Legal · Document 01
Privacy Policy
Effective 2026-05-04 · Updated 2026-09-05
This Privacy Policy explains how H2H ("H2H," "we," "us") collects, uses, discloses, and protects information when you use the H2H Protocol mobile application and related services (the "Service").
H2H Protocol is a nearby discovery and communication service built around Bluetooth Low Energy ("BLE") discovery, short-lived nearby announcements, private 1-to-1 text and voice messages, and voice calling. It also includes Free Match, which matches you with nearby people on what you need, offer, or are interested in, and SOS, a community alert that lets people nearby know you need help. Video calling is not available in this version of the Service; we expect to add it in a future release. All other communication features — text messages, voice notes, photos, files, and voice calls — are available with the limits described in our Terms of Use. Depending on connectivity and device support, the Service may use direct Bluetooth communication between nearby devices, an extended-range Bluetooth network in which nearby phones forward short messages for each other, WebSocket relay over the internet, and call signaling or relay infrastructure.
If you do not agree with this Privacy Policy, do not use the Service.
Privacy at a glance
- We do not require your real name to use core Proximity features.
- City matching and SOS alerts, if you allow location, see only a ~5 km approximate area computed on your phone. Your exact location is read only when you tap Share location inside an SOS room, and it goes only to that room.
- Your Free Match words never leave your phone. Only scrambled codes are compared, and your words reach a person only after you have matched.
- We do not sell personal information for cross-context behavioral advertising.
1. What we collect and process
1.1 Local and account identifiers
We collect and process identifiers needed to operate Proximity, which may include:
- A device-generated Proximity identity created locally on first use. This identity is stable across reinstalls on the same device until you tap Reset App; reinstalling alone does not give you a fresh identity.
- Cryptographic keys associated with that identity and stored in protected device storage (an Ed25519 signing keypair and an X25519 keypair used for end-to-end encryption).
- An anonymous backend account identifier created in the background to support limited network services, integrity features, optional display metadata, or notification delivery. This identifier is created automatically the first time the app starts and exists on our authentication provider (Firebase Authentication) without requiring you to sign in or sign up.
- A short pseudonymous peer identifier derived from your signing key. This is what nearby devices and the relay see; it is not your name, email, or phone number.
- Optional profile metadata, such as a display name or profile photo, if you add it or if it is otherwise available to the Proximity experience.
You are not required to provide your real name to use core Proximity features. The Service does not require a public sign-up or username; for accuracy we describe this as "no public sign-up required" rather than "fully anonymous", because the device-generated identity and the backend account identifier do persist as described above.
1.2 Device, app, and network information
We collect and process technical information needed to operate, secure, and troubleshoot the Service, such as:
- App version, device model, operating system version, language, and related technical configuration.
- Installation identifiers, push-notification token(s), and app-check or integrity tokens where used.
- IP address, connection metadata, relay session metadata, and other network information necessarily processed when your device communicates with our infrastructure or service providers. IP addresses processed by our relay and signaling infrastructure are not stored long-term in association with message content; they are used for connection routing and abuse prevention and are retained only for the periods described in Section 6.
1.3 Nearby discovery and radio data
If you enable Proximity and grant the required permissions, we process information involved in nearby discovery and matching, including:
- BLE advertising and scanning data.
- Pseudonymous nearby identifiers or hashes used for short-range visibility. These identifiers are designed to limit long-term tracking by external observers and are not your account identifier.
- Signal strength readings (RSSI), timestamps, and derived approximate distance indicators.
- Selected keywords and role labels you choose for matching.
- Announcement metadata such as announcement text, voice-clip availability, and expiration timing.
BLE is used for nearby discovery and lightweight visibility signaling. Ordinary chat, file, and call traffic use separate communication paths.
Approximate nearby indicators are not precise measurements and may be affected by radio conditions, device differences, obstructions, interference, spoofing, replay, or relay behavior.
Important: Proximity does not use GPS coordinates to place people on the radar. On some Android versions, however, nearby discovery frameworks may still require location permission or active location services for BLE or nearby connectivity to function. City reach and SOS alerts use approximate location only, as described in sections 1.4 and 1.10. Exact coordinates are handled only by the SOS Share location control (section 1.10), and only when you tap it.
