Privacy Policy
Effective Date: 2 July 2026
Introduction
We respect your privacy and are committed to protecting your personal information. This Privacy Policy explains how the NowhereThen app (“the App”) handles user data across its different features.
Data Storage
Direct Messages
- Messages sent to specific recipients are encrypted end-to-end using the Presence Privacy Protocol (PPP). Each message is wrapped in three layers of encryption so that only the intended recipient can read it.
- The relay server stores only opaque encrypted blobs. It cannot read the content, location, or timing of your messages.
- When using sealed sender delivery, the relay cannot identify who sent a message — it only knows the recipient.
Gated Rooms
- Gated rooms require the room administrator to admit each participant. Admission is controlled via a proximity-verified knock mechanism.
- Messages in gated rooms are end-to-end encrypted with a room key that the admin shares with each participant through an encrypted handshake during admission. The relay never sees the key and cannot read room messages.
Your Identity
- Your identity is controlled by a cryptographic key pair stored only on your device. We do not have access to your private key.
- You can back up your identity using a 12-word recovery phrase that only you know.
Location Data
- When discovering nearby rooms, your device sends a coarse geographic cell identifier (approximately 300 meters resolution) to the relay. The relay does not receive your exact coordinates.
- The precise location of your messages is encrypted inside the message payload — the relay cannot determine where a message is located.
What the Relay Stores
- Encrypted message blobs (opaque to the relay)
- Room metadata: name, public descriptions, geographic cell, expiration time
- Encrypted room messages
- Push notification tokens (for background delivery)
- Sealed sender delivery tokens (12-byte routing tokens, not linked to your identity)
- Encrypted backup blobs (if you enable backup)
Connection Metadata (IP Addresses)
- Like any internet service, the relay receives the IP address your device connects from. This is inherent to making a network connection — it is not part of the encrypted message payload, and no online service can avoid receiving it.
- We do not log, store, or retain your IP address. IP addresses do not appear in our web access logs or in the relay’s service logs, and are never written to disk. Your IP is held in memory only momentarily — to route the response and to enforce per-IP rate limits — and is not persisted.
- Because we keep no record of it, we cannot reconstruct which IP address connected, when, or from where. We do not use connection metadata for advertising, profiling, ad-targeting, or building a history of your movements.
- Two limits, stated plainly: the relay does momentarily receive your IP in order to serve your connection; and our hosting provider, along with the networks between you and the relay, can observe connection-level metadata at the infrastructure layer, as they can for any internet service.
- We are working to reduce even this momentary exposure — oblivious-relay techniques (such as OHTTP) would route part of our traffic through an independent party that strips your IP before it reaches us. This is exploratory and not yet in place; this section describes how things work today.
Data Sharing
- We do not sell your data, and we do not share it with advertisers, brokers, or analytics providers.
- Data is shared between users only when you explicitly choose to share content. Direct messages are end-to-end encrypted so that only the intended recipients can read them.
- Room messages are visible only to admitted participants of that room.
- The one exception is abuse reports you submit — see “Abuse Reports” below.
Abuse Reports
- When you tap Report on a message, the App sends cryptographic evidence for that one message to our moderation operator: the encrypted message together with a key that opens only that message, the reason category you chose, and any free-text details you wrote. The operator decrypts and verifies the evidence to see the reported content.
- Your identity is not included in reports. The evidence proves the message is genuine on its own (the relay’s delivery receipt plus the sender’s signature), so we never learn who reported it. We also do not record the network address a report came from.
- This is the only situation in which message content leaves end-to-end encryption. It happens only on your explicit action, and only for the specific message you report.
- You can also report a room’s name or description. That text was never end-to-end encrypted — it is what the room shows to people nearby — so this adds no new exception. The report simply includes the room’s name and description as your device saw them, plus the reason and any details you wrote. It is anonymous like every other report.
- In rooms, you can choose to flag a message instead of reporting it immediately. A flagged message stays mathematically sealed from the operator until three independent members flag the same message — below that threshold we hold only metadata (which room, which message, the reason) and cannot read the content.
- The operator uses these reports solely to triage abuse, take moderation action (warning, room removal, ban), and keep an audit trail. Reports are not used for advertising, profiling, or training.
- Resolved reports (along with any moderation action taken) are retained for 12 months from the date of resolution, then permanently deleted. Unresolved reports are retained until they are resolved.
- Public keys are pseudonymous — they are not linked to your name, email, or phone number unless you separately publish that linkage.
Server Hosting
- The relay server runs on third-party infrastructure (VPS hosting). The hosting provider has physical access to the server and could, in principle, access data stored on disk.
- For direct messages and gated room messages, this is not a concern — the encrypted blobs are unreadable without the recipient’s private key or the room key, neither of which the hosting provider holds.
Your Rights
Depending on your jurisdiction, you may have rights to access, correct, or delete your data. Since your data is stored locally and encrypted, you exercise these rights directly through the App.
Children’s Privacy
The App is not directed to children under the age of 13 (or the relevant age in your country). We do not knowingly collect personal data from children.
Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted within the App or on this page.
Contact
If you have questions about this Privacy Policy, you can reach us at contact@nowherethen.com.