Privacy policy
Effective 31 July 2026. Applies to the PSippr application for Android and desktop and to this website.
Contact: Milan Jurkulák, mimoccc@gmail.com.
1. The short version
PSippr keeps no data about you on any server. There is no account, no sign-up and no database of users anywhere. Everything you create — profile, photos, albums, messages, call history — is stored on your own device and travels to the devices of the people you talk to, encrypted end to end.
When two devices cannot reach each other directly (typically both on mobile data), the encrypted packets are forwarded by a relay server. The relay sees the IP addresses and device identifiers of both sides and the timing and volume of traffic; it cannot read the content. The relay is run by the author on psippr.org, inside the EU. If the person you talk to still uses an older version of the app, their device may use a relay run by n0 (the makers of the networking library) instead.
Because of that, the author of the app has no access to your data, cannot read your messages, cannot see where you are, and has nothing to hand over to anyone.
2. What data exists and where it lives
| Data | Where it is | Who can see it |
|---|---|---|
| Profile (nickname, age, photos, video, bio, height, weight, preferences, what you are looking for) | your device | people you are visible to in the app |
| Messages, photos, videos and voice notes in chats | your device and the device of the other person | only the two of you |
| Albums | your device; shared copies on devices you granted access to | people you grant access to |
| Date of birth (18+ check) | your device only | nobody |
| Approximate location (geohash) | your device; the coarse area is part of your announcement | people around you in the app |
| Favorites, blocked people, notes | your device only | nobody |
| Call history and settings | your device only | nobody |
Nothing in this table is uploaded to a server operated by the author. The author runs one small service at psippr.org; it holds only network entry points (see section 3), payment confirmations and role certificates, never the data above.
3. What is published about you
To be findable, your device broadcasts a small, cryptographically signed announcement over the local network and into the peer-to-peer gossip room of your coarse area. It contains your nickname, your device identifiers, a coarse area, your online status, a hash of your profile, your age, height and weight, your preferences and what you are looking for, what you are currently listening to (if you turned that on) and the app version — that is, what other users see on your card in the app.
Two more small records exist so that devices can find each other:
- your device publishes a signed record "device identifier → relay address" to the public BitTorrent Mainline DHT (a network of millions of independent nodes that nobody operates) and reads the records of others from there; your IP addresses are not put into the DHT. As a fallback the same record is also kept on psippr.org (older app versions used the DNS service of n0,
iroh.link); - your device writes its discovery identifier into the public DHT record of your coarse area (a record shared by everyone in that area; identifiers older than two hours drop out), so that others in the area can find it. As a fallback it also registers the identifier and coarse area at psippr.org, a service run by the author (entries expire when not renewed). No profile data is stored in either place.
Anyone running the app who is in range can receive this announcement. Turn on incognito mode (part of the bonus pack, free for promo and VIP members) if you do not want to appear in other people's lists.
The signature makes impersonation impossible: without your device key nobody can publish an announcement in your name.
4. Location
The app never publishes exact coordinates. Your position is reduced to a geohash — a coarse cell that says roughly where you are, not at what address. Distances shown in the app are computed from those cells.
Location can be switched off in the system settings; the app keeps working and simply cannot sort people by distance.
To turn a coarse cell into a city name (for example on a profile), the app asks the public service api.bigdatacloud.net. Only the centre of the coarse cell is sent, never your precise position, and never anything that identifies you.
5. Age (18+)
PSippr is strictly for adults. On first start you enter your date of birth. It is checked on the device and never sent anywhere; the app only remembers that the check passed.
6. Adult content
Photos and videos are analysed for adult content on your device. Nothing is uploaded for moderation. Locked (erotic) albums are shown to others only as a blurred silhouette until you grant access, and the blurring is done on the sender's side, so a recipient without access never receives the sharp data.
7. Third-party services
The app has no backend that stores user data, but networking and a few features reach other services. Those services can see your IP address and the request itself.
| Service | Used for | What it receives |
|---|---|---|
| Stripe | payments for optional paid features and donations | data you enter on the Stripe payment page; the app never sees your card |
| GitHub | checking for and downloading app updates | the request for the current release |
| psippr.org (run by the author, EU) | relay for end-to-end encrypted traffic between devices that cannot connect directly; "device identifier → network address" records; table of entry points; payment confirmation; promo/VIP certificates; referral codes | IP addresses and device identifiers, timing and volume of relayed traffic (never the content); relay address and current network addresses; discovery identifier + coarse area; payment confirmation id |
n0 relay servers (*.relay.n0.iroh-canary.iroh.link) — only when the other person runs an older app version | forwarding end-to-end encrypted traffic to that person | IP addresses and device identifiers of both sides, timing and volume; never the content |
Google STUN (stun.l.google.com) | negotiating direct video-call connections | a STUN request (your IP address) |
Google Public DNS (dns.google) | reading bootstrap records that help devices find each other | a DNS query |
| bigdatacloud.net | turning a coarse area into a place name | the centre of a coarse geohash cell |
| Websites you link to | previews of links posted in chats and in the public feed | a request for that page from your device |
| YouTube, Spotify, SoundCloud, OpenStreetMap, Google Maps, Bolt | opening music, video, map and ride links you tap | the link you opened |
| Google Sign-In (optional, Android) | prefilling name and photo when creating a profile | only what you approve in Google's own dialog |
| Cryptolut / web3 domain check (optional) | the "verified user" badge | the domain you are proving |
There is no analytics, no advertising and no tracking of any kind in the app or on this website.
8. Payments
Paid features and donations are handled by Stripe payment pages that open in your browser. Card details are entered on Stripe's page, not in the app. The app only learns whether a feature has been unlocked. Stripe's own privacy policy applies to that payment.
Promo codes are verified through public DNS records; the code is sent in a hashed form, so the record does not reveal the code itself.
9. Permissions the app asks for
- Camera and microphone — photos, videos and calls.
- Location — sorting people and places by distance (coarse geohash only).
- Contacts — only when you explicitly save someone's phone number from a chat into your address book. The app writes into its own account in your address book and does not read, upload or analyse your existing contacts.
- Notifications — messages, calls and other alerts.
- Storage / media — picking photos and videos you want to send.
Every permission can be refused; the app keeps working with the corresponding feature disabled.
10. Security
- Messages travel end to end encrypted directly between devices.
- Announcements and profiles are cryptographically signed.
- The app can be locked with your fingerprint or face.
- Screenshots inside the app are blocked on Android.
- Backup and restore produce a single zip file that only you hold; if you store it in a cloud, that cloud's rules apply to it.
11. Keeping and deleting data
Your data stays until you delete it. In the app you can delete individual photos, albums, messages or your whole profile; deleting the app removes everything it stored, including the address-book account it created.
One honest limitation of a peer-to-peer app: what other people have already received is on their devices, exactly like a message sent through any other app. Deleting your profile stops it from spreading further, but the author has no way to reach into someone else's device and delete a copy from it.
12. Your rights
Because no personal data is processed on any server of the author, there is no central record to export, correct or delete. Data you hold is under your direct control in the app. If you still want to ask anything about processing, write to mimoccc@gmail.com.
13. Children
The app is for adults only (18+). It must not be installed or used by minors.
14. This website
This site is static. It sets no cookies, runs no analytics and embeds nothing from third parties. The hosting server keeps standard access logs (IP address, time, requested address) for operating and securing the server.
15. Changes
Any future change to this policy will be published on this page together with a new effective date.