When silence is part of your job
Doctors, lawyers, tax advisers, therapists, works councils, data protection officers: you keep quiet not out of politeness, but because the law requires it. This page uses six everyday cases to show where an ordinary messenger becomes difficult.
The sentence everything turns on: in your work it is not only the content that is confidential — the name already is. That Mrs Berger is your patient, that Mr Klein has instructed you: that alone is the secret protected by professional confidentiality (in Germany, § 203 of the Criminal Code). A messenger can encrypt the content of your message perfectly and still reveal who wrote to you and when.
Six everyday cases
1. The doctor and the photo of a finding
The everyday version: you photograph a finding and send it to a colleague for a second opinion. Fast, practical, in the middle of surgery hours.
What travels along: with the common messengers the content is encrypted — that is undisputed, and we claim nothing else. But your patient sits in your phone as a contact, by name. As soon as an app is allowed to read your address book, that list leaves your device. And the knowledge “this number is in regular contact with a medical practice” arises entirely without the content.
With us: your address book stays on your device. Only when you yourself use the “Find people” feature does our server briefly check which of the e-mail addresses have an account — it stores nothing, logs no address and passes nothing on. You sign in with an e-mail address, not a phone number.
2. The lawyer and the client who simply writes
The everyday version: your client has your mobile number and writes to it. You answer, because you do not want to turn them away.
What that creates: a service provider drawn into your duty of confidentiality — without anyone ever having agreed to it. German professional law (§ 43e BRAO, § 203(3) of the Criminal Code) assumes that you select such a provider carefully and bind them to secrecy by contract. Ask yourself: with whom would you have concluded that contract?
With us: there is a contracting party based in the EU, a nameable server in Germany, and on request a data processing agreement under Article 28 GDPR.
3. The tax adviser and the receipt at 10 pm
The everyday version: a client photographs a receipt and sends it in the evening. You see it the next morning.
What happens meanwhile: the picture lands on two phones — and, depending on the settings, additionally in an automatic backup held by the operating system vendor. Check once where your message backup goes and who can open it.
With us: every message sits encrypted on our server and is deleted after 30 days. Anything older lives only on the devices of the people involved.
4. The therapist and the changed appointment
The everyday version: “Can I come later on Thursday?” — a harmless message.
Why it is not: it contains no medical finding at all and is still sensitive: the mere fact that someone is in treatment with you is part of the secret. Message previews on a lock screen show exactly that to anyone glancing at the phone.
With us: you can switch the preview off — then it says “New message” and nothing else. And you can mute each conversation on its own.
5. The works council on a company phone
The everyday version: the committee talks in a group — on phones that belong to the employer and are managed by their IT.
Why that is delicate: German works constitution law (§ 79 BetrVG) obliges you to secrecy, including towards the employer. On a managed device, however, it is not the committee that decides which app reads along and which backup runs.
With us: the messenger also runs in the browser and as a program for Windows — on a device of your choosing. And what sits on our server we cannot read; so we could not hand it to anyone who asks either.
6. The data protection officer reporting a breach
The everyday version: you tell a management board that data has leaked. It is urgent.
The irony: the report about a data protection incident travels over a channel whose legal basis you have never examined yourself. Article 38(5) GDPR binds you to secrecy — the very examination you demand of others applies to your own tool.
With us: you get a description of the measures under Article 32 GDPR which also states what is not implemented: our security page.
Five questions for your current messenger
We claim nothing here about other providers. We give you the questions — the answers are in their own documents, and you are practised at reading such things:
- Do I get a data processing agreement under Article 28 GDPR? For professional use it is not a formality but the precondition.
- Which legal system is the provider subject to? And which disclosure obligations follow from that?
- What happens to my address book? In your case those are client and patient names.
- Which traffic data arises — who with whom, when, how often — and how long is it stored?
- Where does my message backup go, and who can open it?
This is not only about “chat control”
Much is written about the planned EU regulation on detecting child sexual abuse material (“chat control”). But that is only one half. The other half applies already today and concerns every provider owned by a US corporation:
- The CLOUD Act (18 U.S.C. § 2713, in force since 2018) obliges US providers to hand over data in their custody — including data held in Europe. A data centre in Frankfurt does not solve that problem if the provider sits in California.
- FISA 702 permits US authorities to conduct surveillance of non-US persons at US providers. That is precisely what brought down the “Privacy Shield” before the European Court of Justice in 2020 (Case C-311/18, Schrems II).
- Reporting duties under 18 U.S.C. § 2258A: US providers must report what they find. Subsection (f) makes clear at the same time that they are not obliged to search for it — so the decision whether to search lies with the provider, not with the law.
Our answer to this is not an assurance but a construction: we cannot read your messages. Not because we promise it, but because the key never leaves your device. What we do not have, we cannot hand over even under an order. What we do see — that two accounts write to each other, for instance — is stated openly in our privacy policy. That too.
What we promise — and what we do not
- ✅ Servers in Germany, contracting party in the EU.
- ✅ Data processing agreement under Article 28 GDPR on request.
- ✅ End-to-end encrypted, no covert address-book matching — checks run only at your request and nothing is stored —, no advertising, no tracking.
- ✅ Messages deleted from the server after 30 days.
- ⚠️ A profile picture is not encrypted — that is the one exception, and it is stated in the privacy policy as well.
- ⚠️ Traffic data arises with us too. Every server has to know where to deliver a message. We say so openly instead of keeping quiet about it.
- ❌ We are not a law firm and give no legal advice. Whether our service satisfies your professional rules is for you to decide — the information here is meant to make that examination possible, not to replace it.
Next step
Have a look at what the messenger can do today and what is still missing: our open development status. Questions about the contract or data processing: [email protected].
To the messenger · Technical measures · To the privacy policy