Skip to content
PsstPsst
Back to home

PsstPsst · Legal

Privacy Policy

How PsstPsst handles your information, what other services can see, and the choices you have.

Last updated: September 20, 2026

On this page

  1. About this policy
  2. Identity and data storage
  3. Messages and relays
  4. Public profiles and usernames
  5. Attachments and external content
  6. Nearby messaging
  7. Wallets, signers, and updates
  8. Device permissions
  9. Website and support
  10. Retention and deletion
  11. Your choices and rights
  12. Children
  13. Changes and contact

1. About this policy

PsstPsst is a free, open-source messaging project built on Nostr and provided by PsstPsst Labs LLC. In this policy, “we,” “us,” and “our” refer to PsstPsst Labs LLC, which provides PsstPsst and operates this website, the blossom.jumble.social media service, and the psstpsst.chat username service. You can contact us at hi@psstpsst.chat.

This policy covers the PsstPsst applications, this website, and those hosted services. We do not operate the app's default Nostr relays. Independent relays, other media hosts, wallet providers, remote signers, and app stores handle information under their own policies.

You can create a cryptographic identity without a phone number or email address. Private message content is encrypted before it leaves your device. This does not make all activity anonymous: public information, network connections, and information shared with recipients have different privacy properties, described below.

2. Identity and data storage

Your public key identifies your Nostr account. When you generate or import a local identity, the app stores private keys using the platform's secure-storage facilities. If you use a remote signer, that signer holds your identity key and handles the operations you authorize.

The app keeps local copies of messages, contacts, drafts, settings, cached profiles, and transaction records in its database. Nostr messages, contact lists, and some settings are also published to and stored on Nostr relays according to your relay configuration and the routing described below. Local storage is therefore only one part of how the app stores your information.

Downloaded attachments may be stored as decrypted files on your device. End-to-end encryption protects private message content sent to and stored on relays; it does not mean every local database, exported file, or device backup is encrypted by PsstPsst.

We do not have a central password-reset or private-key recovery service. Protect your device, keys, and backups. Your operating system, backup provider, or people with access to your unlocked device may have access to locally stored information.

3. Messages and relays

Private Nostr messages use end-to-end encryption and gift wrapping. Relays receive encrypted events to store and deliver, rather than readable message content or the keys needed to decrypt it. Recipients can read, save, copy, forward, or otherwise disclose what you send.

The app connects to configured relays, discovery relays, and relays needed to reach your contacts. A relay can see your IP address, connection times, requests, event sizes, and exposed routing information, including the recipient public key on a gift-wrapped event. If relay authentication is required, it may also receive your authenticating public key and signature. Encryption does not conceal all metadata.

Your contact list and some account settings are also stored on relays and synchronized with the app. Private contact, mute, and block lists are encrypted to your own account before publication. Their contents are not readable by the relay, although the event's public key, type, and other exposed metadata remain visible.

Some synchronized settings are public Nostr events rather than encrypted private lists, including relay lists, media-server preferences, and custom-emoji selections. Public routing and encryption-key announcements are also published so other clients can reach you. These events can be retrieved and copied by others.

Notifications are generated on your device from messages the app receives, including through background relay connections where supported. PsstPsst does not use a central remote-push service for message delivery. Notification previews may expose content on your lock screen according to your settings.

4. Public profiles and usernames

Profile details you publish, such as your display name, biography, picture, website, Nostr address, and Lightning address, are public Nostr data associated with your public key. Public relay lists and other published configuration may also be visible. Other people and services can retrieve, index, and copy public events.

Claiming an optional name@psstpsst.chat username sends the requested name, your public key, and a signed authorization request to the naming service. The name-to-key mapping is public and can be looked up in either direction. It is a Nostr identifier, not an email inbox, and does not verify your real-world identity.

Searching for a username or verifying a Nostr address contacts the relevant domain. That provider receives the lookup and ordinary connection information. Registering a username is not required to use key-based messaging.

5. Attachments and external content

Private message attachments are encrypted on your device before upload to Blossom media servers. Their decryption information is sent inside the encrypted message. Media servers can receive the encrypted file, its hash and size, your IP address, request times, and upload authorization containing the signing public key.

