PagerChat
Privacy Policy
This page makes no requests to any third party: no fonts, scripts or trackers are loaded from elsewhere.
1. Introduction
This Privacy Policy explains what information the app handles, where it is stored, what is sent to our directory server and to other users, and the choices you have. It is provided by Obaid Nejres. Policy version: 2026-09-26.
2. Privacy by Design
The app is built so that as little as possible leaves your device. Your account is local, conversations are stored on your device, and messages are sent directly between devices with end-to-end encryption. A small directory server exists only to help devices find and reach each other; it is not a store for conversations. The app contains no advertising or analytics SDKs.
3. Local Account
Your account is created and maintained locally on your device. When you sign in you enter a private user key, a display name and, optionally, a phone number.
- The private user key never leaves your device. The app derives two values from it on the device: your application identifier (see section 7) and an authentication proof that lets the server confirm the identifier is yours.
- Your display name is sent to the directory server (see section 8).
- Your phone number is stored only on your device. The current version of the app does not send it to the server.
4. Local Storage
Application data stored locally by the app remains on your device unless the app functionality explicitly requires its transmission. Stored locally: your account details, your contacts, your conversations, media you received, and your privacy choices. This data lives in the app's private storage, protected by Android's app sandbox; the app does not add a separate layer of encryption to these files. This data is excluded from Android backups and from transfers to a new phone, so it is not copied to Google Drive or another device; if you change phones you can sign in again with your private user key, but conversations stay on the old device.
5. Nearby People
Nearby People lets you discover and connect with people around you. It is optional and off until you turn it on. Turning it on shows an explanation first, and only then asks Android for location permission. You can use chats, contacts and calls without it.
6. Location Information
- Purpose: only to show you on, and show you, the Nearby People map. Location is never used for advertising or tracking.
- Precision: the app requests Android's approximate location permission only, and rounds coordinates to about 1 km before sending them.
- Foreground only: location is used only while the Nearby People feature is enabled and the app is open on your screen. It is read and sent when you turn the feature on, when you return to the app, and when the app reconnects to the directory server while open. It is not sent on a timer.
- No background location: the app does not request background location permission, has no background location service, and never accesses your location while it is in the background, with the screen off, or after you close it. When you leave the app, it asks the directory server to remove you from the nearby list and stop sharing your last location until you return.
- When you turn Nearby People off, the app stops accessing and sending your location immediately and does not send it again unless you turn the feature back on.
- If you deny or later revoke location permission, the app does not read or send your location, does not try to obtain it any other way, and asks the server to stop listing you.
7. Application/User Identifier
Your identifier is derived on your device from your private user key. It is the same every time you sign in with the same user key, so it identifies your account on the network. It is how contacts find you and how the server routes connection requests to you. It is sent to the directory server whenever the app connects, and it is visible to people you communicate with and, when Nearby People is on, to other participating devices.
8. Directory Server
The application uses a directory server to help devices discover other users participating in the Nearby People network and to set up direct connections between devices.
The directory server receives the application/user identifier and location information required for this feature. When the app connects it also receives your display name, the authentication proof described in section 3, whether Nearby People is on, your device's IP address (as any internet server does), and a push-notification identifier (Firebase Installation ID) so it can notify you of incoming messages and calls.
Your location and IP address are not saved in the server's records. The server uses them only while you are connected and discards them when your connection ends.
To set up a direct connection, the server relays technical connection data (such as network addresses) between the two devices. It does not receive the content of your messages, media or calls: the app never sends that content to the server.
The directory server does not store or process the content of end-to-end encrypted conversations. It does receive your location when Nearby People is on; your identifier and display name identify your account to it.
9. Sharing With Other Devices
When Nearby People is enabled, your location information and identifier may be provided to other participating devices so that you can be discovered as a nearby user. Along with them, other devices receive your display name and your last-seen time. The list is sent only to users who have Nearby People turned on themselves, and it includes everyone who has the feature on, wherever they are, not only people close to you. The map shows the people in the area being viewed, and any user can move the map to see other areas.
