SPREQ privacy statement
Version 1.0, valid from 14 August 2026.
SPREQ is built to know as little about you as possible. This statement sets out precisely what we do process, why, for how long and with whom we share it.
This English text is a translation provided for convenience. The Dutch version is the legally binding one.
1. Who is responsible
Netron ICT, Virulyweg 43 B, 7602 RG Almelo, Chamber of Commerce (KVK) 93536399.
Privacy questions and requests: privacy@spreq.nl
We have not appointed a data protection officer. If SPREQ grows further, we will do so then and report it here.
2. The short answer
- We cannot read or listen in on your messages and conversations. They are end-to-end encrypted and we hold no master key.
- We keep no conversation history. It exists only on your device.
- Messages and files that have not yet been delivered are stored encrypted on our server and deleted immediately once they have been collected. If nothing is collected, we delete them after 72 hours at the latest.
- We do not sell your data and never use the content of your conversations for advertising.
- Our servers are located within the European Economic Area, primarily in the Netherlands, with backup and failover servers elsewhere in the EU.
3. What we process
3.1 Account data
What. Username, email address, first and last name, and optionally a phone number. In addition, the creation date, device and app version, an internal account ID and a device ID for each device on which you are signed in. On registration we also record the IP address, together with the moment you confirmed you were 16 or older and which version of the terms you accepted.
Why. To be able to create an account and deliver the service.
Basis. Performance of the contract (article 6(1)(b) GDPR).
Retention. As long as your account exists, and no more than 30 days thereafter.
3.2 Profiles
What. For each profile the name, profile picture, type (Personal, Work, Business Verified), settings and subscription status. Also the link between the profiles under the same account.
Why. To make multiple identities in one app possible.
Basis. Performance of the contract.
Retention. As long as the profile exists, and no more than 30 days thereafter.
Please note. In the app your profiles are kept separate from one another. Other users cannot see that two profiles belong to the same person. Technically we do know this, because the profiles fall under one account. If you do not want that link to exist on our side either, use separate accounts.
3.3 Signing in and email verification
What. Your email address and a one-time six-digit code, sent by email via our email provider. We store the code only in encrypted form and it is valid for ten minutes. We also record failed sign-in attempts and security events with the IP address and browser or app information.
Why. To verify that the email address is yours, to sign you in and to prevent abuse.
Basis. Performance of the contract and legitimate interest (security).
Retention. Codes and sign-in attempts for no more than 30 days, after which they are deleted automatically. We delete the IP address from your registration after 30 days.
Please note. SPREQ does not use SMS and does not ask for a phone number in order to sign in. You always sign in with your email address.
3.4 Messages
What. Messages that have not yet been delivered. These are end-to-end encrypted: we see only an object ID, the size, the time and the expiry time. We hold no key and cannot read the content. Our server refuses unencrypted messages.
Why. To be able to deliver messages.
Basis. Performance of the contract.
Retention. No more than 72 hours on the server, and deleted immediately once the message has arrived on all of the recipient's devices.
3.4a Photos, videos, voice messages and documents
What. Attachments you send, stored under a random file name without your original file name.
Why. To be able to deliver attachments, even when the recipient only comes online later.
Basis. Performance of the contract.
Retention. No more than 72 hours on the server, and deleted immediately once the attachment has been collected. So we do not wait out the full 72 hours: once the attachment has been delivered, we erase it at once. Profile pictures remain in place as long as the profile exists.
Honest about the difference. Text messages are end-to-end encrypted. Attachments are not yet, at this point: they are encrypted in transit (TLS) and can only be collected with a valid, short-lived access token from a signed-in account, but technically we could open them on our server. We do not do so, except where the law obliges us to. We are working on encryption of attachments; as soon as it is in place, we will amend this text.
3.5 Delivery data (metadata)
What. Which profile queued a message at which moment for which receiving profile, and whether it was delivered.
Why. This is technically necessary to deliver a message.
Basis. Performance of the contract.
Retention. We delete this data once delivery is complete, and after 72 hours at the latest. We do not keep any long-term log of who communicates with whom.
3.6 Voice and video calls
What. If you make a voice or video call, available from the Plus subscription onwards, we process during the call the connection data needed to set up the connection: the profiles involved, the time and technical signalling data such as the IP addresses of the devices. The call itself is end-to-end encrypted. Where possible it runs directly between the devices. Where that is not possible, it runs encrypted via our relay server.
