Nodryn

Privacy policy

Version 1 · effective [date on publication] · applies to the Nodryn app on all platforms

The short version

We never ask for your name, phone number or email, and we never read your address book. There is no sign-up, no password and no profile - so there is no account of yours for anyone to seize. Our mailbox does keep four things so people can reach you; they are all listed below, with how long each one lives.

Messages, calls and files are end-to-end encrypted. We cannot read them - not because we promise not to, but because the keys exist only on your devices.

What we can see is written out in full below, including the parts that are inconvenient for us - the year-long backup, the thirty-day routing rows, and the one thing Apple learns when it wakes your phone. We would rather tell you than have you find out.

Who we are

Nodryn is made by WM SOFT, CORP., a company registered in Florida, United States. Questions about this policy: privacy@nodryn.com. Security reports: security@nodryn.com, see also security.txt.

What we never collect

None of the following is requested, stored or transmitted by the app:

The two Google libraries in the store build

The build we submit to Google Play links two Google libraries, and we would rather name them than let you find them: Firebase Cloud Messaging, which wakes your phone, and Google Maps, used only if you choose to send a location. Neither is analytics and neither reports on you to us. The store-free build we distribute ourselves uses neither - it wakes phones through UnifiedPush and draws maps with an open-source library instead.

What does leave your device

An identity in Nodryn is a pair of cryptographic keys generated on the device itself. For two devices to find each other and exchange messages, some information necessarily travels. This table is what moves; the table after it is what rests, and for how long:

WhatWhere it goesCan we read it
messages, files,
photos, voice notes
directly to your correspondent's device, or - if they are offline - to a mailbox node we operate, where a sealed envelope waits until their device confirms it has it, and at most 7 days either way no
device addresses published to address-book nodes so correspondents can find your device yes, this is public by design
wake address
(push token)
registered with the mailbox node so your phone can be woken when a message arrives; dropped 30 days after you last use that node yes

How long anything of yours can rest on our nodes

Three different things can sit on a mailbox node, for three very different lengths of time. We are listing all three, including the one that lasts a year - you would find it eventually, and it is better that you find it here.

WhatHow longWhy it is there at all
a sealed message
waiting for you
until your device confirms it,
and at most 7 days
so a message sent while your phone was off still reaches you. It is erased the moment your device says it has it - seven days is the outside limit, not the usual case.
your published keys,
device list and
wake address
30 days after you
last use that node
so somebody can start a conversation with you, and so your phone can be woken. Every time your phone talks to the node the clock resets. Leave a node for good and it forgets you within a month, instead of keeping a live map of where to reach you.
an encrypted backup
of your own data
up to a year after you
last use that node
only if you switch backups on - they are off until you do. A year is the gap we allow between losing a phone and buying the next one. After that, your blob should not still be sitting on somebody else's disk.

If you turn backups on, what is copied is your message history, your contacts, your own list of devices and the bookkeeping of your groups. The files themselves and your encryption sessions are deliberately not copied. The whole thing is sealed with a key derived from your twelve words, so the node holding it - and we - cannot open it.

What each of our nodes can see

We will not tell you "we see nothing" - that would be false. Here is the complete list.

Relay nodes

See encrypted packets passing through: which device is speaking to which, the network address the packet came from, its size and the time. A relay has to know where to forward a packet, so it necessarily knows both device keys - anyone claiming otherwise about any relay is describing something that could not work. What it cannot see is a single word of what is inside, and the device keys tell it nothing about who you are.

Address-book nodes

Hold a signed record mapping a device key to its current network address, so your correspondents can reach you. This record is public by design - anyone who already knows your device key can look up its address. It says nothing about who your contacts are.

Mailbox nodes

This is the node that sees the most, and we say so plainly. When your correspondent is offline, an encrypted envelope waits here. The mailbox sees the sender's device, the recipient's device, the time and the size. It cannot open the envelope. After 7 days the envelope is deleted, whether or not it was collected.

If you have switched backups on, this is also the node that holds your encrypted backup, one row per device. It sees that a backup exists, whose device it belongs to, how large it is, and a counter telling it which copy is the newest - that counter has to be readable, or the node could not tell a fresh backup from a stale one. Everything else is inside the encryption. It cannot open that either. The table above says how long each of these lives.

