Legal information

Privacy, without asterisks.

Your most personal content is end-to-end encrypted. Here we explain, in a concrete way, which technical data the Duonook needs anyway and for how long they remain.

Effective August 25, 2026

No advertising profiling, sale of data or third-party analytics. The server stores the shared contents only in encrypted form and does not have the keys to read them.

1. Owner and contacts

The data controller is Guido Cacace, VAT number 13827430961, with headquarters in Via Alberelle 55, 20089 Rozzano (MI), Italy.

A data protection officer has not been appointed because, at present, the conditions that make it mandatory do not exist. For any privacy issue you can write directly to the owner.

2. Scope and minimum age

This information concerns the Duonook app, its backend and the public site. The basic app is intended for those who are at least 14 years old; if there is a higher threshold in the user's country, that threshold applies. Anyone who is not an adult must have permission from a parent or guardian. The methods indicated as adult remain reserved for adults.

Duonook does not ask for your date of birth or document: collecting this data would be disproportionate to the service. Age is confirmed during onboarding.

3. What data is processed

Access and devices

Random account and device identifiers, platform, hashed session tokens, authorization status, public keys, and technical data needed to connect two people in the same Pair. The app does not ask for email, password, phone number, address book or location. The email is processed only if you write to us voluntarily for assistance or privacy.

Torque Operation

Memberships, invitations, identifiers and sequence of events, times, object sizes, delivery status and synchronization. This metadata is used to authorize, order and deliver encrypted packets without reading their contents.

Operational choices and economics

Selected avatar and mood, chosen gift, opening status and reactions, identifiers of biscuits and seals, movements of the little hearts, unlocks, entitlements and receipts. This is limited data and does not include private texts entered by the couple.

Minigames

Chosen game, mode and version, session status, turns and technical results. Responses or packets that may reveal personal choices travel through the relay in encrypted form; quizzes and board games can keep insensitive moves or answers for the duration of the game only.

Notifications, security and support

Encrypted push endpoint, preferences by category, technical delivery results, server log with IP address, user agent, date, requested path and response code, as well as an IP fingerprint to apply anti-abuse limits. Support requests include what you choose to send us: do not attach recovery keys, letters, dedications or private photos.

4. What remains end-to-end encrypted

Names and nicknames, name of the Couple, date of the relationship, text of the Letters, elements of the Together list, titles and notes of the Story, photos and dedications of the gifts are encrypted on the device before sending. The backend stores and delivers opaque data and does not have the keys needed to read it.

Encryption protects the content, not the existence of an event: for example, the server can know that a packet was sent and when, but not what it contains. Duonook does not use the contents of the Nook for advertising, model training or automatic generation. The artificial intelligence tools present in the editorial panel only work on catalog contents prepared by administrators.

Authorized devices are part of the Pair's crypto group. Each person receives a personal recovery key; losing it together with all your authorized devices can make the contents unrecoverable even for Duonook.

5. Purposes and legal bases

  • Contract: create the anonymous account and the Couple, synchronize the encrypted contents, manage devices, catalog, Hearts, unlocks, minigames and assistance requested by the user.
  • Consent: activate optional functions when the law requires a free choice, for example the operating system permission for notifications. Consent can be revoked without retroactive effects.
  • Legitimate interest: protect accounts and infrastructure, prevent abuse and fraud, diagnose errors and defend rights, with minimized data and without commercial profiling.
  • Legal obligation: comply with tax, accounting regulations and valid requests from authorities.

No decisions with legal effects are made based solely on automated processing and no advertising profiling is carried out.

6. Suppliers and recipients

The data is communicated only to the extent necessary for the service:

  • IONOS SE: backend infrastructure, database and backup. The Duonook server verified at the time of this information is located on the IONOS network in Germany;
  • Server Plan S.r.l.: technical infrastructure and email of the duonook.com domain in Italy;
  • Expo / 650 Industries, Inc.: push notification routing and build technical services. The notifications contain generic copy, never names, letters, dedications or photos;
  • Apple and Google: app distribution, operating system notifications and, when present, management of payments made via the store;
  • consultants or authorities, only when necessary for a legal obligation, security or protection of a right.

Duonook does not sell data, does not share user lists with advertisers and does not make the Couple's contents public.

7. Transfers outside the European Economic Area

The main backend and its backups are hosted in Germany. Expo, Apple or Google may involve infrastructure outside the European Economic Area; in these cases the transfer is based on the mechanisms provided for in Chapter V of the GDPR, such as an adequacy decision and/or the standard contractual clauses adopted by the European Commission, as declared by the individual supplier.

8. Storage and deletion

  • Account, Pair and encrypted contents: until the account is deleted. Deletion archives the Pair, deletes contents, server-side keys, memberships, devices and sessions of both members because the space is shared.
  • Login sessions: access token for 15 minutes and refresh token for 30 days; Expired records are then deleted with technical maintenance.
  • Invitations: 48 hours for Duo invitations and 24 hours for minigame invitations; Expired technical records are removed within 30 days.
  • Remote minigames: session active up to 7 days; encrypted packages deleted 24 hours after confirmation of both and in any case within 7 days of closure; terminal metadata within 30 days; safety reports on contents within 180 days.
  • Notifications: token until revocation, cancellation or notification of device no longer registered; technical delivery tracks up to 30 days.
  • Web and API logs: automatic rotation when reaching 10 MB per file, with a maximum of 10 compressed archives. Data isolated for a security incident can remain for up to 180 days, or longer if needed for a prosecution.
  • Support: up to 24 months from the closing of the request, except for defense needs or legal obligations.
  • Accounting and purchasing: tax and accounting documents for 10 years from the last registration. Internal records essential to the integrity of wallets and unlocks may remain without personal attribution.
  • Backups: daily incremental and weekly full backups, with automatic rotation of up to 4 full cycles. After a cancellation, the remaining copies then exit ordinary rotation in approximately 4 weeks; they are not restored to recover individual deleted accounts. Any maintenance manual copies are eliminated within 30 days of the completion of the intervention.

From Settings you can export the readable data on the device and start the deletion. Read what happens, step by step.

9. Rights and complaints

You can request access, rectification, cancellation, limitation, portability and opposition in the cases provided for in articles 15–22 of the GDPR, or withdraw consent. Write to privacy@duonook.com. We will normally respond within one month.

Because the account does not contain email or name, we may ask you to verify the request from an authorized device. We will never ask you for the recovery key. The access right does not allow Duonook to decrypt content for which it does not have the key.

You can also lodge a complaint at Guarantor for the protection of personal data or to the competent supervisory authority where you live or work.

10. This site is public

The site does not use analytics, advertising pixels, profiling or resources incorporated by third parties. It only saves a functional cookie to remember the language, with a maximum duration of 12 months. The server records the technical logs described above for operation and security.

11. Changes to the information

The date at the top identifies the current version. If a change substantially affects processing, Duonook will communicate it in the app before it applies, when requested. Previous versions can be requested from the privacy contact.