1.4 City reach and approximate location
If you allow the approximate-location permission and keep City reach on, H2H extends keyword matching to people up to about 25 km away over the internet. City reach processes:
- Approximate location only. We read the approximate ("coarse") location from the operating system - never precise GPS - and immediately reduce it, on your device, to a fixed city area of roughly 5 km. Only that area code ever leaves your phone.
- Blinded keyword codes. Your selected keywords are converted on your device into scrambled codes that change every day. Our servers compare codes to detect matches; they are designed never to see the words themselves.
- Short-lived presence. Your city presence expires within minutes while you are active and is removed immediately when you turn City reach or the proximity module off. If the app is closed or loses connection, your last approximate area may remain matchable for up to one hour (shown to others as older information), after which it is deleted. We do not keep a history of the areas you have been in.
- Match records. A match record exists only between two matched people, carries no location beyond a rough distance label (such as "within ~5 km" or "in your city"), and is deleted when either person leaves the area, changes keywords, or stops being present (at the latest when the one-hour last-known window above ends).
Background discovery is on by default so nearby and city matching keep working when you switch apps. On Android it runs as a standard foreground service with an always-visible persistent notification. You can turn Background discovery off at any time in Settings; doing so stops all background use.
Honest limits: because matching compares deterministic scrambled codes, a party with full server access could attempt to guess common keywords against those codes. We mitigate this with daily code rotation, short-lived storage, and strict server rules, but no system of this kind can eliminate that possibility entirely.
If you deny the location permission, City reach simply stays off - every other feature works over Bluetooth exactly as before.
City reach never handles your exact location. The only location information City reach uses is a ~5 km city area, computed on your phone. The one place H2H reads exact coordinates is the SOS Share location control described in section 1.10, and only at the moment you tap it.
1.5 Communications and user content
We process content you create or exchange through Proximity, including:
- Text messages.
- Voice notes.
- Images and other file attachments.
- Short-lived announcement text and announcement voice clips.
- Pulses content: when you set a Pulse, your selected emotional state and chosen invitation phrase are processed to enable matching with nearby users in similar states. This information is visible to matched users in the Pulses interaction.
- Call signaling data and session metadata needed to establish voice calls. (Video calling is feature-flagged off in this version; the underlying signaling pathway exists for a future release.)
- Media connection metadata produced by calling components.
- SOS alert content and SOS room messages, described in section 1.10.
- Free Match words, topics, and role, described in section 1.11.
Important note on Pulses: Pulses involves users sharing emotional states (such as feeling lonely, heavy, or lost). We treat this content with the same care as other communications data, but we want you to be aware that emotional states you share through Pulses are visible to matched users and, if you choose to chat, to the person you talk with. As with any other content shared with another user, the recipient may copy, screenshot, or re-share it.
Important note on Announcements: Announcements are broadcast to all nearby users with the app, not directed at any specific recipient. The text and voice content you include in an announcement is visible to every nearby person who receives it for the duration of the announcement's expiry.
Call media may travel by direct or relay-assisted network paths depending on connectivity, device support, and runtime configuration.
1.6 On-device storage and caches
Proximity stores substantial working data on your device. That may include:
- Local chat database records, message states, unread counters, and thread metadata.
- Blocked-peer records.
- Attachments copied into app-private storage.
- Temporary recordings and cached announcement voice files.
- Peer profile cache entries, selected keywords, Proximity on/off state, and other local preferences.
- Security material stored in secure storage.
This local storage supports offline continuity, retry behavior, delivery tracking, and faster reopening of the Proximity experience.
1.7 Diagnostics, integrity, and abuse prevention
We collect and process information needed to maintain reliability and integrity, such as:
- Crash reports, performance signals, and structured diagnostics.
- Event timing, state transitions, transfer outcomes, and error categories.
- Integrity and trust signals, including public-key material, signature verification outcomes, replay-detection data, and quarantined peer-key events.
- Block status and related enforcement data.
Our diagnostic systems are intended to avoid raw message text, raw media, and full file paths where possible, and may use shortened or sanitized identifiers instead. No diagnostic redaction process is perfect.
1.8 What we do not require as part of core Proximity
We do not require your real name, government ID, or payment card information to use core Proximity features.
We do not use precise GPS coordinates to place you on the Proximity radar.
We do not read your precise location except at the moment you tap Share location inside an SOS room.
