Privacy Policy & Zero-Trust Mandate

How ITsf Assistant (assistant.itsf.gr) secures, processes, and respects user data under air-gapped environments

LAST UPDATED: July 29, 2026

Scope of this Policy

This Privacy Policy explains how Assistant ITsf.gr (the "App," "Service," or "we") collects, uses, stores, and protects user data and information collected through our mobile application (the "Client App"), desktop executables, and associated services (the "Backend Server"). To guarantee absolute compliance with the zero-trust paradigm, our storage architecture operates under a Zero-Knowledge mandate—meaning we design systems so that even our administrators cannot read your private communications.

1. Information We Collect

A. Personal Data (Provided by You)
Data Type Purpose Retention Period
Account Details
Username, Email, Passwords
Account provision, login authentication, and secure workspace access. Active Membership
+ 7-day deletion grace
Session Security & Protection
Session Tokens, Tab Expiry State
Auto-halting background requests on 401/403 session end to protect client IPs from false Fail2Ban bans; 2-minute login page inactivity redirect. Transient Browser Session
Instant redirect to /login
User-Generated Content & AssistantBER Transfers
Files, documents, & AssistantBER media stream downloads
Encrypted storage and secure file routing in personal My Files storage. Legal Disclaimer: End-users assume 100% sole legal responsibility and copyright compliance for all streams and files processed via AssistantBER or saved to My Files. Active Membership
Deleted immediately on user request
Wiki Knowledge Base & Confluence Imports
Documentation pages, spaces, & Markdown content
Application-layer zero-trust encryption (EncryptedText) with space-level RBAC clearance isolation (Resistance, Logismos, General). Encrypted RDBMS
Zero-trust access controlled
B. Sensitive Device Permissions
Permission Purpose Data Transfer & Storage Status
Camera QR-code login provision & real-time WebRTC video calls. No Data Transmitted
Processed transiently in-memory
Microphone Real-time voice chats, LiveKit calls, and VoIP. No Data Transmitted
No recording is ever saved
Telephony / Call State Monitors active cellular calls to auto-disconnect VoIP sessions. Local Processing Only
Managed entirely on-device
Biometric Scan Local application unlock & secure token storage. 100% Local (OS Chip)
Zero access by the server
File Picker Enables manual file uploads inside secure vaults. Encrypted Transfer
Transmitted over TLS to vault

2. Cryptographic Zero-Trust Controls

Identity Key Generation

Private Identity Keys are negotiated locally on client devices using the X25519 Elliptic Curve. These keys are never transmitted to our servers and reside in Secure Enclave hardware, preventing man-in-the-middle decryption.

Encrypted Blob Storage

Symmetric chat room keys are encrypted locally under target participant public keys prior to cloud upload. Message payloads, files, and location data are stored on databases strictly as encrypted JSON blobs.

3. Account Deletion & Grace Period

You retain the right to delete your profile, credentials, and data logs at any moment. Requests can be triggered via the Mobile App Settings or the web route /delete-account.

01
Deactivation Account access and keys are locked immediately.
02
7-Day Grace Period Stored securely in isolation allowing deletion rollback.
03
Permanent Purge Automatically and completely wiped from physical storage.

For cryptographic audits or privacy queries, contact our Security Response Team: