Skip to content
Offline Protocol logo Offline Protocol
Connect and sync
Mesh networking Five transports, multi-hop relay, automatic failover Offline identity Device-owned keys, verified device-to-device, bound to accounts Edge sync Edge-native shared state that converges without a server Offline telemetry One opt-in stream, identifiers scrubbed by default
Invoke
Service discovery Advertise, discover, and invoke with no server or DNS Capability Exchange Evidence-based routing across nearby, gateway, and hosted providers Coming soon
Get started
Start building Create a project, get an API key, and watch your devices come online in the developer dashboard. Open the dashboard →
One stack for transport, identity, discovery, data, and execution →
Device makers
Embedded and OEM platforms The leaf profile on constrained silicon, integrated once beside your radio stack Robotics and autonomous systems Swarm coordination past GPS denial and lost links AI agents and edge intelligence Peer-to-peer agent discovery and invocation Agriculture Equipment and sensors beyond rural coverage
Operators
Logistics and field operations Yards, ports, corridors, and linehaul dead zones Energy, utilities, and industrial sites Metering, gateway continuity, and crews off-grid Public sector and distributed sites Coordination through outages and blackouts Live events, venues, and ticketing Crowd-scale connectivity and ticket checks at the gate
Deployed today
Customer stories Read how teams use Offline Protocol to keep their operations running when the network goes down. Read the stories →
Scope an evaluation: one workflow, agreed criteria, 4 to 16 weeks →
Build
Quickstart Install, initialize, and send a message with no server Live demo Watch the SDK pick a transport, in your browser Offline Protocol CLI Log in, wire a project, and add packages from the terminal MCP server Local or hosted, for Claude Code, Codex, Cursor, and more
Reference
Documentation Guides and technical reference API reference TypeScript API over the Rust core Roadmap Shipped, in development, and exploring Security Encryption, identity, and disclosure Service status Live availability and incidents
Agentic development
Build with agents Claude Code, Codex, Cursor, Gemini CLI, VS Code with Copilot, and other MCP clients read the real SDK guidance and scaffold your project. npx -y @offline-protocol/cli mcp serve Connect over MCP →
Ship the mesh in an afternoon. Start with the quickstart →
Pricing
Company
About Who is building it and who backs it Blog Technical and non-technical writing from the team Changelog Every SDK release, newest first Careers Build the network with us Shop Hardware relays and mesh radios
Guides
Glossary Offline and mesh networking terms, defined What is offline mesh networking? The core concept in plain language BLE mesh vs Thread vs Matter How the standards compare Offline-first architecture Designing for no connectivity Compare overview Offline Protocol vs the alternatives
Learn more
Blog What we are shipping, how it works, and where it is being used. Read the blog →
New to offline mesh networking? Start with the glossary →
Docs Start building

Legal

Data processing addendum

Effective September 29, 2026. Last updated September 29, 2026.

The processor terms for personal data that Offline Protocol handles on behalf of customers through its hosted services. It is part of the developer terms automatically, and it includes the details of processing, our security measures, and the Standard Contractual Clauses for international transfers.

On this page
  1. 1. Scope and incorporation
  2. 2. Roles of the parties
  3. 3. OfflineID accounts
  4. 4. Processing on instructions
  5. 5. Personnel and confidentiality
  6. 6. Security
  7. 7. Subprocessors
  8. 8. Data subject requests and assistance
  9. 9. Personal data breaches
  10. 10. Deletion and return
  11. 11. Aggregated and de-identified data
  12. 12. Audits and information
  13. 13. International transfers
  14. 14. U.S. state privacy law terms
  15. 15. Liability and precedence
  16. Annex 1. Details of processing
  17. Annex 2. Technical and organizational measures
  18. Annex 3. Subprocessors

1. Scope and incorporation

This Data Processing Addendum (“DPA”) forms part of the Developer Terms of Service or any Order between Offline Protocol, Inc. (“Offline Protocol”) and Customer (together, the “Agreement”). It applies when Offline Protocol processes Customer Personal Data on Customer’s behalf in providing the Hosted Services. It applies automatically when Customer accepts the Developer Terms. Customers who need a countersigned copy can request one from legal@offlineprotocol.com.

Capitalized terms not defined here have the meanings in the Developer Terms. “Data Protection Laws” means all laws on the processing of personal data that apply to a party’s processing under the Agreement, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and U.S. state privacy laws such as the California Consumer Privacy Act as amended (“CCPA”). “Customer Personal Data” means personal data within Customer Data that Offline Protocol processes as a processor. “Controller”, “processor”, “data subject”, “personal data breach”, and “processing” have the meanings in the GDPR, and “business”, “service provider”, “sell”, and “share” have the meanings in the CCPA.