We do not sell personal information for cross-context behavioral advertising.
1.9 What stays paused when you turn Proximity off
When the Proximity toggle on the radar screen is OFF, the Service stops the discovery and communication paths that depend on you being discoverable to nearby users:
- Bluetooth Low Energy scanning and advertising are stopped.
- Extended-range Bluetooth forwarding is stopped.
- Your City presence, including Free Match codes, is removed.
- The Proximity WebSocket relay connection is closed.
- Voice and text-message delivery to and from the Proximity relay is paused.
For honesty: a small number of background services remain active when Proximity is off so the app can still receive a notification or report a crash. These are: anonymous authentication with our backend (so the app can re-attach when you turn Proximity back on), push-notification token maintenance with the operating system's notification service, periodic refresh of voice-call relay credentials, and crash diagnostics. These do NOT advertise your presence to nearby devices.
1.10 SOS: community alert and SOS room
SOS lets you tell people nearby that you need help, and lets you answer someone else's call for help. When you raise an SOS, we process:
- Your alert: the situation you pick (for example Fire, Health, Accident, Danger, Trapped, or Other), what you need (for example Ambulance, Firefighters, Police, or Helping hands), the words you type (up to 480 characters), and an optional photo and voice note.
- Over Bluetooth: the alert is broadcast to every H2H user in radio range with the situation, what you need, and as much of your words as fits in a short radio packet. The identifiers the app puts on air rotate; it never broadcasts a fixed hardware identifier or your name.
- Over the internet, if you allow the approximate-location permission: the alert is published with your ~5 km city area, computed on your phone, so it can reach H2H users up to about 25 km away. Any signed-in H2H user within that reach can see the alert, including the photo and voice note if you attached them.
- The SOS room: every SOS opens one group room for you and the people who respond. The room record holds, for each member, a pseudonymous peer identifier, the public encryption key of their device, their role (the person in need or a responder), join, leave, and removal state, the responder status they choose (on my way, arrived, leaving), and the optional display name and photo they already set in the app.
- Room messages: short text messages, quick phrases, photos, voice notes, and location cards exchanged in the room.
- Exact location, only on your tap: the room has a Share location control. When you tap it, the app reads your precise position once and posts it to the room as a location card with a map link. Nothing else in H2H reads your precise location, and it is never read in the background or without that tap.
- Notifications: an "SOS nearby" notification on phones within Bluetooth range or within the city reach of the alert; a notification to the other room members for each new room message, showing the sender's display name and a short preview of the message (or its kind: photo, voice message, location); and one when the room has ended. Notifications are delivered through the operating system's push service (section 4.2). A member who was removed from a room receives no further notifications from it.
How the room travels: between phones in Bluetooth range, room text is end-to-end encrypted for each member (X25519 key agreement with AES-GCM) and only text rides the radio. When a phone is online, the room is synchronised through our cloud infrastructure so that members who join later can catch up; those cloud copies, including photos, voice notes, and location cards, are stored in readable form on our servers (Google Firebase) and are visible to the room members while the room is live and to the people who took part in it after it ends. Retention is described in section 6.8.
Who can see what: the alert is a public call for help within its reach. Anyone with H2H nearby, including people you have never met, sees it. The room is visible only to its members. You can end your SOS at any time with I'M SAFE, remove a member from your room, hide or report a room, and leave a room you responded to; leaving is final.
SOS is a community alert, not an emergency service. It does not contact emergency numbers and nobody is obliged to respond. In an emergency, contact your local emergency services first.
1.11 Free Match
Free Match lets you say, in your own words and in any language, what you need, offer, or are interested in, and matches you with nearby people whose entry pairs with yours. When you use Free Match, we process:
- Your words: up to 120 characters, stored only on your phone. They are never sent to our servers, never logged, and never included in a notification.
- Your topics and role: on-device suggestions from a catalogue bundled inside the app (the "Book") turn your words into up to 3 topics, and you pick a role (need, offer, or interest). Looking up a topic does not contact any server.
- Scrambled codes: your topics and role are converted on your device into codes that change every day. Nearby phones compare codes over Bluetooth; at city range, our servers compare codes inside your City reach presence record (section 1.4). The codes are designed so that neither nearby phones nor our servers learn your words or the topic names.
