HopNet is a private, end-to-end-encrypted messenger with no accounts and no phone number. You add contacts in person by scanning their QR code — there is no random matching and no stranger chat. Your messages go directly between devices whenever possible; when your contact is offline, your message waits — still fully encrypted and unreadable to anyone — in a temporary "blind mailbox" until they reconnect. We cannot read your messages, your contacts, or who you talk to: the only thing that ever leaves your phone is encrypted data that no one, including us and our infrastructure providers, holds the keys to.
We do not collect personal information. HopNet has no accounts, asks for no phone number or email, and contains no analytics, no advertising, and no trackers. We do not run servers that can read your data. We use one piece of rented infrastructure — a blind mailbox (see "How messages travel") — which by design holds only encrypted data it cannot decrypt, briefly, and which we cannot use to identify you or map who you talk to.
All of your data is stored locally on your phone: your identity keys (in secure storage), your contacts (added by scanning QR codes), your message history (encrypted at rest), and a local diagnostics log (visible in Settings → Engine Debug) that stays on your device unless you choose to share it. You can erase all of it at any time with Settings → Clear All Data.
HopNet connects your device directly to your contacts' devices over a peer-to-peer network. Messages are end-to-end encrypted (X3DH key agreement and the Double Ratchet, using standard algorithms) so only you and your contact can read them.
Because connections are peer-to-peer, please understand that your IP address is visible to peers you connect to, and is used by the distributed hash table (DHT) to help devices find each other. This is inherent to peer-to-peer networking, the same as other such apps. If you need to hide your IP address, use a VPN or Tor. Other participants in the network can observe connection metadata as in any peer-to-peer system.
If your contact's app is closed when you send, your phone also places the message in a temporary blind mailbox so it arrives the next time they open the app — without both of you needing to be online at the same moment. The mailbox is hosted for us by Cloudflare (acting as a processor). It is "blind" because:
What the mailbox/Cloudflare can technically observe is limited to encrypted blobs, their padded sizes, timestamps, the random box identifiers, and the IP address making the request — never message content, your identity, or your social graph.
Camera — to scan a contact's QR code (and, in future, photo/video). Microphone — for future voice/video calls (not yet active). Photo library — to share photos/videos you choose. These are used only for the stated purpose, on your device.
The app keeps a local diagnostic log on your device to help with debugging. If you use Settings → Send Feedback to send a bug report, your message (and, if you leave the toggle on, your app/OS version) is sent by your own email app to [email protected] — only when you tap send. Separately, if you have Apple's "Share With App Developers" analytics turned on, Apple may share crash reports with the developer per Apple's own policy.
HopNet is intended for users aged 17 and older and is not directed to children.
We may update this policy; the "effective date" above will change. Material changes will be noted in-app or in release notes.
Questions about privacy: [email protected].