App name: ZZZ GhostChat
Platform: iOS / iPadOS
This Privacy Policy explains what information "ZZZ GhostChat" (the "App") handles and how it is used. Please read it before using the App.
1. Our Approach
For its chat function, the App is a serverless, peer-to-peer (P2P) mesh chat app in which nearby devices connect directly to one another over Bluetooth Low Energy (BLE). No account registration or sign-in is required.
The content you handle in the App (your display name, avatar, device identity keys, messages, contacts, and groups) is stored only on your own device. There is no server operated by us, and this content is never sent to or collected by the developer or any third party.
However, to support the App, it displays advertising through a third-party advertising network. Fetching and showing ads uses the internet, and information necessary for ad delivery (such as IP address and device/OS information) is sent to that advertising provider. The App does NOT display the App Tracking Transparency (ATT) dialog and does NOT request or use the iOS Advertising Identifier (IDFA); only non-personalized advertising is served (see Section 6). The App contains no analytics beyond advertising and no in-app purchases. Chat communication between users happens only over Bluetooth.
2. Information Handled On Your Device
The App creates, stores, and uses the following information only on your device.
2.1 Profile (display name and avatar)
- The display name you enter and the avatar (emoji) you choose during first-run setup and in Settings.
- Shown to nearby people and to your message recipients so they can recognize you.
- Stored on your device and also sent over Bluetooth to the devices you communicate with so it can be displayed there.
- We do not ask for your real name, phone number, or email address. We recommend using a nickname of your choice as the display name.
2.2 Device Identity & Encryption Keys (public/private key)
- On first launch, the App generates an Ed25519 key pair (for signing / authentication) and an X25519 key pair (for message encryption) locally on your device.
- The Ed25519 keys sign messages (to verify authenticity and detect tampering) and derive an ID that identifies your device.
- The X25519 keys are used for end-to-end encryption (key agreement). For forward secrecy, this encryption key rotates over time and old keys are purged from your device.
- Private keys are stored only on your device and are never transmitted. Only the public keys are shared with the people you communicate with, so they can verify signatures and encrypt to you.
2.3 Messages, Contacts, and Groups
- Messages you send and receive, the people you have paired with (contacts), and the groups you create or join are stored in a local database on your device.
- This data is used to display conversation history and to reconnect, and is never stored on any off-device server.
3. How Information Is Used
The information above is used solely for the following purposes.
- To discover nearby devices and pair (exchange "business cards") and connect with them.
- To send, receive, and display one-to-one and group messages.
- To sign and verify messages (to confirm the authenticity of the sender).
- To relay messages across the mesh (see below) so they can reach more distant recipients.
- To store and display conversation history, contacts, and groups on your device.
4. Where Information Is Stored
All information the App creates or stores is kept only on your device.
- ✅ Stored only in the App's private storage on your device
- ❌ Never sent to a server operated by the App's developer (no such server exists)
- ❌ No cloud backup
- ❌ No mechanism that lets the developer access it
Note: the above describes your chat data (messages, contacts, profile, keys). For the information a third-party advertising provider handles in connection with showing ads, see Section 6.
5. About Bluetooth Communication and Mesh Relay
The defining feature of the App is that nearby devices communicate directly over Bluetooth without any server. Because of how this works, please understand the following before using the App.
- Messages you send travel over Bluetooth radio to nearby devices.
- To reach more distant recipients, messages may be relayed through other participants' devices (a mesh network). A relaying device forwards the message but, because the body is end-to-end encrypted, cannot read its content.
- Each message is signed with the sender's private key, and its body is end-to-end encrypted so only the intended recipient can decrypt it (see Section 9).
- If the recipient is not present, a message may be temporarily held on a device and delivered later when the recipient reconnects (store-and-forward). What is held is also the encrypted data.
Important: Although message bodies are end-to-end encrypted, the App is a lightweight tool for casual messaging with people nearby. Messages are transmitted as Bluetooth radio signals to the surrounding area, and some metadata (such as who is communicating, and when) may be observable nearby. Please do not send sensitive personal information such as passwords, home addresses, or phone numbers, or anything you would not want others to see.
6. Advertising and Third-Party Services
To support the App, it displays banner and full-screen advertisements through a third-party advertising network. For ad delivery, display, fraud prevention, and measurement, that advertising provider may collect and process information such as:
- your IP address, device/OS information (model, OS, language, country, etc.), and ad interaction data (such as ad impressions and taps).
The App does not display the App Tracking Transparency (ATT) dialog. It therefore does not request or use the iOS Advertising Identifier (IDFA) and performs no cross-app tracking; only non-personalized advertising is served.
This data is acquired and managed independently by the advertising provider as part of its own services, under its own privacy policy. The App's developer cannot access it and does not store or use it. Your chat data — messages, contacts, profile, and keys — is never shared with the advertising provider or any third party.
The App also does not use any of the following services.
- ❌ Analytics
- ❌ Crash reporting
- ❌ In-app purchases or subscriptions
- ❌ User authentication / sign-in / accounts
- ❌ A backend server operated by the developer
The other party in any chat communication is simply a nearby device running the App, not an external company.
7. Permissions Required
The App requests the following permission. On iOS, a system confirmation dialog is shown the first time it is used.
| Permission | Purpose |
|---|---|
| Bluetooth | To discover and connect to nearby devices and send/receive messages directly (the iOS "Bluetooth" permission). |
| Notifications (badge) | To show the number of unread messages as an app-icon badge, the App requests the notification (badge) permission. It uses no banners or sounds and sends nothing anywhere. |
You can change these permissions at any time in iOS Settings → ZZZ GhostChat. The App does not request location, microphone, camera, contacts, photos, or tracking (App Tracking Transparency) permissions.
8. Deleting Your Data
You can delete data in the App at any time.
- You can delete an individual message by long-pressing it (deleting a message you sent also removes it on nearby devices).
- Deleting a contact also deletes the conversation history with that person.
- Leaving a group or disbanding a group deletes the corresponding data.
- Uninstalling the App permanently removes all data the App stored on your device (keys, profile, messages, contacts, and groups).
9. Security
The App attaches an Ed25519 digital signature to each message and control packet, and the receiver verifies the sender's authenticity and the integrity of the content (preventing impersonation and tampering). In addition, message bodies are end-to-end encrypted (X25519 key agreement + AES-GCM). Encryption keys rotate over time and old keys are purged, providing forward secrecy (past messages stay hard to decrypt even if a key later leaks). Encryption and decryption happen only on-device; plaintext never leaves your device.
Please also understand the limits: in a brief window before the recipient's encryption key is known, a small number of messages may be sent without encryption (still signed). Metadata — such as who was nearby and when — is not concealed. Forward secrecy is window-based, so the most recent messages can be affected by a compromise of the current key. As noted in Section 5, please refrain from sending sensitive personal information.
10. Children's Privacy
The App has no developer-operated server that collects or stores personal information. The App is not directed to children under the age of 13 and does not knowingly collect personal information from them. The App displays advertising through a third-party advertising network but is not designed for children. If children use the App, we recommend they do so under the guidance of a parent or guardian.
11. Changes to This Policy
This Policy may be changed without prior notice. If a significant change is made, we will announce it together with an update to the App.
12. Contact
For inquiries regarding this Policy, please contact us through the App Store page where the App is distributed.