Push notifications

To wake a sleeping phone we send a signal through Google's Firebase Cloud Messaging (Android) or Apple's push service (iOS). The two are not the same, and we will not pretend they are.

On Android the signal is empty - literally one field meaning "something arrived". Google learns that your device was woken at a certain time and nothing else.

On iPhone the system draws the notification card before our app is allowed to run, so the signal must say which of three cards to draw: a new message, an incoming call, or a missed call. It carries the name of a phrase, never the phrase - your own phone turns that name into words in your own language. So Apple learns that your device was woken, and which of those three kinds of event it was. Neither Apple nor Google learns who wrote to you, and neither learns a word of what was said.

What stays on your device

Your conversations, files and keys live in encrypted storage on the device itself (SQLCipher). Deleted content is overwritten rather than merely unlinked.

Your identity can be restored only with the twelve-word recovery phrase shown when you first launch the app. We do not have it and cannot obtain it. If you lose those words, nobody - us included - can recover your conversations. This is a deliberate trade: what we do not hold cannot be taken from us.

Deleting your data

There is no "delete my account" request to send us, because there is no account and no profile of you on our side to delete.

What we cannot protect you from

An unlocked phone in someone else's hands. Encryption protects a message in transit and at rest. It does nothing about a device someone picks up already unlocked. Use a screen lock.

The other side of the conversation. Whoever you write to can screenshot, copy or repeat what you said. No messenger can prevent this, and any that claims otherwise is lying.

Losing the twelve words. There is no reset link, no support ticket, no recovery by text message. That is the price of us not holding your keys.

Why we are allowed to hold the little we hold

If you are in the European Union or the United Kingdom, the law wants us to name a lawful basis for every piece of data we process. Ours is short, because the list is short.

WhatWhy we may hold it
a sealed envelope
waiting for you
Performance of a contract. You asked us for a messenger; a messenger that drops everything sent while your phone was off is not one.
published keys,
device list
Performance of a contract. Without them nobody can start a conversation with you at all.
wake address
(push token)
Performance of a contract. A phone that is asleep has to be woken or the message arrives tomorrow.
encrypted backup Your consent. It is off until you switch it on, and switching it off withdraws that consent.
node logs and
counters
Legitimate interest in keeping the nodes running and defending them from abuse. They record that a node did something, not who you are.

Your rights, and the honest limits of them

European and UK law gives you rights over your personal data: to see it, correct it, have it erased, have it handed to you in a portable form, object to its processing, and complain to your national data protection authority. We are not going to pretend those rights work here the way they work at a company holding your profile - because we hold no profile, most of them resolve to something simpler.

One real limit, stated plainly: because we cannot tell which device belongs to which person, we cannot verify that a request to erase somebody's data comes from that somebody. Acting on such a request would let a stranger delete your things. So we do not act on identity-based requests at all - which is why we built the timers above to do the work instead.

Where the data physically is

Our nodes run in Helsinki, Finland and in Ashburn, Virginia, on servers rented from Hetzner, plus one machine of our own in the United States. Your device talks to whichever it can reach, so an envelope may cross a border on its way to you. What crosses is what the tables above describe: sealed bytes, a device key and a timestamp. The company behind Nodryn, WM SOFT, CORP., is registered in the United States, so treat the United States as one of the places your envelope metadata can rest.

Three other companies touch anything at all, and only in the narrow ways already described: Hetzner runs the machines our nodes sit on, Google carries the signal that wakes an Android phone, and Apple carries the one that wakes an iPhone. None of them is given your messages, because none of them could open them.

Legal requests

If we are compelled by lawful process to hand over data, we can hand over only what we actually hold: for a mailbox node, the envelope metadata described above while an envelope exists, plus the routing rows named in the retention table - your published keys, your device list, your wake address, and a sealed backup if you made one - and the operational logs our nodes keep to stay alive. We cannot produce message content, because it is encrypted with keys we do not have. We hold no name, no phone number and no email that could identify you.

Children

Nodryn is not directed at children. We do not knowingly collect information from anyone, of any age, beyond what is described here - and what is described here contains no name, no phone number, no email address and no advertising identifier. It does contain your device's public key, which is what lets anyone reach you at all, and the wake address your phone's operating system hands us.

Changes

If this policy changes, the new version appears on this page with a new effective date.