Your location is therefore not visible to the server only. Anyone using Nearby People may see your approximate position while you appear in the list. Your position is shown with a precision of about 1 km, so others can tell the neighbourhood you are in but not your exact location. People you chat or call with directly can see your identifier and display name, and, as with any direct internet connection, their device may learn your IP address.
10. End-to-End Encrypted Messages
Messages are protected using end-to-end encryption so that message content is intended to be readable only by the communicating parties. Text messages and media are encrypted on your device with a key agreed directly between the two devices (ECDH key agreement and AES-256-GCM), and are sent device-to-device. If a direct route is not possible, encrypted data passes through a relay server that forwards it without being able to read it.
Voice and video calls use the standard WebRTC encryption (DTLS-SRTP) between the two devices.
Your identifier and location used by Nearby People travel on a separate path to the directory server and are not covered by this message encryption; they are protected in transit by standard TLS but are readable by the server, as described above. Not all application data is end-to-end encrypted — only message and media content is.
11. Data Retention
On your device: data is kept until you delete it (individual chats, or Settings › Privacy › Delete Local Data) or uninstall the app.
On the directory server:
- Location: not saved in the server's records. It is used only while you are connected with Nearby People on and the app open, and each new location replaces the previous one. It is discarded when you leave or close the app, turn Nearby People off, lose location permission, or your connection ends.
- IP address: not saved in the server's records; used only for the duration of your connection.
- Identifier, display name, authentication proof, push identifier and last-seen time: stored until you delete your account (Settings › Privacy › Delete Account), so that contacts can find and reach you.
- Anonymous mode identities: not saved in the server's records; discarded about one minute after they disconnect.
On other devices: information another device has already received (for example your position in a list it downloaded, or messages you sent) is under that user's control.
12. Data Deletion
- Settings › Privacy › Delete Account deletes your account from the directory server (identifier, display name, authentication proof, push identifier, last-seen time) and then all local data. It requires a connection; if the server does not confirm, nothing is deleted.
- Settings › Privacy › Delete Local Data deletes your account, contacts, conversations, stored media and privacy choices from this device only, removes you from Nearby People and stops push notifications to this device. Your server registration is kept so you can sign in again.
- Turning Nearby People off removes your location from the server immediately.
- You can also request deletion by e-mail at obaidnigers@gmail.com, for example if you no longer have the app.
- Nothing can remove messages already delivered to other people's devices.
13. Advertising and Tracking
The app shows no advertising and contains no advertising or analytics SDKs. Your data, including your location, is not used for advertising, profiling or tracking you across other apps or websites, and is not sold.
14. Third-Party Services
The app uses these third-party services, only for the functions stated:
- Google Maps SDK for Android — to display the Nearby People map. Google receives the map requests your device makes (for example the area being viewed) under Google's privacy policy.
- Firebase Cloud Messaging (Google) — to deliver incoming-message and call notifications. Google handles the device's Firebase Installation ID and the notification metadata (type of event, sender identifier and display name); message content is never included because the server never has it.
- A public STUN server operated by Google — to help your device discover its network address when setting up a direct connection.
- WebRTC — open-source library for direct, encrypted connections between devices.
The directory server and relay server are operated by us.
15. User Choices
- Nearby People: on or off at any time in Settings › Privacy › Nearby People.
- Location permission: grant, deny or revoke it in Android settings; the app keeps working without it.
- Anonymous mode: chats and calls under a temporary alias identifier; the app never sends a location with the alias.
- Delete Account or Delete Local Data: Settings › Privacy.
- Notifications, camera and microphone permissions can be managed in Android settings.
16. Changes to Privacy Policy
If this policy changes in a way that affects how your data is handled, the app will show the new version and ask you to accept it again before you continue. The version and date you accepted are stored on your device.
17. Contact Information
Obaid Nejres
Privacy questions and deletion requests: obaidnigers@gmail.com