Why. To establish and deliver a call.
Basis. Performance of the contract.
Retention. We do not record calls and cannot listen in. We keep no call content and hold no call history on the server. We process the technical connection data only during the call and do not keep it afterwards.
You can set for yourself who is allowed to call you. By default this is set to "friends only". We store that choice with your profile.
3.7 Technical and security logs
What. IP addresses, times, failed sign-in attempts, rate limits, error messages.
Why. To keep the service secure and stable and to combat abuse.
Basis. Legitimate interest (article 6(1)(f) GDPR) and our security obligation.
Retention. No more than 30 days, unless a specific abuse investigation makes longer retention necessary. In that case, no more than 6 months.
3.8 Subscription and payment data
What. Which subscription you have, start and end date, transaction ID from the app store. For invoicing also company name, address and VAT number.
Why. To deliver your subscription and keep our records.
Basis. Performance of the contract and legal obligation.
Retention. Records kept for 7 years on the basis of the tax retention obligation.
We do not receive any credit card or bank details from you via the app store.
3.9 Business Verified data
What. Company name, Chamber of Commerce (KVK) number, address, phone number, domain name, contact person, evidence of signing authority, verification date and outcome.
Why. To verify the identity of the company and to be able to grant the badge.
Basis. Performance of the contract and legitimate interest in preventing deception.
Retention. As long as the status is active, and 2 years thereafter so that we can demonstrate what we checked in the event of a dispute.
A Business Verified profile is searchable by company name and by the business phone number provided. That is the core of the service. For sole traders, company data may also be personal data. If you do not want to be searchable, choose the Work subscription instead of Business Verified.
3.10 Contacts
What. If you share a contact card in a conversation, the app asks for one-time access to your address book. Only the contact you choose yourself is included, as part of your message.
Why. To be able to send a contact card.
Basis. Consent (article 6(1)(a) GDPR).
Retention. We do not read your address book and do not store it. The chosen contact is contained in the message and follows its retention period.
Please note. SPREQ does not search your address book to determine which of your contacts use the app. You find others solely by typing in their username.
If you do not give consent, you can still use SPREQ as normal. You then add contacts manually.
3.11 Location
What. If you share your location in a conversation, the app asks for one-time access to your location. Only the location you send at that moment is included, as part of your message.
Why. To be able to send a location in a conversation.
Basis. Consent (article 6(1)(a) GDPR).
Retention. We do not track you and keep no location history. The location sent is contained in the message and follows its retention period.
Please note. SPREQ never requests your location in the background and does not use it for advertising or statistics.
If you do not give consent, you can still use SPREQ as normal. You then do not send any location.
3.12 Advertising
What. On Free profiles we show a single advertisement card between the chats. The advertisement shown is chosen at random. We process no personal data for this: an advertisement is not tailored to who you are, what you chat, your location or your behaviour. The only thing we measure is anonymised totals per advertisement: how often it has been shown, how often it has been clicked and the click-through rate. We do not keep track of who saw or clicked anything.
Why. To fund the free service with non-personalised advertising.
Basis. Legitimate interest (article 6(1)(f) GDPR) in funding the free service. Because no advertising ID, cookies or trackers are placed or read, no consent is required for this and we show no cookie banner.
Retention. We only keep anonymised totals per advertisement (impressions, clicks, click-through rate). These contain no personal data.
Sharing with the advertiser. We share these anonymised totals with the advertiser of the advertisement in question, so that they know how the advertisement is performing. We never share who saw or clicked an advertisement.
All advertisements are hosted by SPREQ itself. There is no advertising network. Apart from the anonymised totals above, no data whatsoever goes to external parties, and certainly no personal data. We never use the content of conversations, your contacts or your files for advertising. Advertisements cannot be dismissed; they are part of the Free plan. Paid plans are completely advertising-free.
3.13 Push notifications
What. A push token per device, and the username of the sender and recipient that accompanies the notification.
Why. To let you know that a message is waiting and to open the right conversation when you tap it. The notification contains no message content: because messages are end-to-end encrypted, our server cannot read that content and therefore cannot include it either.
Basis. Performance of the contract.
Retention. As long as the profile is active. For devices that have not been used for 90 days, we delete the push token.
The route of a notification. Our server sends the notification via Expo (650 Industries, Inc., United States) to Apple or Google, who deliver it to your device. These parties see the usernames of the sender and recipient, not the content. See the sub-processor register.