- After a mutual match, and only then, your role, your topics, and your words are sent end-to-end encrypted to the matched person, so they can see what you wrote. That record is stored on their device only. The match card shows "Exact Match" when you picked the same topic and "Close Match" when your topics belong to the same family.
- Share links and QR codes: the invitation link the app generates (h2hprotocol.com/get) carries only a campaign source label. It contains nothing about you.
A Free Match entry is a draft until you tap Done; nothing is published before that. Clearing your entry removes your codes from Bluetooth advertising at once and from your City reach presence record when it is next refreshed, at the latest on its normal expiry (section 1.4).
2. How we use information
We use information to:
- Provide and operate Proximity, including generating local identities, enabling nearby discovery, running keyword matching, publishing announcements, routing chats, supporting attachments, and setting up calls.
- Maintain continuity when the Service changes connection paths between direct Bluetooth transport, the extended-range Bluetooth network, relay, or call infrastructure.
- Publish SOS alerts to people within their reach, synchronise SOS rooms between their members, and send the related notifications.
- Run Free Match comparisons using scrambled codes, and deliver your Free Match words to a person you have matched with.
- Store and restore local history, media, and preferences on your device.
- Display optional name or photo metadata to you or nearby users where available.
- Maintain reliability, security, and abuse prevention, including enforcing blocks, detecting suspicious activity, checking message integrity, troubleshooting failures, and improving service stability.
- Send notifications about chats, announcements, or calls if notifications are enabled in your build and on your device.
- Comply with legal obligations and respond to lawful requests.
3. Legal bases for processing (EEA/UK and similar jurisdictions)
Where GDPR, UK GDPR, or similar law applies, we rely on:
- Performance of a contract, to provide the Service you request.
- Consent, for permissions such as Bluetooth, nearby devices, microphone, camera, photos/files, notifications, and location access where the operating system requires it.
- Legitimate interests, to secure the Service, prevent abuse, maintain reliability, and improve performance, balanced against your rights.
- Legal obligation, where we must retain or disclose information to comply with law.
You may withdraw consent by changing device permissions or app settings, although some Proximity features may not work without the required access.
4. How information is shared
4.1 Shared with other users
Depending on what you choose to do in Proximity, other users may receive or see:
- Your nearby presence signals and pseudonymous discovery identifiers.
- Your selected keywords and role labels when the matching flow requires them.
- Your active announcement text, announcement voice availability, and related expiration state.
- Your messages, voice notes, images, files, and call signaling sent to the person you interact with.
- Optional display metadata such as your display name or photo, when available to the Proximity experience.
- Your SOS alert (situation, needs, words, optional photo and voice note, and your ~5 km area at city range) to any H2H user within its reach; your SOS room messages, and your exact location if you tap Share location, to the members of that room.
- Your Free Match codes to nearby phones and, through our servers, to phones in your city; after a mutual match, your Free Match words, topics, and role to that person.
H2H cannot control what other users do with information you share with them. They may copy, record, screenshot, export, or re-share it.
4.2 Shared with service providers and infrastructure partners
H2H Protocol functions locally on your device for nearby discovery, chat, and calls — these features do not require backend services to operate. We do, however, use third-party providers for supporting infrastructure including online relay (when peers are not within local-radio range), call networking, anonymous identity, and crash diagnostics. These providers process information on our behalf under contractual data-processing agreements and only for the purposes described below. The current providers are:
- Cloudflare, Inc. — relay-server hosting (Cloudflare Workers + Durable Objects), WebSocket infrastructure, signaling support, and TURN/STUN service for voice calls. (Video calling is not enabled in this version; the TURN/STUN pathway is voice-only at present.) Data is processed on Cloudflare's globally distributed edge network, with relay sessions pinned to regional data centers near the participating users.
- Google Firebase (operated by Google LLC) — Firebase Authentication, for the anonymous backend account identifier; Firebase Crashlytics, for crash reporting and diagnostics; Firebase App Check, for app integrity verification; Cloud Firestore and Firebase Storage, for optional profile metadata, City reach presence and match records, SOS alerts, SOS rooms, and the photos and voice notes attached to them; Firebase Cloud Messaging, for notifications; and Cloud Functions, for city matching, SOS notifications, and scheduled cleanup.
