Scope and operator
This policy covers NyxPeer Android app, nyxpeer.com, invite and update APIs, NyxPeer relay nodes, push wake delivery, and TURN relay service. Developer and service operator: NyxPeer. “NyxPeer,” “we,” and “us” mean NyxPeer service operator.
NyxPeer currently uses device cryptographic identities, not phone-number, email, or conventional cloud accounts.
Data kept on your device
Nickname, profile image, contacts, contact keys, group state, messages, reactions, attachments, voice notes, call history, preferences, invite identity, and cryptographic keys remain on device. Chat history uses an encrypted SQLCipher database. Android Keystore protects key material used to unlock local storage.
Camera and microphone data are used only for features you invoke, including QR scanning, voice notes, voice calls, and video calls. NyxPeer does not upload an address book and does not request Android contacts permission.
Deleting app data or uninstalling removes NyxPeer local data, subject to Android device backups being disabled by app configuration. Data already received and stored by another peer remains under that peer’s control.
Data processed by relay nodes
Nodes transiently process source IP address, connection time, anonymous rendezvous route IDs, signal targets, encrypted payload size, ciphertext expiry, and network delivery status. This metadata is needed to authenticate routes, relay encrypted traffic, limit abuse, and operate calls.
When a peer is unavailable, end-to-end encrypted payloads may remain in volatile RAM for no more than five minutes. Delivery, expiry, or node restart removes them. Nodes do not receive plaintext messages, readable files, nicknames, contact lists, private keys, or seed phrases.
With background delivery enabled, node stores an FCM registration token mapped to an anonymous route. Voice or video may pass through TURN when direct WebRTC connection fails. TURN can observe IP addresses, timing, and encrypted traffic volume, but not DTLS-SRTP media content.
Website, invites, and updates
Invite and update API stores device public identity, invite balance, creation and last-seen times, one-way keyed hashes of registration or redemption IP addresses, nonce hashes, invite creation/redemption/download times, download counts, and short-lived update authorization tokens. Invite codes are stored as keyed hashes, not plaintext.
Invite pages use a necessary session cookie for CSRF protection and a session-bound download grant. NyxPeer does not use advertising, analytics, cross-site tracking, or marketing cookies.
Web hosting, reverse-proxy, and security infrastructure may process standard request metadata such as IP address, request path, timestamp, user agent, and security events. That infrastructure logging is separate from NyxPeer message content and may be retained under provider security policies.
Service providers and disclosure
Google Firebase Cloud Messaging supplies background wake delivery. NyxPeer sends an opaque kind=wake data event. It contains no message, sender, contact, route, group, call details, or ciphertext. Google still processes FCM registration tokens, Firebase installation identifiers, IP addresses, device/network metadata, delivery timing, and service data under Google terms.
Cloudflare and hosting, network, DNS, certificate, and security providers process limited infrastructure data needed to deliver and protect service. We do not sell or rent personal data. We do not share data for behavioral advertising.
We may preserve or disclose limited records when legally required, to protect users, or to investigate abuse. End-to-end encrypted content cannot be disclosed from server storage because NyxPeer does not possess plaintext or decryption keys.
Android permissions
Retention
- Queued ciphertext: maximum five minutes in node RAM.
- Live routes: connection lifetime.
- FCM registration token: until replaced, background push is disabled, route is unregistered, or service maintenance removes it.
- Replay-protection nonces: short validity window, then cleanup.
- Update tokens and download grants: expire automatically after configured short validity periods.
- Invite and device records: retained while invite/update service operates or until deletion is requested and legally permitted.
- Provider security logs: retained according to hosting, network, Google, and security provider policies.
- Local content: until you delete it, clear app data, or uninstall.
Your choices and deletion
You can disable notifications or background push, revoke camera/microphone permission, delete chats and contacts, use emergency erase, clear app storage, or uninstall. Disabling push removes NyxPeer route-to-token registration when device can reach node; Google may retain installation records under its deletion schedule.
To request deletion of invite/update records tied to your device identity, email [email protected]. Include device identity shown by app, never private keys or recovery material. Some fraud-prevention or legal records may need limited retention.
Use privacy tools
Privacy is a right. Protecting personal data is normal behavior, not evidence of wrongdoing. We encourage users to reduce exposed network metadata with trustworthy VPNs, Tor, I2P, privacy-respecting DNS, device encryption, and current operating-system security updates.
VPN: A reputable VPN can hide destination traffic from a local network or ISP and replace your public IP with the VPN exit IP. Choose a provider with minimal account data, a clear no-activity-logging policy, independent audits, modern protocols, and an effective kill switch. A VPN shifts trust from ISP to VPN provider. It does not create complete anonymity.
Tor: NyxPeer Tor routing sends tracker and invite/update API traffic through an Orbot SOCKS proxy at 127.0.0.1:9050. Tor mode disables calls because real-time media can expose peer IP addresses. It also unregisters Firebase background push because FCM traffic does not use NyxPeer’s Orbot route. Message delivery therefore requires app to be active or reconnect manually while Tor mode is enabled.
I2P: I2P is valuable for applications and services built inside I2P network. NyxPeer does not currently provide native I2P transport. Running I2P alone does not route NyxPeer traffic through I2P. Native support must be implemented and tested before we claim otherwise.
VPNs, Tor, and I2P protect different parts of network metadata. They do not protect an unlocked or compromised device, information you reveal yourself, screenshots, malicious recipients, or files exported outside NyxPeer. Combining VPN and Tor can reduce privacy when configured incorrectly. Use documented configurations and understand which traffic is covered.
NyxPeer does not block or treat users as suspicious merely for using VPNs, Tor, I2P, privacy-focused operating systems, or other lawful security tools. Abuse controls may still limit harmful traffic regardless of connection method.
Security and limits
NyxPeer uses signed application envelopes, encrypted payloads, TLS-protected network transport, encrypted local storage, Android Keystore, short-lived TURN credentials, bounded in-memory relay queues, and signed Android releases.
No system guarantees absolute security or anonymity. Network operators and service providers can observe traffic metadata. A compromised unlocked device, malicious recipient, screenshots, accessibility malware, or exported files can expose content outside protocol boundary.
Children and international processing
NyxPeer is not directed to children under 13. Do not use service if local law requires parental consent you do not have. Infrastructure providers may process data in United States and other countries where they operate.
Changes
Policy changes will appear at this URL with a new effective date. Material changes affecting app data handling will also be disclosed in app or release notes when practical.
Contact
Privacy questions or deletion requests: [email protected].