password hash, and for each signed-in session the internet address and app version it last used;
- one record per connected account: the network, its state, the network's identifier for the account, and the name or phone number the network shows for it. Once you disconnect it and the network confirms the sign-out, the identifier and the name are removed from that record;
- your devices: platform, a display name, and when each was added, removed and signed out;
- a record of actions on your account, such as connecting, disconnecting or exporting, kept for 400 days;
- how many assistant requests you made today, as a number only;
- when you were last seen: the time of a recent request, updated at most once an hour, which is how an account that goes quiet is paused;
- counts of your recent sign-in starts, contact searches, support messages and error reports, so none of them can run in a loop, as numbers deleted after a day;
- your messages to Kristik support, and Kristik's answers. You are writing to Kristik, so the Kristik team reads them; they are not end-to-end encrypted as your chats are. They are never written to a log, and they are deleted with your account and included in its export. A report about another Kristik person is one of these: who, why, your note, and the message you reported when you reported one, which leaves end-to-end encryption to reach the team. Blocking someone keeps nothing new: it is your account's ignore list on the homeserver.
- if you test Kristik, the bug reports you send, and Kristik's answers. A report holds what it is about, your comment, the screen and app version, the screenshot with what you marked on it, and the error log if you left it attached. The Kristik team reads it, and may have an AI coding assistant (Anthropic's Claude) read it while fixing the bug. It is not end-to-end encrypted, it is never written to a log, and it is deleted with your account and included in its export; a resolved report's screenshot and log are deleted after 30 days. You see your reports, where each stands and Kristik's answers in the app and at kristik.online/reports; in the app you also see your screenshot and the comments, and can reply or open a report again. When Kristik answers a report or changes where it stands, your phones get a notification through Apple or Google with fixed words and the report's number, never what Kristik wrote. There you and Kristik can comment on a report, and you can share one with other testers: they then read what you wrote, Kristik's answers and the comments, and see your screenshot only if you choose that as well, but never your log or your username. What you write on another tester's shared report is read by them and other testers, without your username. Comments are deleted with your account.
Separately, with no account and no device attached: a fingerprint of each error the app reports (its kind, code and where in the code it happened, never a message), counted per day and kept 30 days.
Each bridge keeps a database of its own, which holds your sign-in to that network for as long as the account is connected, and the names and photos of the contacts it has seen.
The relay holds your WhatsApp or Signal number and a connection key, copies of your messages, still encrypted, until your phone has fetched them, and who wrote to whom, when and how large each message was. It keeps read receipts until your phone has fetched them, and the names WhatsApp sends it only sealed to a key on your phone. So that it can wake your phone, it also holds your phone's notification reference, never the notification token itself. The account service keeps a record of each relay link: its state, when it was made, and counts your phone reports, as numbers only. Unlinking the relay, or deleting the account, signs it out of the network and deletes what it holds.
A few named Kristik operators can look up these records and the message server's to fix problems, which shows them chat names, who is in each chat, and the names and numbers of connected accounts, but never what a message says.
When a network asks for a password or a one-time code, Kristik passes it straight through and keeps none of it.
If you stop using Kristik for a while, your connected accounts are paused rather than signed out. They are kept alive so the networks do not unlink them, and they resume when you use the app again.
Invitations
If you ask for an invitation on kristik.online, Kristik keeps your email address until your account is made or the request is turned down, or for 30 days after an invitation is sent if it is never used. The invitation is sent to that address through an email delivery provider. Once your account exists, the address is kept with your sign-in.
Notifications
A notification carries no message text. It tells your phone which conversation and message are new; your phone then fetches the message and decrypts it. Apple and Google deliver the notification, but never see what the message says. A WhatsApp notification comes from the relay and carries only a number of the relay's own; on a locked iPhone it says only that a message arrived. For other networks, what your phone shows is who wrote, not what, unless you turn on Show message text in notifications in Settings; then the text appears on the lock screen and in the phone's notification history. Your phone's notification token is held by Kristik's push service, and the rest of Kristik stores only a reference to it.
Some notifications are about your account rather than a message. A chat request names the Kristik username that sent it, which your phone reads itself. When one of your network accounts needs you to sign in again, or its chats have finished importing, Kristik's server sends a notification through Apple or Google with fixed words that name the network, such as "Sign in to Telegram again": Apple or Google can see which network, never which account. When a WhatsApp or Signal contact's security code changes, your phone says so itself, naming the network and not the contact. An import in progress shows on your lock screen, driven by your phone alone: the network's name and how far it has got.
Calls between Kristik accounts
The sound and video of a call between two Kristik accounts are encrypted between the two phones, and no Kristik server has the keys. When the phones cannot reach each other directly, the call goes through Kristik's relay, which forwards packets it cannot read. While it does, the relay sees both phones' internet addresses, the account name in each phone's relay pass, when the call started, how long it lasted and how much it forwarded. It keeps no record of calls, only a line in its size-capped log when something goes wrong. Phones reach the relay without TLS, so someone watching your network could see that you use it. The person you call learns your phone's internet address, whether or not the relay is used.
