Privacy Statement
Last updated: 1 August 2026
Zeig hands a photo or file from one device to another. It was built so that nobody in the middle — including us — can see what you hand over. What the receiving device does with the file afterwards is up to whoever holds it: a received file is saved on that device like any other download.
What we never see
Your files travel directly between the two devices over an encrypted
peer-to-peer connection. They are end-to-end encrypted with a key that exists
only inside the QR code the sender shows and the device that scans it. The key
travels in the link's fragment (the part after #), which browsers
never send to any server. No file, file name, file size, or key ever reaches
our infrastructure.
When a direct connection is impossible
Some networks will not let two devices reach each other at all. A phone on a mobile network facing a phone behind a company firewall is the ordinary case. Rather than fail, Zeig then sends the file through a relay operated by Cloudflare, and it is only honest to say what changes.
The relay forwards the encrypted stream. It sees how many bytes crossed it, the IP addresses of the two devices, and when. It does not see the file's content, its name (which is sealed inside the encrypted transfer and never travels over any of our servers), or the key, which only ever exists in the QR code and on the two devices. Encryption is not weakened by relaying: the relay forwards bytes it cannot open.
The bytes are kept only for as long as forwarding them takes. Cloudflare does count the total volume that crosses the relay each month, because that is how the service is billed. That counter is attached to our account, not to you, your device or your transfer, and it says nothing about who sent what to whom. Access credentials for the relay are issued per transfer and expire after a few hours.
What our server does
To find each other, the two devices briefly exchange connection details through a small relay at zeig.franzai.com. The relay sees only an opaque room identifier and the connection handshake. It stores nothing: rooms live in memory for at most five minutes, hold at most two participants, and evaporate when the transfer starts or the participants leave.
What passes through it, exactly
Being honest about "only the handshake" means naming it:
- A room identifier: sixteen random hex characters, newly generated for each pairing and tied to nothing else.
- A join proof: a code derived from the QR secret that proves the scanner was there, without revealing the secret.
- The WebRTC handshake — the offer, the answer and the candidates. These contain the network addresses (including IP addresses) that your two devices offer each other, because that is what makes a direct connection possible. The relay forwards them byte for byte and does not read them.
- The IP address of your connection, as any web server necessarily sees it while a request is open.
- A request for relay credentials, sent when a transfer starts. It carries nothing about you, the file or the pairing. It asks for a temporary username and password and nothing else.
Legal bases: providing the relay you asked for is Art 6(1)(b) GDPR (performance of the service); keeping it available and resistant to abuse is our legitimate interest under Art 6(1)(f). None of it is used for anything else.
What we collect
Nothing. No accounts, no analytics, no cookies, no tracking, no logs of who transferred what to whom. The app asks for camera access only to scan the other phone's code, and photo library access only so you can pick what to send. Neither leaves your device.
Nothing above is written to storage. The one thing a room does put on disk is the timer that tears it down — no participants, no addresses, no history. There is no database to search, and none of this survives the five minutes.
Who else is involved
- Cloudflare serves the page and runs the relay for us, as our processor under a data processing agreement. Traffic is handled at the network edge nearest to you and is processed transiently for delivery and for protection against attacks. Cloudflare is a US company with EU infrastructure; where data reaches the US, its standard contractual clauses and its EU-US Data Privacy Framework certification are the safeguards under Chapter V GDPR.
- A STUN server (
stun.cloudflare.com) is asked once per transfer what your device looks like from the outside, so the two devices can reach each other through their routers. It learns your IP address and nothing else — no file, no room, no identifier. This is the standard WebRTC mechanism. It is Cloudflare's deliberately: Cloudflare already runs the relay above, so pairing brings no further company into it. - A TURN relay (
turn.cloudflare.com), only when the two networks allow no direct connection, carries the encrypted file itself. See "When a direct connection is impossible" above for exactly what it can and cannot see. It is Cloudflare's for the same reason as the STUN server, and covered by the same agreement. - Apple distributes the app through TestFlight and the App Store and is its own controller for that. What Apple collects there is covered by Apple's privacy policy, not by this one.
Your rights
Under the GDPR you can ask for access, rectification, erasure, restriction, portability, and you can object to processing based on legitimate interests. In practice there is a catch we would rather state than hide: because we store nothing and identify nobody, we normally cannot tell which — if any — of the transient data was yours (Art 11 GDPR). We will always answer, and we will say honestly when there is nothing to hand over.
Nothing here involves profiling or automated decision-making, and nothing is sold, shared or used for advertising.
You can complain to the Austrian data protection authority: Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, dsb.gv.at — or to the supervisory authority where you live.
Who is responsible
Controller in the sense of Art 4(7) GDPR: Franz Enzenhofer – FullStackOptimization, Fröbelgasse 62/8-9, 1160 Vienna, Austria. Full details in the Impressum.
Contact
Franz Enzenhofer · franz.enzenhofer@fullstackoptimization.com