Privacy Policy & Zero-Trust Mandate
How ITsf Assistant (assistant.itsf.gr) secures, processes, and respects user data under air-gapped environments
LAST UPDATED: July 29, 2026Scope of this Policy
This Privacy Policy explains how Assistant ITsf.gr (the "App," "Service," or "we") collects, uses, stores, and protects user data and information collected through our mobile application (the "Client App"), desktop executables, and associated services (the "Backend Server"). To guarantee absolute compliance with the zero-trust paradigm, our storage architecture operates under a Zero-Knowledge mandate—meaning we design systems so that even our administrators cannot read your private communications.
1. Information We Collect
A. Personal Data (Provided by You)
| Data Type | Purpose | Retention Period |
|---|---|---|
| Account Details Username, Email, Passwords |
Account provision, login authentication, and secure workspace access. | Active Membership + 7-day deletion grace |
| Session Security & Protection Session Tokens, Tab Expiry State |
Auto-halting background requests on 401/403 session end to protect client IPs from false Fail2Ban bans; 2-minute login page inactivity redirect. | Transient Browser Session Instant redirect to /login |
| User-Generated Content & AssistantBER Transfers Files, documents, & AssistantBER media stream downloads |
Encrypted storage and secure file routing in personal My Files storage. Legal Disclaimer: End-users assume 100% sole legal responsibility and copyright compliance for all streams and files processed via AssistantBER or saved to My Files. |
Active Membership Deleted immediately on user request |
| Wiki Knowledge Base & Confluence Imports Documentation pages, spaces, & Markdown content |
Application-layer zero-trust encryption (EncryptedText) with space-level RBAC clearance isolation (Resistance, Logismos, General). |
Encrypted RDBMS Zero-trust access controlled |
B. Sensitive Device Permissions
| Permission | Purpose | Data Transfer & Storage Status |
|---|---|---|
| Camera | QR-code login provision & real-time WebRTC video calls. | No Data Transmitted Processed transiently in-memory |
| Microphone | Real-time voice chats, LiveKit calls, and VoIP. | No Data Transmitted No recording is ever saved |
| Telephony / Call State | Monitors active cellular calls to auto-disconnect VoIP sessions. | Local Processing Only Managed entirely on-device |
| Biometric Scan | Local application unlock & secure token storage. | 100% Local (OS Chip) Zero access by the server |
| File Picker | Enables manual file uploads inside secure vaults. | Encrypted Transfer Transmitted over TLS to vault |
2. Cryptographic Zero-Trust Controls
Identity Key Generation
Private Identity Keys are negotiated locally on client devices using the X25519 Elliptic Curve. These keys are never transmitted to our servers and reside in Secure Enclave hardware, preventing man-in-the-middle decryption.
Encrypted Blob Storage
Symmetric chat room keys are encrypted locally under target participant public keys prior to cloud upload. Message payloads, files, and location data are stored on databases strictly as encrypted JSON blobs.
3. Account Deletion & Grace Period
You retain the right to delete your profile, credentials, and data logs at any moment. Requests can be triggered via the Mobile App Settings or the web route /delete-account.
For cryptographic audits or privacy queries, contact our Security Response Team: