Roles
For end-user data that your app sends to hosted services, your organization is the controller and Offline Protocol is your processor under the data processing addendum. OfflineID is the exception: the core OfflineID account (email or phone, username, sign-in security) can be used across several apps, so Offline Protocol controls that account record and processes your app’s records for you. Offline Protocol controls developer account, billing and service-log data. Local peer-to-peer traffic over Bluetooth LE, Wi-Fi or other local transports never reaches Offline Protocol. The SDK opens no connection to Offline Protocol unless your app configures a hosted service.Hosted services
OfflineID
Requesting deletion of an OfflineID account signs the person out on every device and starts a 30-day grace period; signing in during it cancels the deletion. When the grace period ends, the account is deleted together with its related records: profile details and connections, relay identity keys, group memberships and queued messages, uploaded media and profile pictures, Proof of Location commitment secrets and off-chain records, and the person’s profile and events in Offline Protocol’s product analytics (PostHog). When Offline Protocol deletes an account on request, it keeps a record of the deletion that holds only keyed hashes of the email address and usernames, for three years, to show it was carried out.
Relay
The relay forwards MLS-encrypted message content it cannot decrypt. It sees sender and recipient addresses, usernames, group and message IDs, and message timing and size. It stores public identity keys, group membership and last-seen times. Undelivered messages are kept until delivered, for at most 7 days. If your app enables push notifications, notification details go through Firebase Cloud Messaging. The relay offers no anonymity or traffic-analysis resistance; see the threat model.Telemetry
Telemetry is off until you enable it for the application in the portal and callenableTelemetry in your app. It measures how the mesh behaves: message delivery results, latency and hop counts, routing decisions and transport changes, relay role changes, neighbor counts, queue sizes and bytes per minute, per-session summaries, encryption session errors, and battery level and charging state. Each record carries the application ID, app version, operating system and major version, a country code and a session identifier. It never carries message content, message IDs, contacts, names, usernames, email addresses, phone numbers, advertising identifiers, or location more precise than the country. Peer, user and group identifiers are hashed on the device and are not stored.
Session identifiers are random and rotate when the app goes to the background. A device identifier is sent only if you set includeDeviceId. The service hashes both again with a key that rotates every quarter, does not read the client IP address, and takes the country from its network provider’s request header.
Your plan limits how far back the portal shows analytics (7, 30 or 90 days, or longer by agreement). That limit does not delete older data.
Offline Protocol also builds aggregated, de-identified statistics across applications, grouped by day, region, operating system and transport. They contain counts, sums and percentiles only, carry no application or customer identifiers, and a group is kept only if it covers at least 100 distinct devices or app sessions. Smaller groups are discarded. The developer terms and the privacy policy’s section on aggregated data cover this.
Proof of Location
Proof of Location runs on the Ethereum Sepolia testnet. Your app sends the username, latitude, longitude and application ID. The service converts the coordinates to a geohash of about 5 km and does not store the raw coordinates. Witness operators receive the coordinates to check the claim. A random task ID, the geohash, the block time and a commitment (keccak256(username, geoHash, nonce) with a secret nonce) are written onchain. They are public and permanent. Offchain, the service keeps the username, task ID, commitment, transaction hash and nonce, and an index of each task with the centre point of its public geohash cell. Read location evidence security and obtain informed consent before you submit a location.