The app uses your configured media servers and may mirror files to other configured servers. We operate blossom.jumble.social, the default upload server, which is also tried as a fallback if your configured upload servers fail. Choosing another server does not disable that fallback. We store uploaded files and the metadata needed to host and retrieve them; private attachment contents remain encrypted.

Public profile images and custom emoji are uploaded without message encryption. Anyone with their URLs may retrieve them. Image metadata removal is best-effort; original-quality images, animations, and other files may retain embedded information such as location or author details.

Loading remote profile images, emoji, linked media, or other external content contacts the host serving it, which can observe your IP address and request details. Opening a link takes you to a service with its own privacy practices.

6. Nearby messaging

When Nearby is enabled, the app uses Bluetooth to discover and communicate with nearby devices. Discovery exposes a public display name and device-local proximity identity, separate from your Nostr account identity. Nearby observers can detect your presence, and a persistent proximity identity may allow repeated encounters to be linked.

Nearby conversations use encrypted device-to-device sessions. Nearby text messaging can work without an internet connection. Attachments may also be uploaded to and downloaded from Blossom servers when connectivity is available, using the proximity identity for upload authorization, with Bluetooth transfer supported between compatible peers. Nearby attachments should therefore not be treated as exclusively offline transfers.

Disabling Nearby stops discovery through that feature. It does not remove information already received by another device or uploaded to a media host.

7. Wallets, remote signers, and updates

  • Lightning wallets: if you connect a wallet through Nostr Wallet Connect, the app stores its connection secret in secure storage and communicates encrypted requests through the wallet's relay. Your wallet provider processes authorized balance, invoice, transaction, and payment information. Resolving a Lightning address also contacts its provider. PsstPsst does not hold your funds.
  • Remote signers: if you connect a Nostr signer, signing or cryptographic requests are sent to it through the selected relays. The signer can access the data needed for those operations. Choose a signer you trust and manage its permissions with that provider.
  • Desktop updates: packaged desktop versions check GitHub Releases for updates. GitHub and its download infrastructure receive normal network information, including your IP address and requested release files. Downloading and installing an update each require your confirmation.

App stores and operating systems may separately collect installation, purchase, or diagnostic information according to their policies and your settings.

8. Device permissions

Depending on your platform and the features you use, PsstPsst may request:

  • Camera and photos: to take or select images, scan QR codes, and save media.
  • Microphone: to record voice messages.
  • Files and media storage: to send, download, import, or export files and backups.
  • Bluetooth / nearby devices: to discover and message nearby peers. Older Android versions require location permission for Bluetooth scanning; PsstPsst does not use this to obtain GPS location.
  • Notifications and background operation: to receive messages and show local alerts while the app is not in the foreground, subject to operating-system limits.
  • Device authentication: to confirm payments. Biometric matching is handled by the operating system; PsstPsst receives the authentication result, not your fingerprint or face template.

You can manage permissions in system settings. Denying a permission may prevent the associated feature from working.

9. Website and support

This website stores your color-theme preference in your browser's local storage. You can clear it using your browser's site-data controls. The website and app do not include advertising trackers or behavioral analytics SDKs.

In our application logic, we use IP addresses only to enforce rate limits. We do not currently maintain a separate application request-log store. If we introduce one, we will retain its logs for no longer than one month and describe the information recorded and its purposes in this policy before logging begins.

We use Cloudflare for infrastructure. Cloudflare processes information such as IP addresses and traffic data to deliver and protect its services, and may retain network and security data. Platform logging and retention depend on the services used, their configuration, and Cloudflare's applicable terms and Privacy Policy. Our one-month limit does not describe the retention of data Cloudflare holds for its own purposes.

If you contact us, we receive the contact details, message, and attachments you provide. We use that information to respond, investigate issues, and handle your requests. Do not send private keys, wallet connection secrets, or unnecessary private message content. Public issue trackers are visible to others.

Infrastructure and email providers may process information as necessary to host these services and deliver support correspondence. We may disclose information we hold when required by applicable law. Neither circumstance gives us the keys to decrypt private message attachments stored on our media service.