2. Roles of the parties

For Customer Personal Data, Customer is the controller (or a processor acting for its own controller, in which case Offline Protocol is a subprocessor), and Offline Protocol is the processor. For the purposes of the CCPA, Offline Protocol is Customer’s service provider.

Offline Protocol is an independent controller for Account Data and Service Data, and for aggregated, de-identified data under Section 11. Its privacy policy governs that processing.

3. OfflineID accounts

An End User can use one OfflineID across several Customer Applications and across Offline Protocol’s own apps. For that reason:

  • Offline Protocol is an independent controller of the core OfflineID account: the email address or phone number, username, account status, and sign-in security records, and the End User’s own choices about their profile and connections.
  • Offline Protocol is Customer’s processor for records about the End User’s use of Customer’s Application, such as the fact and dates of sign-ins to that Application, and any other data Customer’s Application submits.
  • When an End User deletes their OfflineID account, it is deleted for every Application. Customer may ask us to remove an End User’s records relating to Customer’s Application without deleting the core account.

4. Processing on instructions

Offline Protocol will process Customer Personal Data only on Customer’s documented instructions, unless the law requires otherwise, in which case it will inform Customer first unless the law prohibits that. The Agreement, Customer’s configuration of the Services (such as enabling telemetry or Proof of Location for an Application), and Customer Applications’ calls to the Hosted Services are Customer’s complete instructions. Offline Protocol will tell Customer if it believes an instruction infringes Data Protection Laws.

Customer is responsible for the lawfulness of its instructions, for giving End Users the notices and obtaining the consents that Data Protection Laws require, and for the accuracy of the data it submits. Customer will not submit special categories of personal data unless an Order allows it.

The subject matter, duration, nature, and purpose of the processing, and the types of personal data and categories of data subjects, are set out in Annex 1.

5. Personnel and confidentiality

Offline Protocol will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and have access only as needed to provide, secure, and support the Services.

6. Security

Offline Protocol will implement and maintain the technical and organizational measures in Annex 2, which are designed to protect Customer Personal Data against a personal data breach. Offline Protocol may update the measures as long as the overall level of protection is not reduced. Customer is responsible for its own security, including keeping API Keys secret, configuring allowed origins and Member roles, and securing Customer Applications and devices.

7. Subprocessors

Customer gives Offline Protocol general authorization to engage subprocessors. The current list is on the subprocessors page. Offline Protocol will impose data protection obligations on each subprocessor that are no less protective than this DPA, and remains responsible for their performance.

Offline Protocol will update the list before a new subprocessor begins processing Customer Personal Data and, for Customers who subscribe, will send notice at least 30 days in advance. Customer may object on reasonable data protection grounds within that period. The parties will then discuss the objection in good faith. If Offline Protocol cannot offer a reasonable alternative, Customer may terminate the affected Services and receive a refund of prepaid fees for the period after termination.

8. Data subject requests and assistance

If Offline Protocol receives a request from a data subject about Customer Personal Data, it will direct the person to Customer where it can identify Customer, and will not respond to the substance of the request except as Customer instructs or the law requires. Taking into account the nature of the processing, Offline Protocol will provide reasonable assistance to Customer in responding to data subject requests, in carrying out data protection impact assessments, and in consultations with supervisory authorities, to the extent Customer cannot do so with the Services’ own features.

9. Personal data breaches

Offline Protocol will notify Customer without undue delay, and where feasible within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice goes to the Organization owner’s email address and will describe, as far as known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Offline Protocol will provide further information as it becomes available and take reasonable steps to contain and remedy the breach. Notification is not an acknowledgment of fault.

10. Deletion and return

Customer can retrieve Customer Personal Data through the Hosted Service APIs during the term. An owner can delete an Organization in the portal once any outstanding balance is paid. Deleting it cancels the paid subscription, bills any overage for the final billing period, and deactivates the Organization and its Applications and API Keys immediately. Thirty days later we permanently delete its Customer Data and Organization records, except records we must keep for legal, tax, billing, or security reasons. On termination of the Agreement, or on Customer’s written request to legal@offlineprotocol.com, Offline Protocol will delete Customer Personal Data within 30 days, except where the law requires it to be kept, and except for data in backups, which is deleted as the backups expire and is protected under this DPA until then.

Proof of Location records written to a public blockchain cannot be deleted by Offline Protocol or anyone else. Customer acknowledges this before submitting data to Proof of Location.

