This page is for authorities and their counsel. It sets out what we hold, what we do not, and what a request can therefore produce — so that a request can be framed against what exists rather than against what a notes service is usually assumed to have.
legal@myne.md — in German or English. Requests are accepted electronically; there is no requirement to post paper. Please include the legal basis you are relying on and the account identifier you have.
Myne is end-to-end encrypted: content is encrypted on the user's device with keys derived from a password the user holds, and those keys never reach the server. What remains on our side is the following, in full:
| What | What it is |
|---|---|
| account_number_hash | A 16-byte hash. Not the account number itself. |
| SCRAM verifier | What a login is checked against. Not a password, and not reversible into one. |
| Encrypted blobs | Notes and attachments as ciphertext. We hold no key. Producible only in that form. |
| Device registry | One record per enrolled device: a client-generated device id and enrolment/activity state. No device names, no hardware identifiers, no addresses. |
| Counters | Total bytes stored, number of devices. |
| Account policy | A freeze flag and any per-account storage or device limit. Server-side plain text. |
These are not withheld — they are absent. No process, court order or technical measure on our side can produce them, because nothing generates them in the first place:
Several of these are consequences of the architecture rather than of policy, and cannot be reversed by a change of mind on our part. Registration collects no email because the flow has no such step. Rate limiting operates on per-account counters because the server does not retain the address a request arrived from. A user's own timestamps sit inside the encrypted blob, so no operator can read when anything was written.
A request under § 22 TDDDG must be made in writing or electronically. In a criminal investigation it requires sufficient factual grounds; a court order is not a precondition of this provision. Where the requested data exists, it is transmitted without undue delay and in full.
§ 22 does not create a duty to collect. It governs disclosure of subscriber data a provider holds. It does not require a provider to begin holding data it does not hold, and it cannot reach data that was never generated. In practice this means a § 22 request against a Myne account produces the account hash, the device registry, the counters and the policy flags — and nothing resembling an identity, because none is on file.
§ 23 reaches access credentials, and only for the serious offences catalogued in § 100b StPO, on a court order. Two things bound what it can produce here. First, we hold no password: what is stored is a SCRAM verifier, which authenticates a login and cannot be turned back into the credential that satisfies it. Second, the provision itself leaves encryption untouched — eine Verschlüsselung der Daten bleibt unberührt. An order under § 23 does not become an order to decrypt.
There is no basis in German law that obliges a provider to break the encryption of its own service, and in this case the question is moot before it is legal: the keys are derived on the user's device from a secret the user holds, and no copy reaches us. We cannot decrypt the data on request, on order, or of our own volition.
Encrypted data is therefore produced in encrypted form. If an order requires production, what we can hand over is the ciphertext exactly as it sits on disk.
Each request is reviewed against the applicable provision and answered on its terms. Where a request seeks data that exists, it is produced. Where it seeks data that does not exist, we say so plainly and explain why — this page is the long form of that answer.
We notify the affected user where we are permitted to do so and where a channel exists to reach them. Both conditions matter here: with no email address on file, there is often no channel at all, which is a consequence of collecting nothing rather than a decision to stay silent.
Emergency requests involving a risk to life or physical safety are handled with priority. Write to the address above and say so in the subject line.
Myne can be self-hosted, and the server software is open source. Where an account lives on someone else's server, we are not the provider and hold nothing at all — not the ciphertext, not the account hash, not the fact that the account exists. Requests about such accounts have to reach the operator of that deployment.
Deutsche Fassung: Behördenanfragen. See also the Privacy Policy.