Privacy Policy

Effective date: March 21, 2026

What Data We Collect

We collect no personal data. Hooly does not require registration, phone numbers, email addresses, or any personal information. Your identity is a cryptographic key pair generated on your device.

How Encryption Works

All messages are end-to-end encrypted using the PQXDH (post-quantum X3DH + ML-KEM-768) and Double Ratchet protocols. This hybrid approach provides quantum-safe encryption today. Encryption keys are generated and stored exclusively on your device. We have no access to your messages, contacts, or media.

What the Notification Proxy Knows

Our notification proxy server knows only:

The proxy never sees message content, metadata, sender identity, or any information about who you communicate with. It simply wakes your device when a new encrypted message is available.

Data Retention

All messages are stored exclusively on your device. You control deletion. We have no servers that store your messages, contacts, or media. When you delete data in the app, it is permanently removed from your device.

Mesh Networking

Hooly can communicate via Bluetooth and Wi-Fi Direct without internet. Messages travel through nearby devices using multi-hop relay. No data passes through any server. Store-carry-forward (DTN) allows message delivery even when recipients are offline for extended periods.

Post-Quantum Encryption

Hooly uses hybrid post-quantum encryption (PQXDH) combining X3DH with ML-KEM-768 (Kyber) to protect against future quantum computer attacks. This hybrid approach ensures your messages are secure both today and in a post-quantum future.

Bot Platform

Bots communicate via the same P2P encrypted channels as regular users. They are indistinguishable from regular Hooly users at the network level. The notification proxy has zero knowledge of whether a participant is a bot or a human.

Stories

Stories are distributed P2P and auto-deleted after 24 hours. They are never stored on any server. Story content is end-to-end encrypted and shared only with your chosen contacts.

Third-Party Services

Hooly uses Firebase Cloud Messaging (FCM) and Apple Push Notification service (APNs) solely for push notification delivery. These services receive only an opaque notification payload — they cannot read your messages.

Children's Privacy

Hooly is not directed to children under 13. We do not knowingly collect information from children. If you believe a child has used our service, please contact us and we will take appropriate action.

Changes to This Policy

We may update this privacy policy from time to time. Changes will be posted on this page with an updated effective date.

Contact

For privacy-related questions, contact us at: privacy@cecats.ru