PRIVACY_POLICY.md
Last updated: July 2026
bitchat is designed for private, account-free communication. This policy describes what the app keeps on your device, what it sends when you use mesh or optional internet features, and how long local data can remain.
Identity and cryptographic keys
Nickname, preferences, and relationships
Private group state
Queued and carried private messages
Recent public mesh messages and notices
Media attachments
Optional location-channel state
While running, bitchat maintains active connections, routing state, deduplication state, and bounded in-memory conversation timelines. Closing the app clears the in-memory timelines and active connections, but it does not erase the persistent stores listed above.
Depending on the feature you use, nearby peers can receive:
Noise identity keys can persist across sessions; do not treat them as anonymous identifiers. Panic wipe rotates local identity state.
Private group members receive the group's name, roster, key epoch, and encrypted group traffic needed to participate. Group messages are confidential to devices holding the current group key, subject to the security of those devices and members.
Internet-backed features are optional. When enabled or used:
Nostr relays are operated by third parties. Their retention, logging, availability, and privacy practices are outside the project's control. Public events and encrypted events may remain on relays according to each relay's policy.
You can add relays yourself in settings, including .onion addresses. Added relays are stored locally, are limited in number, and are erased by panic wipe. Tor routing is on by default; while it is off, every relay you connect to can see your IP address, including relays carrying your private messages.
Location permission is optional and requested as when-in-use access. It is used to compute geohash channels, bridge rendezvous cells, and nearby place labels.
CLGeocoder service may process the location under Apple's privacy terms.Private and public features use different protections:
No cryptographic system can protect content after a recipient reads, copies, screenshots, or exports it.
bitchat does not:
The project does not knowingly operate a service that collects children's personal data. The app has no account registration or age-verification system. Users and guardians should understand that public mesh, board, bridge, and location-channel posts are visible to other participants and may be relayed.
Material behavior changes will be reflected in this document and its “Last updated” date. Updating this policy cannot retroactively retrieve data that remained only on a user's device.
bitchat is an open source project. For privacy questions:
This policy is released into the public domain under The Unlicense, like the project itself.