Each provider receives only the information needed to perform its specific function. We update this list when our infrastructure changes; please check the "Last updated" date for the current version. If you require the full subprocessor list with corporate addresses for compliance purposes, contact us at the address in Section 13.
4.3 Shared for legal, safety, and compliance reasons
We may disclose information:
- To comply with law, regulation, legal process, or lawful government request.
- To protect the rights, safety, and security of H2H, our users, or the public.
- To investigate fraud, abuse, threats, unlawful conduct, or violations of our Terms.
- In connection with a merger, acquisition, financing, or sale of assets, subject to appropriate safeguards.
5. Permissions and device access
Depending on your device and operating system, the Service may request or depend on:
- Bluetooth scanning, advertising, or connection access.
- Location permission or location services on some Android versions, because the operating system may tie nearby discovery to those controls.
- Approximate location for City reach, Free Match at city range, and SOS alerts at city range.
- Precise location, read once at the moment you tap Share location inside an SOS room.
- Microphone access for voice notes and calls.
- Camera, photos, or file access when you choose to capture or attach media.
- Notifications permission to alert you about messages, calls, matches, and SOS alerts.
You can manage these permissions in your device settings. Disabling them may prevent Proximity from discovering nearby users, exchanging media, or supporting calls.
6. Retention and deletion
We use a combination of local persistence, automatic expiry, operational retention, and user controls.
6.1 Local retention
Chat history, message state, blocked-peer records, copied attachments, cached profile metadata, local preferences, and security material may remain on your device until you delete them, clear app data, uninstall the app, or use a full-reset feature if one is available in your build.
Removing a thread from the inbox may hide it locally, but new activity from the same peer may cause the thread to appear again.
6.2 Automatic expiry
Nearby announcements are intended to expire after their selected time limit. Expired announcements should no longer be actively shown as current nearby broadcasts, although related local caches, diagnostics, or temporary files may persist briefly until cleanup routines run.
SOS alerts expire 2 hours after they are raised unless the person extends them in 1-hour steps, and end earlier when they tap I'M SAFE. Expired alerts and their photo and voice note are deleted by a cleanup routine that runs every 15 minutes.
City reach presence, including Free Match codes, expires within minutes of your last refresh (at most about one hour as last-known information), and city match records expire within 24 hours.
6.3 Operational and provider retention
When relay, signaling, diagnostics, or notification services are used, those systems retain certain data for the periods needed to deliver the service, prevent abuse, and meet legal and provider requirements. Specific retention periods are:
- Relay-server message queues: when the recipient of a message is online, the H2H relay routes the message in real time and does not store it. When the recipient is offline, the relay temporarily holds the message — both the message body AND the sender-identity fields (sender display name, sender photo URL, and the anonymous backend account identifier) are end-to-end encrypted under the recipient's public key, so the relay cannot read either — for up to 30 days, then permanently deletes it. The envelope the relay does see contains routing fields only: sender and recipient peer identifiers, message id, timestamp, and trace id. Per-recipient queues are capped at 1000 messages or 10 MB total, whichever is reached first; messages beyond the cap are rejected at submission time and are not stored. Queues are held on Cloudflare Durable Objects in the same regions as the relay. We do not retain copies of delivered messages once the recipient's device acknowledges receipt.
- Offline-recipient message queues: up to 30 days, after which queued messages are permanently deleted whether delivered or not.
- Push-notification delivery records: up to 30 days.
- Crash reports and diagnostic logs: up to 90 days.
- Server-side abuse-prevention records (block events, rate-limit triggers, integrity violations): up to 6 months.
- Operational backups of relay infrastructure: up to 30 days, after which they are overwritten in normal rotation.
- Audit and security records required for legal compliance: retained for the period required by applicable law, typically up to 7 years.
Specific retention periods may vary slightly by service provider; the figures above reflect H2H's policies and the contractual limits we set with our providers.
A note on the end-to-end encryption used for chat content: we use a static X25519 key-agreement model, meaning the shared encryption key for any given pair of users does not rotate over time. If a private key is compromised in the future, prior messages exchanged with that peer could in principle be decrypted by someone who also possesses the matching ciphertext. Forward-secrecy (per-message ratcheting) is on our roadmap for a future release.
