POSIMO / LEGAL
Privacy policy
Last updated: 7 September 2026. Posimo is built around a simple rule: your memories belong to you. This policy explains what APG352 processes, why it is needed, and the choices you have.
Who is responsible
APG352 is the controller for the Posimo website and the personal data processed through it. Registration: RCS A40928. VAT: LU29012776. Contact: contact@posimo.io.
What we process
For early access, we process your email address and the message you choose to send. For private comment invitations, we process the memory content, invitation token, reply, and delivery information needed to provide that invitation. We receive only what you submit or deliberately share.
Community accounts and discussions
If you join the community, we store your Apple account identifier, verified email address, chosen public community name and acceptance of the community guidelines. Apple verifies your sign-in. Forum profiles and discussion posts are public; email addresses are hidden from public profiles. Login codes expire after one minute and app community sessions after 30 days. The forum uses necessary login cookies. Private companion memories are not sent to the forum automatically. You can request account access, export or deletion at contact@posimo.io.
Why we process it
We use this information to provide Posimo, respond to requests, deliver invited replies, prevent abuse, secure the service, and comply with legal obligations. The legal basis is performance of a requested service, our legitimate interest in security, or your consent where consent is required.
Where data is stored
Posimo’s online services run on servers in Germany. Memories remain on your device unless you choose an action that sends something elsewhere. We do not sell personal data, build advertising profiles, or operate a public memory feed.
Service providers and transfers
We use infrastructure and delivery providers only where needed to run the requested service, under contracts and access controls. Our primary hosting is in the EU. If a provider or support process ever requires a transfer outside the EEA, we will identify the destination and the safeguards used in the relevant notice.
Security
Connections use TLS. Sensitive payloads are encrypted before relay where the feature supports it, and stored application payloads are protected as ciphertext. Access is limited to the service functions needed to deliver the action you chose. No internet service can promise absolute security, so we also provide deletion and access controls.
Retention
We keep data only for as long as needed for the stated purpose, legal obligations, dispute handling, or security. Invitation links expire and can be deleted by the owner. You can ask us to delete or export data by emailing contact@posimo.io.
Your rights
You may request access, correction, deletion, restriction, portability, or object to processing. Where processing is based on consent, you may withdraw it at any time. You may also complain to the Luxembourg data protection authority, the CNPD.
Data protection contact
APG352 has not appointed a data protection officer because the current processing does not trigger the mandatory DPO criteria. For any privacy request, contact contact@posimo.io.
Updates
We may update this policy when Posimo changes. The current version is always published on this page.