HOP Privacy Policy
HOP is built to know as little about you as possible. You don’t create an account, you don’t give us a phone number or an e‑mail, and the content of your messages is end-to-end encrypted — we can’t read it. Below we describe exactly what data exists, where it lives and who can see it.
This English version is provided for convenience; the Polish version is legally binding.
1. Controller
The controller of personal data is Appifi Sp. z o.o., Tylna 2D/41, 90-346 Łódź, Poland, KRS 0001150929, NIP (VAT) PL7252351636, REGON 540700682 (“we”). For privacy matters write to privacy@hop-app.eu or by post to our registered office.
On the App Store the app is published from the Apple developer account of Rafał Mirowski, CEO of Appifi Sp. z o.o., on the company’s behalf. This does not change the controller of your data, which is Appifi Sp. z o.o.
This policy covers the HOP app for Android and iOS, the HOP internet relay, the hop-app.eu website and e‑mail contact with us.
2. In short
- We run no user accounts and do not store your messages, contacts or conversation history — everything stays on your phone.
- Private messages are end-to-end encrypted. Phones along the way and our relay don’t know their content — they only see who a message is from and to (HOP identifiers), when it was sent and how big it is.
- By default HOP works without the internet. It connects to our server only if you turn the internet on in the app.
- We use no ads, no analytics, no profiling and no trackers. The hop-app.eu website sets no cookies.
3. Data on your phone
The app stores locally your cryptographic key pair (your HOP identity), name and status, contacts, messages, photos you sent and received, settings, and other people’s encrypted messages your phone carries on. On Android this data is in an encrypted database whose key is protected by the system key store (Android Keystore). On iPhone the identity keys are in the iOS Keychain and the rest is in app files protected by iOS Data Protection — readable only after the phone has been unlocked once since it was switched on. We have no access to this data. Uninstalling the app removes it from the phone.
4. What other phones in the mesh see
- Your card — name, status and public key — is visible to HOP phones nearby and passed on through the network. With “Hide me from strangers” on, strangers get a card without name and status; only your friends and people you write to get the real one.
- Private messages are end-to-end encrypted (X25519, HKDF-SHA256 and ChaCha20-Poly1305, Ed25519 signatures). Phones that carry them see the sender and recipient identifiers (public keys), time, size and hop count — not the content. Messages are encrypted to the recipient’s long-term key (no forward secrecy): someone who kept copies of encrypted messages and later obtained the recipient’s keys (for example from their unlocked phone) could read them. Disappearing messages are deleted only from the sender’s and recipient’s phones.
- “Nearby” announcements are public: signed but not encrypted. Every HOP phone around (up to 4 hops) sees them for the time you choose (15–60 minutes).
- An SOS alarm to everyone nearby is public: it contains your name, an optional note, battery level and — if you decide — your GPS position, updated as you move. It travels only through the mesh, never over the internet.
5. Internet relay (optional)
When you turn the internet on in the app, HOP connects over TLS to our relay (a server in an OVHcloud data centre in Poland). The relay stores and delivers encrypted messages to your contacts, also when they aren’t nearby. For this it processes:
- your IP address (for the duration of the connection),
- your card, which every HOP connection exchanges — your public key plus name and status (without name and status when “Hide me from strangers” is on),
- HOP device identifiers (public keys) of sender and recipient, packet time and size,
- encrypted packets — until delivered or expired (3 days by default, at most 7 days),
- encrypted “I’m online” signals HOP sends every few minutes to your verified contacts.
The relay doesn’t know message content, tells no one who else is connected and doesn’t log who connects — it records aggregate counters only. If you turn on the “bridge” (hub) feature, your phone carries other people’s encrypted messages between the nearby network and the internet, within a daily data limit you set.
Legal basis: Art. 6(1)(b) GDPR (providing the service you request by turning the internet on) and Art. 6(1)(f) GDPR (security of the service).
6. Location
HOP doesn’t track your location. Your GPS position is used only when you attach it to an SOS alarm or open the compass to reach someone calling for help. Only the recipients of the alarm see it; it reaches us only inside an encrypted SOS message to your contacts carried by the relay. On Android the system may require the location permission to scan for Bluetooth devices — HOP doesn’t read your position for that.
7. SMS and 112
If you wish, HOP prepares an SMS with your position for people you choose. You send it yourself with the system SMS app; it goes through your carrier and isn’t encrypted. The list of people is stored only on your phone. Calls to 112 are made by the system phone app.
8. App permissions
- Nearby devices / Bluetooth / Wi‑Fi — finding HOP phones and connecting to them.
- Notifications — new messages and SOS alarms, an ongoing notification while working in the background.
- Camera — only while scanning a contact’s QR code; the image is neither saved nor sent.
- Location — see section 6.
- Photos — you pick a specific photo to send; it is compressed and encrypted on the phone.
- Contacts — only picking people for SMS SOS; HOP doesn’t read your address book.
- Background work / battery optimization (Android) — so the phone relays messages with the screen off.
9. Third-party services in the app
On Android HOP uses the Nearby Connections service of Google Play services, which connects phones locally. Google may process diagnostic data under its own privacy policy (policies.google.com/privacy). The app contains no advertising, analytics or crash-reporting libraries.
10. The hop-app.eu website and e‑mail
The website uses no cookies or analytics. The server keeps standard logs (IP address, date, page address, browser) for 14 days for security (Art. 6(1)(f) GDPR). If you write to us, we process your e‑mail address and the correspondence to reply (Art. 6(1)(f) GDPR), for as long as needed to handle the matter and no longer than 3 years.
11. Recipients and transfers outside the EEA
The relay, website and mail servers run at OVH (OVHcloud) in the European Union; OVH processes data only on our behalf. We don’t transfer data outside the European Economic Area and we don’t sell it to anyone.
12. Your rights
You have the right to access, rectify and erase your data, to restrict processing, to data portability and to object to processing based on our legitimate interest. Since we run no accounts, you control most data yourself in the app (deleting chats, hiding, turning the internet off, uninstalling). To exercise your rights write to privacy@hop-app.eu. You may lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warszawa), or with the authority in your country.
13. Children
HOP is intended for people aged 13 and over. People under 16 may use the internet features with the consent of a parent or guardian.
14. Changes
We will announce material changes to this policy on hop-app.eu and in the app’s update notes.
Effective 3 October 2026.