A note on diagnostic data: crash reports and minimal diagnostic events flow to Google Firebase Crashlytics. These are processed independently of the Proximity toggle so we can be alerted to crashes regardless of whether you are actively discoverable. Crashlytics data is retained per the Firebase product's standard retention windows (currently up to 90 days for full crash reports, with anonymized aggregates retained longer for trend analysis); see Google's Firebase documentation for the current values.
6.4 Residual copies
Backups, cached copies, or recovered transfer fragments may persist temporarily as part of routine operation, retry behavior, or security handling.
6.5 Moderation reports you submit
When you tap "Report" on a peer, message, call, or announcement, we receive a moderation report. The report flow runs entirely inside the app over an authenticated connection to our moderation backend on Cloudflare. We do not, by default, see your messages, voice recordings, or call audio.
- A report submitted in-app contains: the category you chose (harassment, inappropriate content, spam, etc.), the peer identifier of the person being reported, the kind of context (chat / voice message / call / announcement), an optional reference id for the specific item, and your optional 500-character note. That is what we receive by default.
- Evidence (selected text, voice clips, call metadata, announcement references) is uploaded ONLY if you explicitly attach it during the report flow. You see exactly what will be uploaded BEFORE you confirm; the default is to attach nothing.
- Voice-clip evidence is stored on Cloudflare R2 with a 90-day lifecycle policy: clips are permanently deleted 90 days after upload regardless of moderation status.
- Other report data is retained for the period required by our moderation policy and applicable law (typically up to 12 months for an open or actioned report; longer if a legal request requires it).
- If your device cannot reach our moderation backend (offline, service degraded, etc.), the report flow falls back to opening your email app pre-filled with a report. In that case the email body includes the recent conversation for context, and you review it before tapping Send. The recipient address (`legal@h2hprotocol.com`) is published and unchanged from earlier app versions.
- Your reporter identifier (the same anonymous peer id used by Proximity) is stored alongside the report so we can apply rate limits and detect coordinated abuse, but is not shown to moderators by default.
6.6 Photos and files
When you send a photo or file to someone you've matched with on H2H, the content is end-to-end encrypted on your device before it leaves it. Our relay routes the encrypted content to the recipient and cannot read it. If the recipient is offline, the encrypted content is held on our infrastructure (Cloudflare Durable Objects, hosted in the United States) for up to 30 days and is automatically deleted once delivered or when the retention period expires, whichever comes first.
Photos are automatically compressed to a maximum of 600 KB before sending to keep transmission fast and costs low. Files must be one of the following document types — PDF, Word, Excel, PowerPoint, or plain text — and cannot exceed 1 MB. We do not inspect, scan, or process the content of your photos or files at any point. We do not retain copies after delivery.
6.7 Mesh discovery and short messages in crowded venues
In dense indoor venues such as malls, festivals, conferences, and transit hubs, your device can act as an opportunistic forwarder for small encrypted packets from other H2H users nearby. We call this the extended-range network. It exists so two H2H users on opposite sides of a venue can still discover each other even when they are out of direct Bluetooth range.
Your device only forwards packets that are small, encrypted, short-lived, and explicitly type-allowlisted: pulse matches, connect requests, announcement broadcasts (text only, no voice clip), and short chat replies (up to 140 characters). Voice notes, photos, files, video, and any longer text always take the direct or cloud-relay paths — they never enter the extended-range network.
Packets are encrypted end-to-end. Your device cannot read the content of packets it forwards for other users — it is a conduit, not a reader. Packets carry a hop limit (at most 5 hops for announcements, fewer for other types) and a short time-to-live (at most 90 seconds for announcements, less for other types). After the limit or the timer expires, the packet stops propagating.
We do not log or store the content of mesh packets on any server. The relay infrastructure (Cloudflare Durable Objects described in § 6.3) is a separate path and does not see mesh packets at all.
- You can turn extended-range forwarding off at any time in Settings → Privacy → Help nearby people connect. With forwarding off your device will still discover other H2H users in direct range, but it will not relay packets for them.
- When your battery is low or your device is thermally stressed, your device automatically pauses forwarding to protect battery life. You can still originate your own announcements and messages even when forwarding is paused.
- We can disable the entire extended-range network remotely and instantly if we observe abuse or other safety concerns, with no app update required.
