Privacy policy

Effective 11 September 2026. Applies to the Yapmesh app for Android in both editions, the laptop browser client, and this website. Replaces the policy of 8 September 2026; the changes are listed at the end.

The short version

Yapmesh has no server, no account, no phone number, no analytics, no crash reporting and no advertising. We collect nothing, because there is no "we" that your phone talks to. Everything Yapmesh knows lives on your phone, encrypted at rest, and is yours to delete with the app. The only way anything reaches us is if you email it.

Three optional features reach out over the internet when you switch them on, and each one is off until you do: internet reach (public relays other people run), link previews (your phone fetches a linked page), and a spool (a mailbox relay you typed in). What each of those can see is set out below, plainly, because "no server" is only true of us.

Who is responsible

Yapmesh is an independent project made by one developer, Zafar Ali Khan. For data-protection law he is the person responsible for this app and this website. Questions and requests go to [email protected]. Under laws such as the GDPR, the UK GDPR, the CCPA and Pakistan's electronic-crimes and data-protection rules, Yapmesh processes no personal data of its users: the app is software you run, and it sends nothing to us. The one exception is what you write to us yourself, covered under "What reaches us".

What this covers

  • The Yapmesh app for Android, Google Play edition. Installed from Google Play. It does not read SMS and does not install or hand out its own APK, because Play forbids both; everything else is identical.
  • The Yapmesh app for Android, yapmesh.com edition. The APK from this site, from GitHub, or from another phone. It can read Yapmesh texts that arrive by SMS and can hand its installer to the phone next to it.
  • The laptop browser client, served by a phone on your own Wi-Fi or hotspot.
  • This website, yapmesh.com.

What the app stores on your phone

Everything below is kept in the app's private storage and encrypted at rest with a key that lives in the phone's hardware keystore, so a copy of the files without the phone is unreadable. Uninstalling removes all of it.

  • Your identity: an Ed25519 signing key and an X25519 encryption key, generated on the phone and never sent anywhere; a small set of one-time prekeys that let a contact's first message to you be forward-secret; and the ratchet sessions with your contacts.
  • Contacts: the signed contact codes you scanned, tapped, pasted or were introduced to, the names you gave them, whether you verified their safety number, presence grants you gave or received, and, if you typed them, a phone number for the SMS rung, an internet address for a direct internet link, and a per-contact "internet: never" mark.
  • Messages, voice notes, call signalling and files you sent and received, with their delivery ticks, reactions, mentions and retractions; group keys, rosters, fence descriptions and retention settings for your groups; which chats you archived, hid or marked unread.
  • Cargo for other people: sealed frames you are carrying for someone you have not met yet (up to 256 frames or 512 KB). You cannot read them. They are dropped when delivered or expired.
  • Safety records: the people you blocked, your community-block votes, and the reports you wrote, each with the reported message, the reported person's public key, and when and where. They stay until you delete them.
  • Internet reach settings: whether it is on, the relay and broker hosts (the defaults or yours), your push endpoint if you installed a distributor, and the last time each contact was reachable that way.
  • Settings and small caches: theme, app-lock delay, media auto-download choices, link-preview switch, abuse-filter switch, LoRa board pairing, the seen-cache that stops a frame being handled twice, and the install counter (how many phones this phone gave the app to, a number only). Nothing that identifies you.