11. Aggregated and de-identified data

Customer authorizes Offline Protocol to create aggregated, de-identified data derived from the use of the Hosted Services, including telemetry and usage, and to use, publish, share, and license it for any lawful purpose, provided that it does not identify Customer, any Customer Application, or any individual. Offline Protocol will: (a) remove application and Customer identifiers; (b) keep an aggregate group only when it covers at least 100 distinct devices or app sessions, and discard smaller groups; (c) not attempt to re-identify any person or Customer; (d) contractually prohibit recipients from attempting re-identification; and (e) take reasonable measures to ensure the data cannot reasonably be linked to an identified or identifiable person. Data meeting these conditions is not Customer Personal Data, and Offline Protocol processes it as an independent controller, or not as personal data at all.

Telemetry describes how the mesh network behaves: delivery results, latency, routing, transports, relay roles, queue sizes, encryption session errors, and battery state, with an application ID, app and operating system versions, a country code, and randomly generated session and install identifiers that Offline Protocol hashes with a quarterly rotating key. It does not contain message content, contacts, names, usernames, email addresses, phone numbers, advertising identifiers, or location more precise than the country.

12. Audits and information

Offline Protocol will make available the information reasonably necessary to demonstrate compliance with this DPA, including written responses to reasonable security questionnaires once per year. If that information is not enough to satisfy an obligation under Data Protection Laws, Customer may conduct an audit, at its own cost, no more than once every 12 months, on at least 30 days’ written notice, during business hours, subject to confidentiality, and in a way that does not disrupt the Services or other customers’ data.

13. International transfers

Offline Protocol and its subprocessors may process Customer Personal Data outside the country where it was collected, including in Singapore, the United States, the European Union, and India. Where a transfer of Customer Personal Data from the EEA, Switzerland, or the United Kingdom to a country without an adequacy decision is made under this DPA, the parties agree to the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 (the “SCCs”), which are incorporated by reference as follows:

  • Module Two (controller to processor) applies where Customer is a controller, and Module Three (processor to processor) applies where Customer is a processor.
  • Clause 7 (docking clause) applies. In Clause 9, Option 2 (general authorization) applies, with the notice period in Section 7 of this DPA. The optional language in Clause 11 does not apply.
  • In Clauses 17 and 18, the SCCs are governed by the laws of, and disputes resolved by the courts of, Ireland.
  • Annexes I and II of the SCCs are completed with Annexes 1 and 2 of this DPA. The competent supervisory authority is the one determined under Clause 13.
  • For transfers from the United Kingdom, the International Data Transfer Addendum issued by the UK Information Commissioner (version B1.0) applies, with the tables completed with the information in this DPA, and either party may end it as allowed by its Section 19.
  • For transfers from Switzerland, references to the GDPR include the Swiss Federal Act on Data Protection, and the Swiss Federal Data Protection and Information Commissioner is a competent supervisory authority.

14. U.S. state privacy law terms

As Customer’s service provider, Offline Protocol will not: sell or share Customer Personal Data; retain, use, or disclose it for any purpose other than the business purposes in the Agreement, including for any commercial purpose other than providing the Services; retain, use, or disclose it outside the direct business relationship with Customer; or combine it with personal data it receives from other sources, except as permitted by the CCPA. Offline Protocol will comply with the CCPA’s obligations on service providers, will tell Customer if it can no longer meet them, and allows Customer to take reasonable steps to stop unauthorized use. Offline Protocol certifies that it understands these restrictions.

15. Liability and precedence

Each party’s liability under this DPA, and under the SCCs to the extent the SCCs allow, is subject to the exclusions and limitations of liability in the Agreement, including the aggregate cap, except where Data Protection Laws do not allow it. If this DPA conflicts with the Developer Terms, this DPA controls for the processing of Customer Personal Data. If it conflicts with the SCCs, the SCCs control.

Annex 1. Details of processing

ItemDetails
Data exporterCustomer, as identified in its Organization. Contact: the Organization owner.
Data importerOffline Protocol, Inc., a Delaware corporation. Contact: legal@offlineprotocol.com.
Data subjectsEnd Users of Customer Applications; Customer’s personnel whose details Customer submits to the Hosted Services.
Nature and purposeProviding the Hosted Services that Customer enables: authenticating End Users and maintaining their OfflineID profiles and connections (OfflineID); storing and forwarding encrypted messages (relay); collecting mesh performance telemetry and producing analytics (telemetry); recording and attesting location claims (Proof of Location); metering, security, and support.
FrequencyContinuous, for as long as Customer uses the Hosted Services.
DurationThe term of the Agreement and the deletion period in Section 10.
Sensitive dataPrecise location, when Customer Applications submit profile location or Proof of Location claims. No special categories of data are intended. Safeguards: access controls in Annex 2; exact profile locations visible only to the owner and to connections the owner chooses; Proof of Location coordinates reduced to a coarse geohash before publication and not stored.