6.8 SOS rooms
An SOS room ends when the person who raised it taps I'M SAFE or when the alert expires. After it ends, the room, its messages, its member records, and the photos and voice notes attached to it are retained for 90 days so that the people who took part can review what happened and so that we can act on reports, and are then deleted automatically by the same cleanup routine.
Reports you file about an SOS room (the room, the reported member, and the reason you chose) are kept for the period described in section 6.5.
Deleting your profile (section 9.3) does not remove an SOS room you took part in or the messages you posted in it; they remain visible to the other members until the room's 90-day retention ends. To ask for earlier removal, contact us at the address in Section 13.
7. Security and important limitations
We use administrative, technical, and organizational measures intended to protect information, including access controls, signed or verified protocol elements, integrity checks for transferred files, and transport protections where supported.
7.1 What is protected
- Media attachments and call media use authenticated encryption for confidentiality and integrity during transit between you and the person you are communicating with.
- Chat messages, signaling, and announcement payloads are cryptographically signed using device-bound keys, so the recipient can verify they originated from the sender and were not altered in transit.
- Cryptographic keys associated with your device identity are stored in protected device storage.
- File transfers include integrity checks designed to detect tampering or corruption.
- SOS room text exchanged over Bluetooth is end-to-end encrypted for each member (X25519 key agreement with AES-GCM), and only text travels over the radio.
7.2 Important limitations
- No method of storage, radio communication, or internet transmission is completely secure.
- BLE-based proximity can be inaccurate and can be affected by walls, reflections, interference, device differences, spoofing, replay, relay behavior, or malicious actors.
- We do not guarantee that a nearby signal represents a person's exact location, identity, truthfulness, or safety.
- We do not represent that every communication path in Proximity uses end-to-end encryption in every circumstance — please do not assume otherwise for the most sensitive content.
- SOS room content delivered through the cloud is stored in readable form on our infrastructure so that members can catch up and so that reports can be acted on. Treat an SOS room as a group conversation with strangers, not as a private channel.
8. International data transfers
H2H processes data in the following regions:
- Primary infrastructure (relay servers, signaling, WebSocket transport, TURN/STUN): globally distributed via Cloudflare's edge network, with relay sessions pinned to regional data centers near the participating users.
- Crash reporting (Crashlytics), anonymous authentication (Firebase Auth), and app integrity verification (App Check), provided by Google Firebase: processed in regions designated by Google, which may include the United States and European Union.
- Profile metadata, City reach presence and match records, SOS alerts and SOS rooms, and their photo and voice attachments (Cloud Firestore and Firebase Storage, provided by Google Firebase): stored in us-central1 (Iowa, United States). The Cloud Functions that match city presence and clean up SOS data run in asia-south1 (Mumbai, India) and us-central1.
If you are located in the European Economic Area, the United Kingdom, or another region with cross-border data protection requirements, transfers of your personal data outside that region rely on the Standard Contractual Clauses (SCCs) approved by the European Commission, where applicable; adequacy decisions issued by the European Commission, where applicable; and additional technical and organizational safeguards consistent with applicable law.
You may request more information about the specific transfer mechanisms in use by contacting us at the address in Section 13.
9. Your privacy rights
9.1 GDPR/UK GDPR and similar rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or port personal data, and to withdraw consent where consent is the basis for processing.
9.2 U.S. state privacy rights
Depending on your state of residence, you may have rights to know what personal information we collect, request deletion, correct inaccurate information, and receive non-discriminatory treatment for exercising privacy rights.
We will verify requests as required by law and may ask for information needed to confirm your identity.
How to exercise your rights: contact us at privacy@h2hprotocol.com. We aim to respond within 30 days of receiving a verifiable request. If we cannot fulfill your request within that time, we will tell you why and provide an updated timeline.
Right to lodge a complaint: if you are in the European Economic Area, the United Kingdom, or a similar jurisdiction, you have the right to lodge a complaint with your local data protection supervisory authority if you believe we have not handled your personal data lawfully. You can find your local authority through the European Data Protection Board (edpb.europa.eu) or your country's regulator.
9.3 What happens when you delete your account
When you tap Delete profile & erase everything in the app, we run a coordinated erasure across every storage location we control:
- On your device: chat threads, messages, attachments, voice notes, blocked-peer records, profile cache, preferences, and your local cryptographic identity are deleted permanently.