What leaves your phone, and who can see it

  • To the phones around you, in the clear: a hello beacon carrying a display name (empty while you hide), which rungs are up, the app version, the battery level, the names of your direct neighbours, and the highest presence tier you answer at. This is how the mesh forms. Hide, and your name is left out.
  • Presence tokens: only if you granted presence to a contact: a 16-byte token that changes every 15 minutes and is meaningless without the secret you gave them.
  • Direct messages, voice notes, private files, calls, and delivery and read receipts: sealed to one recipient with the Signal protocol's building blocks. Relays and carriers see a signed header (your public key, the recipient's public key, a hop count, a size, an expiry) and ciphertext. Receipts are sealed too, so a relay cannot tell a "read" from a "delivered".
  • Group messages and files: encrypted with the group's current key before they are sent or chunked; a private group is announced by its id only, and a member who leaves or is removed never gets the next key.
  • Nearby room messages and drop-zone files: signed, not encrypted. Everyone in radio range is the audience, by design. Files you put in the drop zone spread to every phone in range automatically.
  • SOS: signed, not encrypted, so every phone can show it; it carries your location only if you switch that on, and your battery level.
  • A contact card you share: a contact's signed card can be forwarded to a third person as an introduction; it carries what the card carries (public keys and a display name), never messages.
  • A "delete for everyone": a signed request naming the message id, which phones that obey the protocol honour. It proves you sent the original.
  • By SMS or another app: when you hand-carry a message, your messaging app or the app you shared through sees that you sent a piece of text, and your carrier sees an SMS. The text is a sealed frame.
  • Over a LoRa board: if you paired a Meshtastic board, frames go out on its radio channel. On Meshtastic's default channel, which every board can read, Nearby-room messages are public to any board in range; sealed messages stay sealed but their headers are visible to every board that forwards them.
  • Over the internet, only if you switch internet reach on: a sealed, signed beacon posted to public relays under a tag derived from keys you and each contact already share. The tag changes every hour, the relay key is derived fresh each day, and the relay cannot tell who is talking to whom. When two phones then connect directly (WebRTC), each learns the other's IP address, as in any call. What the relays and STUN servers see is in the table below.
  • To a spool, only if you typed one in: sealed envelopes for a contact, filed under a hashed mailbox id.
  • A contact link (yapmesh.com/add followed by a #fragment) carries your contact code after the # sign. Browsers do not send the fragment to the website, so this site never receives it; the app on the other phone reads it from the link.
  • To a linked website, only if you switch link previews on: your phone requests the page to draw a title and a picture.

Nothing goes to Yapmesh, ever. There is no server to receive it.

Every third party the app can touch

Every row here is something on your phone or something you switched on. None of them is run by Yapmesh, none of them is paid by Yapmesh, and none of them can read a message.

WhoWhenWhat they can seeHow to stop it
Phones around you running YapmeshAlways, while the app is openYour hello beacon in the clear; sealed frames and signed public frames as described above.Close the app, or hide your name from the Mesh tab.
Google Play Services (Nearby Connections)Bluetooth and Wi-Fi Direct rungs, on phones that have Play ServicesThe radio links themselves are made by a Google library on your phone. Yapmesh hands it only sealed or signed frames. Google's own privacy policy governs what Play Services records about itself; Yapmesh cannot see or change that.Refuse the Bluetooth and Nearby Wi-Fi permissions; the LAN, Wi-Fi Aware, BLE, hand-carry and SMS rungs do not use Play Services.
Public Nostr relays (by default relay.damus.io, nos.lol, relay.primal.net) and public MQTT brokers (test.mosquitto.org, broker.hivemq.com, broker.emqx.io)Only if you switch internet reach onYour phone's IP address, a random 16-byte tag that changes every hour, opaque encrypted bytes, and when. Never who you are, who you are talking to, or what is said. The relays are run by other people with no connection to Yapmesh; you can replace every one of them in the settings.Menu → Internet reach → off (the default). Mark any contact "internet: never".
STUN servers (by default Google's and Cloudflare's)Only during internet reach, when two phones try a direct connectionYour phone's public IP address and port, nothing else. That is what STUN is for.Same switch.
The contact you are connected to over the internetOnly during internet reach, when a direct connection succeedsYour phone's IP address, as with any direct call.Same switch, or "internet: never" for that contact.
A push distributor you installed (UnifiedPush, usually the ntfy app; its Play build rides on Google's push)Only if you installed one and switched internet reach onAn IP address and a random topic when a contact wakes your phone. Never who or what.Uninstall the distributor, or switch internet reach off.
A spool (mailbox relay) you typed inOnly if you typed a spool URL; none is set by default and Yapmesh runs noneA hashed mailbox id, envelope sizes, times and your IP address. No sender, message, file or group.Remove the URL from Menu → Internet spools.
A Meshtastic LoRa board and every other board on its channelOnly if you paired a boardOn the default public channel, Nearby-room messages are readable by any board in range, and the headers of sealed messages (sender and recipient keys, size) are visible to every board that forwards them.Menu → LoRa radio → unpair, or keep private messages off that rung with its switch.
The site behind a link in a messageOnly if you switch link previews onYour phone fetches the page itself to draw a title and a picture, so that site sees your IP address, as it would if you opened the link. The sender learns nothing.Media settings → Link previews (off by default).
Your mobile carrierOnly when you send a message by SMSThat you texted that number, when, and the sealed text.Do not use the SMS rung.
The app you share throughOnly when you hand-carry a message through another appThat you shared a piece of text or a file, and its contents, which are sealed.Do not use the share rung.
Google Play, GitHub, CloudflareWhen you download the app or visit this websiteOrdinary download and access logs held by those companies under their own policies. Yapmesh does not receive them.Hand-carry the APK from another phone; it verifies the signature itself.

