Privacy policy

What we know about you

Last updated: 25 July 2026 · Dipling · Hungary

Lauther exists so you can stop handing your email address to every website. It would be absurd to build that and then quietly hoover up your data. This page is written to be read — including the parts that are less flattering to us.

The short version

Who we are

Lauther is operated by Dipling, Hungary. For any privacy question, or to exercise the rights listed below, contact hello@lauther.id. Under the GDPR we are the data controller for the data described here.

What we store, and why

DataWhyWhere
Email address Sign-in and account recovery — so losing your phone doesn't lose your identities. There is no password. Never shared with any service. Firebase Authentication (EU)
Your notification inbox So messages survive being dismissed and are readable on your other devices. Firestore (europe-west1)
Connected services The per-service ID, the alias you chose, and the push credential — this is what lets you revoke a service later. Firestore (europe-west1)
Device push tokens The address Google/Apple use to wake your phone. Deleted automatically when a device stops responding. Firestore + FCM/APNs
Email aliases Only if you create them. Maps a throwaway address to your inbox. Firestore (europe-west1)

What never reaches our servers

What a service learns about you

When you sign in to a website with Lauther, that website receives:

That is the complete list.

Two services cannot compare notes. Because each gets a different identifier and a different alias, there is no shared key to join their databases on. That is the entire point of the product.

What we can see — stated plainly

Lauther itself can tell which identities belong to the same account. Our servers hold the link between your account and each pairwise identity, because that is what makes one-tap revocation, account recovery and multi-device sync possible.

So the accurate claim is pairwise pseudonymity toward the services you use — not anonymity from us. Notification content passes through our infrastructure encrypted in transit (TLS) but is not end-to-end encrypted today; end-to-end encrypted payloads are on the roadmap. If your threat model includes us, or a party who can compel us, please plan accordingly.

We also record ordinary operational data — timestamps, delivery counts and error logs — to keep the service running and to stop abuse. These are kept for as long as needed to operate the service and then discarded.

Who we share data with

We do not sell data, and we do not share it for advertising. We use these processors to run the service:

Push notifications necessarily transit Google's or Apple's delivery network to reach your device; that is true of every app on your phone. We may also disclose data where we are legally required to.

Your rights

Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to our using it. Most of this you can do yourself, immediately, without asking us:

Deleting your account removes your inbox, your connected services and your identities from the live database. You also have the right to complain to your local supervisory authority — in Hungary, the NAIH.

Children

Lauther is not directed at children under 16 and we do not knowingly collect their data.

Changes

If this policy changes in a way that materially affects you, we will say so in the app rather than quietly editing this page. The date at the top always reflects the current version.

Questions, or think we've got something wrong? hello@lauther.id. If you find a security issue, we would genuinely rather hear it from you than read about it later.