Categories of personal data and retention, by service

ServicePersonal dataRetention
OfflineIDEmail address or phone number; username; profile details (text, picture, social links, optional location); connections and location-sharing choices; off1 device address; push tokens with device model, OS, and app version; per-application sign-in dates and counts; sign-in events.Until the End User deletes the account (30-day grace period) or Customer requests deletion of its application records. When the grace period ends, we delete the account together with its related records: profile details and connections, relay identity keys, group memberships, and queued messages, uploaded media and profile pictures, Proof of Location commitment secrets and off-chain records, and the person’s profile and events in our product analytics (PostHog). Sign-in codes: 10 minutes.
RelaySender and recipient addresses and usernames; group and message IDs; message timing and size; end-to-end encrypted message content; public identity keys; group membership; last-seen time; push notification details when enabled.Queued messages: until delivered, at most 7 days. Keys, groups, and last seen: while the OfflineID account exists.
TelemetryRandomly generated session identifiers and, where the app opts in, install identifiers, hashed on our servers with a quarterly rotating key; application ID; app version; operating system and major version; country code; mesh delivery, latency, routing, transport, relay, queue, encryption session error, and battery measurements. No IP address is stored.Raw events: 30 days. Per-minute: 48 hours. Live feed: 2 hours. Daily per-application aggregates: life of the Application. Breakdowns by OS and country: 2 years.
Proof of LocationUsername; application ID; submitted latitude and longitude (not stored); geohash; commitment; transaction hash; secret commitment value; witness attestations.Off-chain records: while the OfflineID account exists, or until deletion under Section 10. On-chain geohash, time, and commitment: permanent.

Annex 2. Technical and organizational measures

  • Encryption in transit. TLS on every public endpoint of the portal, hosted APIs, and hosted MCP server.
  • End-to-end message encryption. Message content sent through the relay is encrypted by the SDK with MLS (RFC 9420); the relay cannot decrypt it.
  • Hosting. Databases and services run on Railway in Singapore, with relay servers also in the United States, and uploaded media is stored with Hetzner in the European Union, under those providers’ physical and environmental security controls.
  • Authentication. One-time sign-in codes that expire after 10 minutes and are rate limited per identifier and per IP address; signed (RS256) session tokens; revocable API Keys (we store API Keys only as hashes. A key is shown in full once, when it is created, and cannot be shown again.); CLI sign-in session secrets stored only as hashes; CLI sign-in requests that expire after 5 minutes.
  • Authorization. Organization roles (owner, admin, developer, billing, analyst, read-only), per-Application access grants, optional email-domain restrictions on membership, and per-Application allowed web origins checked on browser requests.
  • Data minimization. The telemetry service does not read client IP addresses and re-hashes session and device identifiers with a quarterly rotating key; Proof of Location does not store raw coordinates; public network statistics round locations to about 1 km and omit usernames; error monitoring has sending of default personal data disabled.
  • Payment data. Card details are collected by Stripe on Stripe-hosted pages and never reach Offline Protocol’s systems.
  • Access control for staff. Production access limited to personnel who need it for their role.
  • Logging and monitoring. Service logs kept by our hosting provider for 90 days or less, error monitoring, and an audit log of CLI sign-ins kept for 12 months, then deleted automatically.
  • Availability. Managed hosting, with the relay running in two regions (Singapore and the United States).
  • Vulnerability management. Automated dependency updates, a responsible disclosure policy, and coordinated fixes.
  • Incident response. Breach notification to Customers as set out in Section 9.
  • Subprocessor management. Written agreements with each subprocessor, listed on the subprocessors page.

Annex 3. Subprocessors

The subprocessors authorized under Section 7 are those marked as processing Customer Data on the subprocessors page.

Questions about this document, privacy requests, and anything else policy related: email legal@offlineprotocol.com. Security vulnerabilities: security@offlineprotocol.com. All of our legal documents are listed on the legal page.

Offline Protocol

The coordination layer for physical systems.

© 2026 Offline Protocol, Inc.

Platform

The platform Mesh Identity Edge sync Telemetry Discovery Embedded

Solutions

RoboticsAI agentsAgricultureLogisticsEnergyPublic sectorEvents and ticketing Stories

Developers

Developer portal Quickstart Live demo CLI MCP server Documentation API reference Roadmap Security Pricing

Resources

Glossary Compare Blog Changelog The network Ecosystem

Company

About Careers Contact Shop Terms Privacy Developer terms Legal

We use privacy-friendly analytics to understand what's useful and improve the site. Nothing is collected until you allow it. See our privacy policy.

Privacy preferences

Choose what this site may use. You can change this anytime from the privacy policy. Nothing here is shared with advertisers or used to track you across other sites.

Essentiali
Always on

Remembers your theme and this consent choice, in your browser only. No analytics, no tracking.

Product analyticsPostHogi

Helps us see which content and calls-to-action are useful. On by default. Turn it off here anytime.