Diffuse privacy notice

Effective 2026-07-31 · Offline Protocol, Inc. · legal@offlineprotocol.com

Offline Protocol, Inc., a Delaware corporation, operates Diffuse. Diffuse is offline-first: public broadcasts are intentionally replicated, while connections-only posts remain connection-addressed.

Information Diffuse handles

Diffuse handles optional OfflineID email and account data; profile labels and public signing keys; posts, metadata-stripped photo attachments, source snapshots, signatures, hashes, evidence metadata, reports, optional coarse location, settings, delivery and retry state, and ordinary service-security and network metadata. Camera, photo, document, nearby-device, local-network, and location access occur only for the features the user chooses and the permissions the operating system grants. Original video attachment is disabled until a metadata-safe transcode path is available.

Public and private distribution

Public posts, public display names, author public keys, coarse place labels, signatures, source snapshots, and evidence metadata can be copied to nearby devices, configured Nostr relays, the hosted global archive, exports, and other users. Connections-only posts are excluded from public mesh deltas, default Nostr publication, and global upload, but recipients can still copy them.

How information is used

Information is used to authenticate accounts; sign, encrypt, route, synchronize, preserve, display, and verify posts; remove embedded metadata from selected photos; capture user-approved sources; obtain timestamp proofs; provide optional location relevance; enforce safety and anti-abuse rules; respond to reports and requests; secure the service; and provide privacy-minimized crash diagnostics when configured. Diffuse application request logs omit raw IP addresses and ports. Abuse-report deduplication stores a daily HMAC pseudonym derived from the request IP instead of the raw IP or caller-supplied reporter identifier; Railway and connectivity providers can still receive ordinary connection metadata.

Legal bases

Where the GDPR or UK GDPR applies, processing may be necessary to perform the requested service or contract, based on consent for optional permissions or diagnostics, necessary for legitimate interests such as service security and public-record integrity after considering affected rights, or required for legal obligations and legal claims. User content may reveal sensitive information, and users should not publish another person’s sensitive data without a lawful basis.

Recipients and services

OfflineID handles email one-time-code authentication. Offline Protocol Mesh SDK handles compatible local and Nostr transport. Railway-hosted infrastructure stores the operator global feed and evidence service. Configured Nostr relays, nearby nodes, OpenTimestamps calendars, chosen safety publishers, Sentry, linked source sites, Apple, Google, and connectivity providers receive the data and ordinary network metadata needed for their roles. Independent nodes, relays, publishers, websites, and users are not controlled by Offline Protocol.

Diagnostics

Diffuse includes no advertising SDK or product analytics and does not use content to train AI models. Mobile diagnostics default to off; when Sentry is configured and the user opts in, it receives privacy-minimized crash events. Diffuse disables screenshots, replay, view hierarchy, release-health sessions, performance tracing, post text, source URLs, location, account or mesh identifiers, and request bodies; Sentry’s network edge may still receive ordinary connection metadata.

Storage and security

Local posts and state use SQLCipher. Detached blobs use authenticated AES-256-GCM encryption, with account-scoped keys protected by Keychain or Keystore. Android application backup is disabled. Emergency local wipe crypto-erases Diffuse-managed local data only; Mesh SDK 0.17.0 exposes no deletion API for its platform-secured device signing key, so that key is not claimed erased. Public records are not confidential merely because the local database is encrypted, and no system is completely secure.

Retention

Ordinary abuse reports are pruned after 90 days and idempotency records after 24 hours by default. Public signed posts and pinned evidence are retained for the requested archive and integrity history, subject to revocation, safety restrictions, law, storage policy, and rights requests. Restricted integrity copies and high-severity review records may remain while necessary for security, legal obligations, or claims. Independent copies cannot be guaranteed erased.

Your choices and rights

Users can manage permissions, distribution scope, relays (including disabling Nostr by clearing the relay list), safety publishers, muted authors, relay policy, revocations, export, and emergency local wipe. Depending on location, users may have access, correction, deletion, restriction, portability, objection, appeal, and complaint rights. Diffuse does not sell personal information or share it for cross-context behavioral advertising.

Automated safety processing

Diffuse automatically applies signed hash and domain lists plus local spam, similarity, rate, trust, and storage rules. These controls can quarantine, hide, reject, or limit content but do not determine legal guilt or truth. Users can inspect and choose publishers and seek human review.

Children and international processing

Diffuse is not directed to children under 13 and does not knowingly collect their personal information. Offline Protocol is a United States company, and independent services and network participants operate globally, so information can be processed outside the user’s country.

Contact

Privacy, access, correction, safety, and deletion requests can be sent to legal@offlineprotocol.com. Include only the minimum information needed to verify and locate the record; never send a private key, one-time code, precise location, or illegal media.

Changes

The effective date identifies the current notice. Material changes will be presented in the app or through another reasonable notice, and renewed consent will be requested when applicable law requires it.