Privacy
Data you write on this blog isn't persisted on our server, and when you upload an image, it goes to a media server — there's no database of ours storing it.
We don't collect your data. This app doesn't know who you are beyond your public key.
Your private key never passes through here in plain text. It's encrypted only on this browser — this app uses that encryption to sign each post, comment or like, but never sees or sends the key itself anywhere.
What stays only in your browser
The only three things this app stores, kept only on this device — never sent to any server:
- A signed post that no relay accepted, kept so you can try again without losing the text.
- The date you last opened notifications, to know what's new.
- Your private key, encrypted with a key that never leaves this browser — not even this app can extract it.
What you publish is public, by your own decision
Posts, comments, likes and profile you publish go to the relays and stay there, public — that's how the protocol works. This isn't data we "collect": it's content you decided to make public, and it leaves here straight to the network, without passing through any server of ours in between. The Why page goes into more detail on the implications of this — including what isn't as private as it seems, like a draft in plain text and an image that's always public.