- On our servers: your anonymous Firebase Authentication user is deleted, your profile document and profile photo are deleted from Firestore and Firebase Storage, and any pending messages addressed to or from you on the relay are purged immediately (rather than waiting for the normal 30-day expiry).
- Reports you previously submitted through the in-app reporting tool are not deleted outright — we anonymize them so the moderation history stays intact for safety purposes but can no longer be linked back to you. Your reporter identifier is replaced with a one-way salted hash and your anonymous backend account id is cleared from those rows. Any voice-clip evidence you attached to those reports is deleted from our evidence storage.
- Reports that other users filed against you are not affected by your account deletion — those are about conduct toward other users and remain available to our moderators to act on.
- City reach presence, Free Match codes, and match records stop being refreshed and expire on their normal schedule (presence within about an hour, matches within 24 hours, and your notification registration within 60 days). SOS rooms you took part in are handled as described in section 6.8.
If the server-side erasure step cannot complete at the moment of deletion (for example, your device is offline when you tap Delete profile & erase everything), the deletion still proceeds locally and the server-side artefacts expire on their normal schedule: pending messages within 30 days, voice-clip evidence within 90 days.
10. Children and minors
The Service is intended for users aged 18 and over. H2H Protocol supports communication and broadcasts between strangers in nearby physical spaces, including features that involve emotional disclosure (Pulses), direct messaging and voice with people not previously known to the user, SOS rooms with strangers who respond, and Free Match. These features are not appropriate for children.
We do not knowingly collect personal data from users under 18. If we learn that we have collected personal data from a person under 18 without verified parental consent (where local law permits processing on that basis), we will take steps to delete the information.
If you believe a person under 18 is using the Service, please contact us at the address in Section 13 so we can take appropriate action.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will post the updated version at the same public URL and revise the "Last updated" date.
For material changes — changes that meaningfully affect what data is collected, how it is used, who it is shared with, or your rights regarding it — we will provide reasonable advance notice through an in-app notice that requires acknowledgment before continuing to use the Service. Continued use of the Service after the effective date of the updated version constitutes acceptance of the updated Privacy Policy.
12. Special care for sensitive features
Certain features in H2H Protocol involve content that may be more sensitive than ordinary communications:
- Pulses allows you to share an emotional state (such as feeling lonely, heavy, or lost) with nearby users. Because this involves emotional vulnerability, we apply additional care: Pulses content is held to the same encryption and integrity protections as other communications, and our internal diagnostic systems are designed to never log Pulses content in plain text.
- Announcements are broadcast to all nearby users with the app for the duration of the announcement's expiry. Because this is a 1-to-many disclosure, we recommend exercising caution about identifying details included in announcement text or voice clips.
- First-contact consent and abuse protection. When a new peer reaches you for the first time, the Service does NOT directly open a chat thread. You see a short request with an optional 120-character note and choose Accept, Block, or Report. Voice messages, voice calls, and any media from a new peer are refused until you Accept. If you Block or Report a peer, a 24-hour cooldown drops their messages and calls at your device. The Service also applies per-peer and per-sender rate limits at both the device and our relay server (sized so a normal user never hits them; a tampered client cannot bypass the server-side limits).
- SOS. Raising an SOS tells strangers nearby that you are in trouble, roughly where you are, and what you wrote or recorded. Tapping Share location inside the room gives its members your exact position. Both are deliberate, one-tap actions; use them when you need people to find you.
- Free Match. Your words can be personal. They stay on your phone and reach only a person you have matched with, after the match. Nobody can browse Free Match entries.
If you choose to use these features, the protections described elsewhere in this Privacy Policy apply, but the inherently social nature of the features means that the people who receive your content may, like any human recipient of any communication, retain or re-share it.
13. Contact us
Data controller: H2H Protocol, established in the Sultanate of Oman.
- Privacy and data-protection enquiries: privacy@h2hprotocol.com
- General support: support@h2hprotocol.com
- Legal notices: legal@h2hprotocol.com
For users in jurisdictions requiring an EU representative or UK representative under GDPR, please contact privacy@h2hprotocol.com and we will provide the appropriate representative's details.
This Privacy Policy should be read together with our Terms of Use and Community Guidelines. The plain-language summary of how we handle data is available in the Privacy & Data page within the app. To delete your account, see our account deletion guide.