The assistant
The assistant can write out a voice message, summarise a conversation, round up several chats, draft a reply, answer a question about a chat, describe a photo or read text aloud. It does nothing until you press a button. When you do, what that answer needs is sent to OpenAI: the voice message; the text of the messages involved, with the display name of whoever sent each and when, in your phone's timezone, and for a summary the words your phone itself transcribed from voice messages and noted about photos in that chat; the name of the chat, or for a roundup each chat's name and network; your question; the photo, without its location and other metadata, and its caption; or the text to read aloud. This is so in every chat, including WhatsApp and Signal chats and chats with another Kristik person, which Kristik's servers otherwise do not read. You can turn the assistant off in Settings. The first time you use the assistant, the app says this before anything is sent. Kristik asks OpenAI not to store what it sends; OpenAI's own settings for its API still decide what it keeps, and by default it may keep requests for up to 30 days to monitor abuse. Kristik keeps no copy: nothing is written to a database or a log, and a voice message or photo passes through the server's memory only. Generated speech is held briefly in memory and then discarded. Kristik counts how many requests you make each day, as a number only, and deletes the count with your account. A suggested reply goes into your message box and is never sent unless you send it.
On your phone
Your messages and encryption keys are stored on your phone in an encrypted database. Its key is kept in the iPhone Keychain or the Android Keystore, and the database is excluded from device backups. The search index the app builds from your messages is encrypted too. Photos you open are decrypted only into the app's own cache.
Before you connect a network, the app makes a recovery key and shows it to you once. It locks the backup of your encryption keys on the message server, and Kristik never receives it. A new phone reads your earlier messages with that key, or by signing in with a phone you already use.
Which of your devices a message is encrypted for. A bridge encrypts a bridged message only for the devices you have approved with your recovery key, and it keeps none of the keys afterwards. What you send yourself, what another Kristik person sends you, and the WhatsApp and Signal messages your phone encrypts again from the relay are encrypted for every device signed in to your account, so a device added to it could read those from then on, though not your earlier history, which needs your recovery key. Not done yet: making the app as strict as the bridge waits on the bridges publishing cross-signing identities of their own.
Removing a device. Removing a device in Settings signs it out: Kristik ends its sign-in, the message server deletes the device with its keys, and your other devices, the bridges and other Kristik people share no new message key with it. Its notifications stop at once, and the list shows it signed out once the sign-in has ended. What it already downloaded stays on it. A WhatsApp or Signal link made on it stays linked, and the relay keeps holding that account's messages for it, until you remove it under Linked devices in that app.
Where your data is and who helps run Kristik
- Google Cloud hosts Kristik's servers, storage and backups in the Netherlands (europe-west4).
- OpenAI processes content only when you use the assistant. OpenAI is based in the United States.
- Apple and Google deliver notifications, without their content.
- An email delivery provider sends invitation emails.
- The networks you connect — WhatsApp, Telegram, Signal, Facebook Messenger and Instagram — continue to handle your messages under their own terms. Kristik does not change what they store.
Kristik's logs contain no message content, and each server log is capped in size and overwritten.
Backups
Kristik's databases are backed up every night, encrypted so that only the operator can open them, and kept for 30 days: the message server's, the sign-in service's, the account service's and those of Kristik's other services, such as the push service's. Message text inside a backup is still the encrypted copy the message server holds.
Each bridge's database, which holds your sign-in to every connected network, is not backed up. If Kristik ever has to restore from a backup, you connect your networks again. Backups made before this changed did include it, and are deleted 30 days after they were made.
Getting a copy of your data
You can export your account data from the app's settings.
Deleting your account
Deleting your account happens at once, before the app confirms it, and cannot be undone. Kristik signs out every connected account, which takes its conversations out of your inbox; stops notifications to your devices; deletes every record about you in its account service, including the record of actions; and deactivates and erases your message-server account and your sign-in. The app then erases everything stored on your phone.
Some things remain:
- conversations no other Kristik person is in are removed from the message server within minutes, and those a bridge created once its sign-out is confirmed; a conversation you shared with another Kristik person stays for them;
- the message server keeps the internet addresses your devices used for 7 days;
- the sign-in service keeps your username as a closed account, with your old password hash, which can no longer be used, and your ended sessions, each with the internet address and app version it last used;
- a record that an account was deleted, with its internal number and how many connections it had, and nothing you wrote, for 400 days;
- if a bridge or the relay did not confirm signing you out, a retry keeps your username until it does;
- the names and photos of contacts a bridge learned stay in that bridge's database and on the message server, which everyone on that bridge shares;
- files in storage are deleted on the schedule above;
- copies of deleted records remain in encrypted backups until those backups expire after 30 days.
It does not delete anything from WhatsApp or the other networks, or recall a message someone has already received.
Your rights
You can ask to see, correct, export or delete your data, and you can object to how it is used, by writing to hello@kristik.online. You can also complain to Lithuania's State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, vdai.lrv.lt), or to the data protection authority where you live.
Changes
If this notice changes, the date at the top changes with it, and any change that affects what Kristik can see is announced in the app.