Privacy
Privacy policy
Peers collects no personal data. This page sets out what OPUS holds, which is very little, and where anything at all is handled on your behalf.
What OPUS collects
Nothing. There are no accounts, no phone numbers, no email addresses, no analytics, no crash reports, and no advertising identifiers. OPUS holds no profile of you and nothing that identifies you.
This website has no cookies, no tracking scripts and no third-party requests of any kind. Visiting it tells OPUS nothing about you.
Your messages
Messages, files and call media are end-to-end encrypted on your device before they leave it. The relay and the mailbox handle sealed data only and cannot open it. OPUS holds no key that could.
- The relay passes sealed packets between devices. It sees a sealed packet, a random-looking chat number and the time.
- The mailbox holds sealed messages for a device that is offline. It retains them for up to 24 hours and then deletes them. It cannot read them.
- TURN servers forward encrypted call media when a direct connection between devices is blocked. They cannot listen to what they forward.
These are provided by the ird p2p network as sealed-box transport.
Waking a sleeping phone
A locked iPhone can only be woken by Apple. A separate program run by OPUS, which ordinary users never install, asks Apple to wake a phone on your behalf. It sees a device token, the time of the request, and whether it is a call or a message. It does not see who asked, which chat is involved, or what was said, and it stores none of it.
Apple’s push service sees what it sees for any app’s notifications: the device token and an encrypted payload. Apple’s handling of that is covered by Apple’s own privacy policy.
You can run your own relay and your own doorbell instead of the ones OPUS runs. See the doorbell page.
Optional GIF search
GIF search uses Tenor and is off by default. If you turn it on, your search terms go to Tenor, and what Tenor does with them is governed by Tenor’s privacy policy, not ours. Leave it off and nothing is sent.
Permissions the app asks for
- Local network, to find and connect to nearby devices directly.
- Camera and microphone, for calls, photos and voice notes.
- Face ID, Touch ID or your passcode, to unlock the app if you switch that on.
- Notifications, to tell you about messages and calls.
None of this data leaves your device except as part of a message or a call you chose to send.
Where your data lives
On your devices. Your profile, contacts, conversations, messages and attachments are stored encrypted on your iPhone and Mac, under a key held in the system Keychain. There is no copy anywhere else, so there is nothing for OPUS to export, hand over or lose. If you delete the app, that data goes with it.
Children
Peers is not directed at children under 13, and since no data is collected, none is collected from them either.
Changes
If this policy changes, the new version will be posted here with a new date at the top.
Contact
Questions about privacy go in the issue tracker on GitHub.