App name: ZZZ Lifeline Mesh
Platform: iOS
This Privacy Policy explains what information "ZZZ Lifeline Mesh" (the "App"), an offline communication app intended for use in emergencies such as disasters, handles and how it is used. Please read it before using the App.
1. Our Approach
The App is a serverless, peer-to-peer (P2P) mesh communication app in which nearby devices connect directly to one another over Bluetooth Low Energy (BLE). No account registration or sign-in is required, and it is designed to work where there is no internet connection (such as during a disaster).
The content you handle in the App (your display name, device identity keys, SOS / safety beacons, public board posts, messages, contacts, groups, and any location you choose to attach) is stored only on your own device. There is no server operated by us, and this content is never sent to or collected by the developer or any third party.
The App contains no advertising whatsoever. It has no analytics, no tracking, and no in-app purchases. Communication between devices happens only over Bluetooth; there is no communication with any external company or server.
2. Information Handled on Your Device
The App creates, stores, and uses the following information only on your device. It is never sent to an external server. (For how some of it is shared over Bluetooth with the people you communicate with or with nearby relaying devices as required by the features, see Sections 5 and 6.)
2.1 Profile (display name, avatar)
- The "display name" you enter and the "avatar (emoji)" you choose, at first launch and in Settings
- Shown so nearby people and the recipients of your SOS / safety, board, and messages can identify you
- Stored on your device and also sent over Bluetooth to the devices of the people you interact with
- We do not ask for your real name, phone number, or email address. We recommend a nickname, or a name useful for safety checks (e.g. a name your family will recognize)
2.2 Device Identity / Encryption Keys (public and private keys)
- At first launch, the App automatically generates, on your device, an Ed25519 key pair (for signing and authenticity) and an X25519 key pair (for message encryption)
- The Ed25519 key is used to sign messages, SOS / safety beacons, and board posts (to verify against impersonation and tampering) and to derive the ID that identifies your device
- The X25519 key is used for end-to-end encryption (key agreement) of 1:1 and group messages. For forward secrecy, this encryption key is rotated periodically and old keys are discarded from your device
- Private keys are stored only on your device and are never sent externally. Only the public keys are shared with the other party's device, during communication, for signature verification and encryption
- From Settings, you can view/restore a backup code of this device's identity (key), or generate a new identity. Because the backup code contains your private key, keep it safe and do not share it with others
2.3 SOS / Safety Beacons, Public Board, Messages, Contacts, Groups
- SOS / "I'm safe" beacons you send, posts to the public board, messages you send and receive, peers you have paired with (contacts), and groups you create or join are stored in a local database on your device
- This is used to display history and to support reconnection / re-delivery; it is never stored on a server outside your device
- By their nature, SOS / safety beacons and public board posts are features intended to reach nearby, unspecified devices using the App (i.e. they are public) (see Section 5)
3. How Information Is Used
The information above is used only for the following purposes.
- To discover nearby devices and pair (exchange "business cards") and connect with them
- To broadcast and receive SOS and "I'm safe" status during emergencies such as disasters
- To share notices on the public board (e.g. water distribution, shelter information)
- To send, receive, and display 1:1 and group messages
- To sign and verify messages, beacons, and posts (to confirm the sender's authenticity)
- To relay information across the mesh so it reaches more distant participants (see below)
- To store and display history, contacts, and groups on your device
4. Where Information Is Stored
All information the App creates and stores is kept only on your own device.
- ✅ Stored only in the App's private storage on your device
- ❌ Never sent to a server operated by us (no such server exists)
- ❌ No cloud backup
- ❌ No mechanism for the developer to access it
- ❌ No advertising, analytics, or tracking
5. About Bluetooth Communication and Mesh Relaying
The defining feature of the App is that nearby devices connect directly over Bluetooth and communicate without going through a server. Given this design, please understand the following.
