Nullchat

Privacy policy

Effective 5 October 2026 · applies to the Nullchat apps for iPhone, Android, web and Mac, this website, and the public push service

The short version

Who we are

Nullchat is free, open-source software (GNU AGPL-3.0) published by Codeways Pvt Ltd (“we”, “us”). The source code is public at github.com/rchat-app/rchat, so every statement on this page can be checked against the code.

Because Nullchat is designed so that we don’t receive your messages or contacts, there is very little personal data for us to handle. Where we do touch personal data (the push service and this website, both described below), Codeways Pvt Ltd is responsible for it.

What stays on your device

Everything that makes up your Nullchat identity and history is created and stored on your device:

What your contacts see

When you add someone or accept their request, the app sends them, end-to-end encrypted: your display name, avatar number, public key, the list of your devices’ public keys, and (if you use push notifications) a sealed push handle that lets their app wake yours. They see the messages and photos you send them, the read receipts you send (you can turn read receipts off, except in dark chats), and whether you took a screenshot in a dark chat or of a view-once photo. Anyone you share your contact link or QR code with learns your public key, name and avatar.

What Nostr relays see

Nullchat delivers messages through Nostr relays: independent servers run by third parties, which store encrypted envelopes until the recipient picks them up. By default the app uses relay.primal.net, auth.nostr1.com and relay.ditto.pub; you can change this in Settings → Relays, including to a relay you run yourself. These operators are not our service providers and have their own policies.

Every message, receipt and photo is sealed with the sender’s key, then wrapped in an outer envelope signed by a one-time key (NIP-44 and NIP-59). A relay therefore cannot read the content, the type of message, or who sent it from the stored data. A relay can see:

WhatDetails
Recipient keyThe public key of the device each envelope is addressed to. For your phone this is your Nullchat identity, so a relay knows which inbox a message is for.
TimingWhen each envelope arrives and when it is fetched. Stored timestamps are randomised up to two days into the past, but a live relay sees real arrival times.
SizeThe approximate size. Content is padded, but a photo is clearly larger than a text message.
IP addressThe IP address of every device that connects, both when sending and when receiving. A relay that watches connections can link a sender’s IP address to the recipients it writes to. Use a VPN or Tor if this matters to you.
Login keySome relays (for example auth.nostr1.com) only hand out an inbox to its owner, so your device proves its key when reading. When sending, the app uses a throwaway key instead.
Public listsTwo small events you publish openly, signed by your key: your list of preferred relays (Nostr kind 10050) and your list of device keys with optional device names such as “Chrome on MacBook” (kind 10410). Anyone can read these.

Envelopes carry an expiry of at most 7 days, and your app asks relays to delete each one as soon as the recipient confirms delivery. Well-behaved relays honour both, but relays are run by third parties and we can’t guarantee that every relay deletes on time or doesn’t keep copies.

The app also fetches each relay’s public information document (NIP-11) over HTTPS to check its limits, which shows the relay your IP address.

Push notifications (optional)

Without push, the app checks for new messages when the operating system lets it run in the background. If you turn on push in Settings → Notifications, the app uses a small, stateless push service that we operate (you can enter your own instead, or leave it empty to turn push off). It runs either on a server we manage or on Cloudflare Workers; the code is the same open-source code in either case. It works like this:

  1. Your device asks Apple (APNs) or Google (Firebase Cloud Messaging) for a push token, and sends that token to the push service once. The service seals the token with a key only the service holds and returns opaque “handles”. It doesn’t store the token or the handles.
  2. Your app gives one handle to each accepted contact, inside an encrypted message.
  3. When a contact sends you a message, their app sends your handle to the push service. The service unseals it in memory and asks Apple or Google to show a notification that only says “New message”.

What the push service sees: the push token (only while handling a request, never stored), the platform (iOS or Android), the IP address of the device registering or sending a wake-up, and the time. It never receives message content, names, public keys, chat identifiers or who is writing to whom by name. To stop abuse it keeps short-lived, in-memory rate-limit counters keyed by IP address and by a hash of the push token, which expire within about a minute. We keep no request or access logs for the push service. Our hosting provider (the data centre that runs our server, or Cloudflare when we use Workers) carries the network traffic and may see the same connection data.

Apple and Google deliver the notification and can see that your device received a “New message” notification and when. Handles expire after 30 days and are refreshed automatically; a blocked contact stops receiving new ones.

Abuse reports and emails to us

If you email us, including with Report… in the app, we receive your email address, what you write, and anything you choose to include. A report includes the reported person’s public key and display name, the reason you picked, your note, and any of their text messages you ticked. Dark-chat messages and photos are never included. The app only prepares the email in your mail app; nothing is sent until you send it.

We use this only to answer you and act on the report (for example, banning a key from services we operate, or passing illegal content to the relevant authorities or relay operators). We delete it once the matter is closed, and at the latest after 12 months, unless the law requires us to keep it longer. Your email provider and ours handle the message under their own policies.

This website and contact links

This website is a set of static pages hosted on Cloudflare Pages. It sets no cookies and loads no analytics, fonts or scripts from anyone else. Cloudflare, as host, processes standard request data (IP address, browser user agent, time) to serve and protect the site.

Shareable contact links look like …/c#npub1…. Everything after the # stays in your browser and is never sent to the web server, so the host can’t see whose contact card was opened.

What we don’t do

If you choose to share diagnostics with app developers in your iPhone or Android settings, Apple or Google may give us aggregated, anonymous crash and usage statistics through their developer consoles. We use these only to fix bugs.

Deleting your data

We hold no account or message data that we could delete on your behalf. If you think we hold something about you, write to us (see Contact) and we will check and reply.

Your rights

Depending on where you live (for example under the EU and UK GDPR or California law), you may have rights to access, correct, delete or object to processing of personal data about you, and to complain to your local data protection authority. The only personal data we process is the transient push and website request data described above, and emails you send us, processed on the basis of our legitimate interest in delivering the notifications you turned on, keeping the services safe and answering you. We don’t keep the push and website data, so in practice the only thing we could export or erase is your correspondence with us. We will still answer any request sent to the address below.

Our hosting providers may process this data outside your country. Where the law requires it, such transfers are covered by appropriate safeguards such as standard contractual clauses.

Children

Nullchat is not directed at children under 13, and we don’t knowingly process personal data of children under 13 (or under the minimum age set by your country). Because there are no accounts, we have no profile to delete. If you believe a child is using Nullchat, use Delete everything on their device, and contact us if you need help.

Changes to this policy

We will post any change here and update the date at the top. The history of this page is public in the source repository. If a change affects what leaves your device, we will also mention it in the app’s release notes.

Contact

Questions or requests about privacy:

Codeways Pvt Ltd
support@example.com

To report a security vulnerability, follow the security policy.