What reaches us

The only data Yapmesh ever holds about a person is what that person emails to [email protected]: a support question, an exported abuse report, a security report, a legal request. We keep that mail for as long as it takes to deal with and for our own records afterwards, we do not add it to any list, sell it, or share it, with two exceptions: a report that describes harm to a child, or a threat to someone's life, is passed to the authorities able to act on it; and a lawful order may compel us to produce our own correspondence. Ask, and we will delete what you sent us unless a law requires us to keep it.

Every Android permission and why

Yapmesh's onboarding lets you switch each radio permission off before it is asked for; the permission is then never requested, and you can change your mind later from the Mesh tab. Nothing is asked for at install time, and nothing is asked for a feature you have not tapped.

PermissionWhat it is forIf you refuse
Bluetooth (connect, scan, advertise; Android 11 and older: Bluetooth and Bluetooth admin)The Bluetooth rung: Bluetooth LE links and classic Bluetooth links through Android's Nearby Connections, and the Bluetooth link to a Meshtastic LoRa board if you pair one. Scanning is declared "never for location".Refuse it and Yapmesh still runs over Wi-Fi, by hand-carry and by SMS.
Nearby Wi-Fi devices (Android 13 and newer)The Wi-Fi Direct rung through Nearby Connections, and the Wi-Fi Aware rung. Declared "never for location".Refuse it and those two rungs stay off.
Location, coarse and fine (foreground only; background location is never requested)Android 12 and older require it before an app may scan for Bluetooth or Wi-Fi devices; Yapmesh asks for it there only for that reason. On every version it is asked when you tap to attach your place to a message or an SOS, and when you create or join a geo fence (to compare your position with the circle) or a Wi-Fi fence (Android hands out network identifiers only with this permission). A fence produces a signed inside/outside record, nothing else. Your position leaves the phone only inside a message you chose to attach it to.Refuse it on Android 13+ and every rung still works; geo and Wi-Fi fences read "unknown", which counts as outside; the attach-location button is off.
CameraScanning a contact's QR code, an invite, a safety number, or the animated code of a hand-carried message.Refuse it and you can still paste codes or receive them by tap or sound.
MicrophoneRecording voice notes, listening for the sound rung, and the microphone of a call.Refuse it and those three features are off.
Receive SMS (yapmesh.com edition only; not in the Google Play edition)When a Yapmesh message arrives as a text (a sealed code split into pieces), Yapmesh reads that text so it lands in the chat instead of your inbox. It looks only at texts that carry Yapmesh's own code prefixes and ignores every other SMS. Yapmesh never has the Send SMS permission: sending opens your own messaging app and you press Send on each piece.Refuse it and Yapmesh can still send by SMS; received pieces stay in your SMS app and can be pasted in. The Play edition does not ask at all.
NotificationsMessages, SOS alerts, and the permanent notification of the foreground service.Refuse it and the mesh still runs while the app is open; you will not be told about new messages.
Foreground service (data sync) and wake lockKeeps the radios and the mesh running while Yapmesh is open or in the background, under a visible notification. Nothing runs after you close the app.Android grants these without a prompt.
Ignore battery optimisationsAsked once, from Menu → Battery & background, for internet reach: without the exemption Android's Doze closes the relay connection minutes after the screen goes off and contacts cannot reach you. It is never needed for the radio rungs.Refuse it and internet reach works while the screen is on and for a few minutes after; everything else is unchanged.
Internet and Wi-Fi stateThe router rung on your own network, the laptop gateway, hosting a hotspot, an internet address you typed for a contact, and, only if you switch it on, internet reach through public relays, a spool, and link previews. There is no Yapmesh server: this permission never contacts one.Android grants these without a prompt; the internet features each have their own switch, off by default.
NFCExchanging contact codes by tapping phones; Yapmesh presents your signed contact code as a tag.Only on phones with NFC.
Install packages (yapmesh.com edition only; not in the Google Play edition)Installing a newer build that arrived over the mesh, after Yapmesh has checked it was signed by the same key.You are asked at install time. The Play edition never offers, serves or installs an APK; it links to the store.
BiometricThe app lock: your phone's own fingerprint, face or screen lock in front of Yapmesh. Yapmesh stores no PIN.Only if you switch the lock on.
Modify audio settingsRouting a call to the speaker, and playing the sound rung's tones at a set volume.Android grants this without a prompt.

