Nome
Menu

PRIVACY / PRINCIPLES

Privacy principles

We do not require a phone number, we do not create a public user ID, and we do not put your core data into a cloud account.

  • No phone number
  • No public ID
  • Device-held data
Privacy & identityN

LOCAL IDENTITY

Your identity belongs to you

Profile data stays on this device instead of a public account.

N

My NomeStored on this device

Local

No phone number collectedConnect through invitations

No public user IDNo shared account to search

Data held by your deviceYou decide when to back up

Create a local identity

Every relationship remains separate

Privacy overview

You control identity, not assumptions

Privacy comes from local identity, separate connections, and minimal exposure.

Network privacy and identity privacy stay separate.

Privacy principles

Two separate identity systems

Chat identity lives in the app and chat data layer. Website email belongs only to the invite application flow. It does not become a public chat ID or affect public downloads.

Chat does not require a public ID

Nome chat connections start from chat invites you create or accept, not a searchable phone number or public user directory.

Minimum invite-system data

The application system processes email, country or region, platform, purpose, optional referral source, application status, invite status, and necessary security audit data.

The console cannot see chats

The admin console has no access to chat content, contacts, groups, chat invites, SMP/XFTP queues, or communication relationship graphs.

Tokens and invites are stored as digests

Email tokens, admin sessions, and Nome invites are stored as non-recoverable digests. A full invite is shown only once when issued.

Minimized security logs

Application abuse controls and necessary security records keep only required events and server-keyed IP and user-agent digests, not long-term raw IP profiles.

Retention, deletion, and anonymization

One-time links expire automatically. Application and audit records are retained only for invite operations, disputes, and recovery. The console supports minimum exports and application anonymization or deletion.

What you will and won't see

The console may show

Application email and region, request time and state, invite state, device count, coarse last-active date, and reserved payment status.

The console must not see or store

Chat messages, contacts, group members, chat-invite links, communication relationships, raw hardware identifiers, server private keys, or complete communication-server credentials.