Skip to main content
Use this page to write your app’s privacy notice and to fill in a data protection assessment. It describes how the services behave. The privacy policy, developer terms and data processing addendum are the binding documents; if this page and those documents differ, those documents control.

Roles

For end-user data that your app sends to hosted services, your organization is the controller and Offline Protocol is your processor under the data processing addendum. OfflineID is the exception: the core OfflineID account (email or phone, username, sign-in security) can be used across several apps, so Offline Protocol controls that account record and processes your app’s records for you. Offline Protocol controls developer account, billing and service-log data. Local peer-to-peer traffic over Bluetooth LE, Wi-Fi or other local transports never reaches Offline Protocol. The SDK opens no connection to Offline Protocol unless your app configures a hosted service.

Hosted services

OfflineID

Requesting deletion of an OfflineID account signs the person out on every device and starts a 30-day grace period; signing in during it cancels the deletion. When the grace period ends, the account is deleted together with its related records: profile details and connections, relay identity keys, group memberships and queued messages, uploaded media and profile pictures, Proof of Location commitment secrets and off-chain records, and the person’s profile and events in Offline Protocol’s product analytics (PostHog). When Offline Protocol deletes an account on request, it keeps a record of the deletion that holds only keyed hashes of the email address and usernames, for three years, to show it was carried out.

Relay

The relay forwards MLS-encrypted message content it cannot decrypt. It sees sender and recipient addresses, usernames, group and message IDs, and message timing and size. It stores public identity keys, group membership and last-seen times. Undelivered messages are kept until delivered, for at most 7 days. If your app enables push notifications, notification details go through Firebase Cloud Messaging. The relay offers no anonymity or traffic-analysis resistance; see the threat model.

Telemetry

Telemetry is off until you enable it for the application in the portal and call enableTelemetry in your app. It measures how the mesh behaves: message delivery results, latency and hop counts, routing decisions and transport changes, relay role changes, neighbor counts, queue sizes and bytes per minute, per-session summaries, encryption session errors, and battery level and charging state. Each record carries the application ID, app version, operating system and major version, a country code and a session identifier. It never carries message content, message IDs, contacts, names, usernames, email addresses, phone numbers, advertising identifiers, or location more precise than the country. Peer, user and group identifiers are hashed on the device and are not stored. Session identifiers are random and rotate when the app goes to the background. A device identifier is sent only if you set includeDeviceId. The service hashes both again with a key that rotates every quarter, does not read the client IP address, and takes the country from its network provider’s request header. Your plan limits how far back the portal shows analytics (7, 30 or 90 days, or longer by agreement). That limit does not delete older data. Offline Protocol also builds aggregated, de-identified statistics across applications, grouped by day, region, operating system and transport. They contain counts, sums and percentiles only, carry no application or customer identifiers, and a group is kept only if it covers at least 100 distinct devices or app sessions. Smaller groups are discarded. The developer terms and the privacy policy’s section on aggregated data cover this.

Proof of Location

Proof of Location runs on the Ethereum Sepolia testnet. Your app sends the username, latitude, longitude and application ID. The service converts the coordinates to a geohash of about 5 km and does not store the raw coordinates. Witness operators receive the coordinates to check the claim. A random task ID, the geohash, the block time and a commitment (keccak256(username, geoHash, nonce) with a secret nonce) are written onchain. They are public and permanent. Offchain, the service keeps the username, task ID, commitment, transaction hash and nonce, and an index of each task with the centre point of its public geohash cell. Read location evidence security and obtain informed consent before you submit a location.

Developer tools

Deletion and export

An owner can delete an organization in Settings, Advanced once any outstanding balance is paid. Organizations on an Enterprise contract are closed through your account team. Deleting it cancels the paid subscription, bills any overage for the final billing period, and deactivates the organization and its applications and API keys immediately. Thirty days later its data is permanently deleted, except records Offline Protocol must keep for legal, tax, billing or security reasons. You can delete your developer account in the portal after you transfer or delete each organization you own. The request signs you out everywhere and revokes the API keys created by CLI logins. Your account is deleted 30 days later, with the same exceptions; signing in before then cancels the deletion. To ask for any other deletion, email legal@offlineprotocol.com.

Contact

Privacy requests and policy questions: legal@offlineprotocol.com. Security and vulnerability reports only: security@offlineprotocol.com.