Not asked for, ever: contacts, call log, send SMS, background location, all-files access, the advertising ID, accessibility services, notification access to other apps, or the list of installed apps.

How long things are kept

  • Messages and files stay until you delete them or a group's retention drops them. A group can be set to forget messages after a number of hours, and to delete everything when you leave.
  • Cargo for other people expires with the frame's own expiry, or when delivered, or when the store is full and older cargo is evicted.
  • Seen-cache and presence tokens are short-lived working memory, hours at most.
  • Blocks, votes and reports stay until you remove them.
  • Relays that carry internet beacons do not store them: Yapmesh posts ephemeral events that relays forward and drop. A spool keeps an envelope until the recipient collects it or its expiry passes.
  • Everything goes with Menu → Safety → Delete everything on this phone, or with uninstalling the app. A message already delivered to another phone is on that phone and is theirs, as with any messenger.

Security

Direct messages use X25519 and Ed25519 with a Signal-style Double Ratchet and X3DH prekeys, so the first message to a contact is forward-secret too. Group messages use per-epoch group keys with sender keys. Every frame is signed, every file chunk is verified against a Merkle root, everything at rest is encrypted under a keystore-wrapped key, and you can compare a 60-digit safety number with a contact to be sure nobody swapped a key. What is and is not protected, in plain words, is on the security page. No independent audit has been carried out yet, and we say so there.

Children

Yapmesh is for people aged 18 and over and is listed that way on Google Play. It has no account and no age check, so it cannot know how old a user is. It has no directory, no search for people and no suggestions: a contact can only be added by someone in the same room or by a code they already have, which is the strongest protection an app can give a child against strangers, but it is not supervision. A classroom or family deployment is the school's or the parents' responsibility under their own rules. Our child safety standards say what is forbidden and what we do with a report.

Your rights

Wherever you live, you have the right to know what a company holds about you, to correct it, to have it deleted, to take a copy of it, to object to its use, and to complain to a regulator. Yapmesh holds nothing about you unless you emailed us, so for the app these rights are met by design: the copy of your data is on your phone, and deleting it is a tap. For anything you emailed us, write to [email protected] and we will answer within 30 days. If you are in the European Union or the United Kingdom you may complain to your national data-protection authority; in Pakistan, to the authority designated under the data-protection law in force. We would rather hear from you first.

International transfers

Yapmesh transfers nothing anywhere. If you switch internet reach on, the public relays and STUN servers you use are wherever their operators put them, and the same is true of a spool or a push distributor you chose. Your phone sends them only what the table above says.

The laptop browser client

The browser client is served by a phone on your own Wi-Fi or hotspot and runs entirely in the browser. It keeps its identity in the browser's storage and sends nothing anywhere except to that phone. It is not hosted on this website.

This website

yapmesh.com is static files. It sets no cookies, loads no third-party scripts or fonts, has no analytics and no forms. The hosting provider (Cloudflare Pages) keeps ordinary access logs (IP address, time, page) for its own operation under its own policy; we do not use them. The site's service worker stores a copy of the pages in your browser so it opens offline; clear site data to remove it. A light/dark choice is kept in your browser's local storage only. The contact-link page reads a code from the part of the address after the # sign, which never leaves your browser.

Requests from governments and courts

We have nothing to hand over, and we say so in advance: see Government and legal requests, which also carries a transparency report we will keep up to date.

Changes to this policy

This page is versioned in the public repository. A change is a new commit with a date; the effective date above moves with it. Material changes are also named in the app's release notes.

  • 11 September 2026: added internet reach through public relays, STUN, push wake and direct connections; spools; the LoRa rung; link previews; the abuse filter; file safety; encryption at rest; safety numbers and prekeys; the two editions; the third-party table; "What reaches us"; retention; rights; transfers; the government-requests page.
  • 8 September 2026: first published policy.

Contact

Zafar Ali Khan, Yapmesh, Pakistan. [email protected].