HopNet is a private, end-to-end-encrypted messenger with no accounts and no phone number. You add contacts in person by scanning their QR code — there is no random matching and no stranger chat. Your messages go directly between devices whenever possible; when your contact is offline, your message waits — still fully encrypted and unreadable to anyone — in a temporary "blind mailbox" until they reconnect. We cannot read your messages, your contacts, or who you talk to: the only thing that ever leaves your phone is encrypted data that no one, including us and our infrastructure providers, holds the keys to.
We do not collect personal information. HopNet has no accounts, asks for no phone number or email, and contains no analytics, no advertising, and no trackers. We do not run servers that can read your data. We use one piece of rented infrastructure — a blind mailbox (see "How messages travel") — which by design holds only encrypted data it cannot decrypt, briefly, and which we cannot use to identify you or map who you talk to.
All of your data is stored locally on your phone: your identity keys (in secure storage), your contacts (added by scanning QR codes), your message history (encrypted at rest), and a local diagnostics log (visible in Settings → Engine Debug) that stays on your device unless you choose to share it. You can erase all of it at any time with Settings → Clear All Data.
HopNet connects your device directly to your contacts' devices over a peer-to-peer network. Messages are end-to-end encrypted (X3DH key agreement and the Double Ratchet, using standard algorithms) so only you and your contact can read them.
Because connections are peer-to-peer, please understand that your IP address is visible to peers you connect to, and is used by the distributed hash table (DHT) to help devices find each other. This is inherent to peer-to-peer networking, the same as other such apps. If you need to hide your IP address, use a VPN or Tor. Other participants in the network can observe connection metadata as in any peer-to-peer system.
If your contact's app is closed when you send, your phone also places the message in a temporary blind mailbox so it arrives the next time they open the app — without both of you needing to be online at the same moment. The mailbox is hosted for us by Cloudflare (acting as a processor). It is "blind" because:
What the mailbox/Cloudflare can technically observe is limited to encrypted blobs, their padded sizes, timestamps, the random box identifiers, and the IP address making the request — never message content, your identity, or your social graph.
The most private way to add a contact is to scan their QR code in person — that exchange never touches any server. For convenience you can also share an invite link. An invite link carries only your public contact information — your display name and public keys (the same data the QR shows). It never contains your private keys or any message, and it cannot be used to read your messages or impersonate you.
By default the invite link is a short, tappable web link: when created, your public contact bundle is stored briefly by our blind-mailbox provider (Cloudflare) under a random identifier and auto-deleted within 30 days. As a result, for invite links the provider can observe that an invite was created and opened, the requester's IP, and your public identity — metadata about an introduction, never message content, private keys, or who you message over time. If you prefer that invites never touch our server, turn on Settings → Private invite links; the link then carries its data only in the part of the URL browsers never send to a server, and the recipient pastes it instead of tapping.
Either way, treat an invite link like a key to your front door: anyone who obtains it — including anyone the link is forwarded to or who sees it in a chat or screenshot — can add you and see your public profile until it expires. Share it only with people you want to be able to reach you.
Camera — to scan a contact's QR code (and, in future, photo/video). Microphone — for future voice/video calls (not yet active). Photo library — to share photos/videos you choose. These are used only for the stated purpose, on your device.
The app keeps a local diagnostic log on your device to help with debugging. If you use Settings → Send Feedback to send a bug report, your message (and, if you leave the toggle on, your app/OS version) is sent by your own email app to support@hopnetapp.com — only when you tap send. Separately, if you have Apple's "Share With App Developers" analytics turned on, Apple may share crash reports with the developer per Apple's own policy.
HopNet is intended for users aged 17 and older and is not directed to children.
We may update this policy; the "effective date" above will change. Material changes will be noted in-app or in release notes.
Questions about privacy: privacy@hopnetapp.com.