10. Retention and deletion

  • On your device: local information remains until removed through the app or your device's data controls. Use Settings → Account → Remove account to remove that account's local keys, wallet connection secrets, messages, drafts, contacts, managed archives, and attachment references. This does not delete messages, contact lists, or synchronized settings stored on relays. Shared profile caches and files referenced by another account may remain.
  • On relays: encrypted messages, private lists, and published settings remain subject to each relay operator's retention and deletion practices. Replacing a list or setting does not guarantee that every relay or other holder deletes older copies. Data that remains available may be retrieved again when you use the account on another device or re-add it with the necessary keys. Relay storage is not a guaranteed backup.
  • Backups and copies: exports you saved or shared outside the app, saved media, operating-system backups, and data on other devices must be deleted separately. Exporting chat history does not replace backing up your identity and messaging keys.
  • Our username service: we store the name-to-public-key registration to provide public lookups until the registration is removed. Removing an account locally or removing the identifier from your public profile does not release its psstpsst.chat username. To request removal, email hi@psstpsst.chat with your username and public key. We may ask you to prove control of that key without disclosing your private key.
  • Our media service: uploaded files and associated hosting metadata currently have no fixed expiry period and remain stored until removed. We may introduce periodic cleanup of older files in the future; no cleanup interval or file-age threshold has been set. We will publish the retention criteria here before scheduled cleanup begins. To request deletion from blossom.jumble.social, email hi@psstpsst.chat with the file URLs or hashes and the uploading public key, if available. We may need to verify ownership or another valid basis for the request. We can manually remove files and associated records under our control; deleting our copy does not delete copies held by recipients or other hosts.
  • Request logs and support: we do not currently maintain a separate application request-log store. Any future application request logs, and any platform request logs we export or otherwise retain under our control, will be kept for no more than one month. This limit does not apply to hosted files, username registrations, or data Cloudflare retains for its own purposes as described above. Support correspondence is kept only as long as needed to handle the request and any applicable legal obligations.
  • Independent relays, other media hosts, and recipients: their retention policies and technical capabilities determine how long their copies remain. Local deletion does not erase remote encrypted files or events, public profiles, or recipients' copies. We cannot guarantee deletion across the decentralized network.

Before removing an account, save any keys or data you wish to keep. Loss of the necessary keys can make your identity or encrypted history permanently inaccessible. Keep your own copies of important files: our media service does not guarantee permanent storage.

11. Your choices and rights

You can edit your public profile, choose relays and media servers, disable Nearby, adjust notification previews, disconnect wallets or signers, revoke permissions, export local chat history, and remove local accounts. Public data and remote copies are subject to the limits described above.

Depending on the law that applies to you, you may have rights to access, correct, delete, or obtain a copy of personal information we hold, restrict or object to processing, withdraw consent where processing relies on it, and complain to your local data-protection authority. Contact us to make a request. We may need proportionate verification of your identity or key ownership; we will never ask you to disclose your private key.

Decentralized providers and recipients may be located in different countries. Information you send to them may be processed outside your country under different laws. We can act on information and services within our control, but cannot retrieve private keys or decrypt messages on your behalf.

12. Children

PsstPsst is intended for a general audience aged 13 and older, subject to any higher minimum age required by applicable law. It is not directed to children under 13. Minors must obtain a parent or legal guardian's consent where required by applicable law, as described in our Terms of Service.

We do not knowingly collect personal information from children under 13 through our hosted services. If you believe a child below the permitted age has provided us with personal information, contact hi@psstpsst.chat. We will investigate and delete information within our control where required by applicable law.

13. Changes and contact

We may update this policy as the app or our practices change. The revised policy will appear at this URL with an updated date. For material changes, we will provide additional notice where required and obtain consent when applicable law requires it.

For privacy questions, access or deletion requests, or concerns about our hosted services, contact PsstPsst Labs LLC at hi@psstpsst.chat. Include only the information needed to identify your request; never send private keys or wallet connection secrets.

PsstPsst
Privacy PolicyTerms of Servicehi@psstpsst.chatGitHubDonate
© 2026 PsstPsst Labs LLCFree and open source · MIT License