- Information you send reaches nearby devices over Bluetooth radio
- To reach more distant recipients, information may be relayed through other participants' devices (a mesh network). Relaying devices also process the data in order to carry out the communication
- The body of 1:1 and group messages is end-to-end encrypted and can be decrypted only by the intended recipient; relaying devices cannot read the body (see Section 10)
- SOS / safety beacons and public board posts are sent unencrypted, readable by anyone, because their purpose is to reach everyone nearby (they are not suited for confidential content). They still carry the sender's signature
- In case the recipient is not present, information may be temporarily held on your device and delivered when they reconnect (store-and-forward)
- If you enable "fixed relay node" in Settings, that device keeps its screen on and actively helps relay nearby communication (optional)
Important: The App is intended to convey safety status and messages to nearby people during emergencies such as disasters. Communication is transmitted as Bluetooth radio to the surroundings, and some information (metadata) such as who communicated and when may be observable nearby. In particular, SOS / safety beacons, the public board, and location are by design "made public to everyone nearby." Please refrain from sending secret information such as passwords, or anything you would not want unspecified people to know.
6. Handling of Location (GPS)
When you send an SOS, an "I'm safe" status, or a public board post, the App can, optionally and at your choice, obtain your device's location (approximate latitude/longitude) and attach it to that transmission. This is a feature for telling those nearby "where I am asking for help" or "where I am."
- Location is obtained only when you choose to attach it at the time of that transmission; the App does not track you continuously (it uses only "When In Use" location, with no ongoing background location collection)
- An attached location is, as part of that SOS / safety / post, shared and relayed to nearby devices over Bluetooth (by the nature of the public board and SOS, recipients can view it on a map)
- Location is never sent to any server operated by us or to any third party (no server exists)
- If you do not want to attach location, you can choose not to include it when sending. You can also disable the App's location permission entirely in your device settings (in which case the attach-location feature is unavailable)
- A received party's location may be shown as a link that opens in a map app
7. Advertising and Third-Party Services
The App is designed with your privacy as the top priority. It uses none of the following.
- ❌ Advertising (no ads of any kind)
- ❌ Analytics
- ❌ Crash reporting
- ❌ Tracking identifiers (no tracking under App Tracking Transparency, either)
- ❌ In-app purchases or subscriptions
- ❌ User authentication / sign-in / accounts
- ❌ Any backend server operated by us
The parties you communicate with are the nearby devices running the App themselves, not any external company. Your information is never handed to advertisers or third parties.
8. Permissions Requested
The App requests the following permissions.
| Permission | Purpose |
|---|---|
| Bluetooth | To discover nearby devices, connect, and send/receive SOS / safety, board posts, and messages directly |
| Location (When In Use) | Used to optionally attach your location to SOS / safety / board posts (Section 6). The App does not perform continuous location tracking |
| Notifications | To alert you, on your device, to incoming SOS and unread messages. Nothing is sent externally |
You can change these permissions at any time from your device settings. The App does not request microphone, camera, contacts, or photos permissions. The App does not communicate with any external server, and your information is never sent to any company on the internet.
9. Deleting Data
You can delete the App's data at any time.
- Individual messages can be deleted by long-pressing the message
- Deleting a contact (a peer) also deletes the conversation history with them
- Leaving or disbanding a group deletes the corresponding data
- "Reset contacts and history" in Settings clears contacts, conversations, board, and similar data (your own identity / key is kept)
- Uninstalling the App completely deletes all data the App stored on your device (keys, profile, messages, contacts, groups, beacons, posts)
10. Security
The App attaches an Ed25519 digital signature to each message, SOS / safety beacon, board post, and control message, and the receiver verifies the sender's authenticity and the integrity of the content (preventing impersonation and tampering). In addition, the body of 1:1 and group messages is end-to-end encrypted (X25519 key agreement + AES-GCM). Keys are rotated periodically and old keys are discarded, providing forward secrecy (so that even if a key is later leaked, past messages are hard to decrypt). Encryption and decryption happen only on your device.
Please also understand the limits: SOS / safety beacons, the public board, and any attached location are not encrypted (anyone can read them), because they are meant to reach everyone nearby. A small number of 1:1 messages may be sent unencrypted in brief early moments before the recipient's encryption key has been obtained (they are still signed). Metadata such as who was nearby and when is not concealed. As noted in Section 5, please refrain from sending information that must be kept secret.
11. Children's Privacy
The App has no server on the developer side that collects or stores personal information, and contains no advertising. The App is not designed for a specific age group; if children use it, we recommend they do so under the guidance of a parent or guardian.
12. Changes to This Policy
This Policy may be changed without prior notice. If there are significant changes, we will notify you together with an App update.
13. Contact
For inquiries about this Policy, please contact us via the store page from which the App is distributed.