3.14 Reports and abuse
What. What has been reported, against whom, when, the assessment and the action taken. If, when making a report, you choose to include messages, we additionally receive the last 5 received messages from the reported user in that conversation. Of attachments we receive only a technical fingerprint and the file type, not the file itself.
Why. To tackle illegal content and abuse. This is required under the Digital Services Act.
Basis. Legal obligation and legitimate interest.
Retention. 1 year after completion, or longer if proceedings are ongoing.
3.15 Contact with support
What. Your message and contact details.
Basis. Legitimate interest.
Retention. 2 years after resolution.
3.16 Name reservations
What. If you reserve a name before launch: your name, your email address, the chosen username or company name and your IP address.
Why. To secure the chosen name for you until launch and to contact you when you need to complete your registration. We use the IP address to prevent abuse of the reservation form.
Basis. Performance of the contract at your request (article 6(1)(b) GDPR) for the reservation, and legitimate interest (article 6(1)(f) GDPR) in combating abuse for the IP address.
Retention. Until 7 days after launch at the latest. If you do not complete your registration, we delete the reservation and the associated data.
4. What we do not do
- We do not read your messages and technically cannot. The only exception is where a user themselves includes messages when making a report. Those messages are decrypted on their own device and uploaded by them. We do not break any encryption.
- We do not scan the content of conversations, not even for illegal content.
- We do not sell or rent out personal data.
- We do not build profiles based on your behaviour in conversations.
- We use no advertising network and no advertising trackers. Advertisements are shown at random and not tailored to your behaviour. With the advertiser we share only anonymised totals (impressions, clicks, click-through rate), no personal data.
- We make no conversation backups.
5. With whom we share data
We only engage parties that we need in order to deliver the service. A processing agreement has been concluded with each of them.
| Party | For what | Location |
|---|---|---|
| Hosting | hosting of servers and database | Netherlands, backup in the EU |
| Apple Inc. | push notifications (APNs) and payments via the App Store | United States |
| Google LLC | push notifications (FCM) and payments via Google Play | United States |
| Accountant and bookkeeping firm | financial administration | Netherlands |
We also share data where we are legally obliged to do so. See article 8.
An up-to-date overview of sub-processors is available at spreq.nl/subverwerkers. We announce changes there at least 30 days in advance.
6. Transfers outside the EEA
For push notifications and app store payments we work with Apple and Google. This may involve a transfer to the United States. That takes place on the basis of the European Commission's standard contractual clauses and, where applicable, the EU-US Data Privacy Framework.
The content of your messages never passes through unencrypted. Push notifications contain no message content from our server.
For all other processing, your data remains within the EEA.
7. Security
Among other things, we take the following measures:
- end-to-end encryption of messages, files and calls
- encrypted local database on your device
- encrypted transport (TLS) between app and server
- encrypted storage of temporary objects on the server
- access restriction and two-factor authentication for staff
- logging of administrative actions
- no administrative function whatsoever that allows conversation content to be viewed
- periodic penetration tests and security reviews
- separation between temporary message storage and other databases
If you discover a vulnerability, please report it via security@spreq.nl.
8. Requests from police, prosecutors and authorities
We cooperate with requests that rest on a valid legal basis. We can only provide data that we actually hold at that moment. That is never the content of conversations.
Every request is assessed and recorded in a separate audit log. How we do this is set out in our policy on Requests from police, prosecutors and authorities at spreq.nl/wettelijke-verzoeken.
9. Your rights
You have the right to:
- access to the data we hold about you
- correction of inaccurate data
- erasure of your data
- restriction of processing
- object to processing based on legitimate interest
- portability of data you provided yourself
- withdraw consent given, at any time
Send your request to privacy@spreq.nl. We respond within one month. We may ask for additional verification, for example a confirmation from your account in the app.
Two things we cannot do:
- we cannot give you a copy of your conversations, because we do not have them
- we cannot delete messages from your conversation partner's device
You can delete your account yourself in the app under Settings.
10. Complaints
If you disagree with how we handle your data, please let us know via privacy@spreq.nl. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), Postbus 93374, 2509 AJ The Hague, autoriteitpersoonsgegevens.nl.
11. Age
SPREQ is intended for users aged 16 and over. We do not target children. If we discover that an account belongs to someone under 16, we delete it.
12. Changes
We may amend this privacy statement. The current version is always available at spreq.nl/privacy. In the event of significant changes, we will inform you in the app or by email.