Effective date: July 26, 2026 Last updated: 2026-07-19
CHRP Communications Inc. ("we", "us") makes CHRP. This policy explains what CHRP does with your information. It is short because CHRP collects very little.
#The short version
- CHRP has no accounts. No email, no phone number, no username, no password, no sign-in.
- We cannot read your messages or hear your voice. Everything you send is end-to-end encrypted between your device and your contact's device. We hold no key that can open it.
- Most of the time, nothing touches our servers at all. CHRP is built to connect your devices directly — over Wi-Fi, peer-to-peer radio, or Bluetooth. Our relay is a fallback, not the default path.
- We do not track you, and we do not have advertising. There are no third-party analytics or advertising SDKs in CHRP.
- We do not sell or share your personal information as those terms are defined by the California Consumer Privacy Act, and we never have.
#1. Your identity in CHRP
When you first open CHRP, your device generates a random identifier and a cryptographic key pair. The private key is created and stored inside your device's Secure Enclave and never leaves it. We do not assign you an identity, we do not see it created, and we hold no registry of users.
You choose a display name. That name is stored on your device and is sent to the contacts you pair with, so they know who you are. It is not sent to us.
Contacts are added by physical proximity — tapping devices together with NFC, holding them near each other with Ultra Wideband, scanning a code, or opening a CHRP Link. There is no directory, no discovery of strangers, and no way to be contacted by someone you have not explicitly paired with.
#2. What stays on your device
Your conversations, voice messages, photos and files, contacts, group memberships, app settings, and your Chrpi companion's state are stored on your device only.
CHRP includes a message-retention setting that can automatically delete conversation history. Deleting a conversation, a contact, or the app itself removes that data from your device. We have no copy to delete on your behalf, because we never received one.
#3. What we do receive
CHRP contacts our servers in a small number of specific situations.
#3.1 Push notification tokens
So a contact can reach you when CHRP is closed, your device gives us an Apple Push Notification service token. We store it, associated with your CHRP identifier, so we can route a wake-up signal to the right device. Tokens are rotated by Apple and expire. They contain no personal information and cannot be used to read anything on your device.
The notifications themselves carry no message content — only a signal that someone is trying to reach you, and the display name your contact chose to show.
#3.2 Relayed traffic
When CHRP cannot reach your contact directly — no shared Wi-Fi, out of radio range — it falls back to relaying through our server. Relayed traffic is already encrypted before it leaves your device and is forwarded without being stored. We can see that two identifiers exchanged data and roughly how much. We cannot see what it was. We do not keep message logs.
#3.3 Safety reports you choose to file
If you report someone for a safety concern, what we receive depends on what you report:
- Routine reports (harassment, spam, unwanted contact) are content-blind. We receive the reported person's public key, the category you selected, and a timestamp. We do not receive your messages, your identity graph, or anything else.
- Serious reports (child safety, credible threats of violence, human trafficking) may include the conversation transcript, if and only if you choose to attach it. You select which messages to highlight. That transcript is encrypted on your device to an offline review key before it is sent — our servers cannot open it. It is decrypted only on an air-gapped machine by a human reviewer.
Reports are one-way by design: no part of our system can return a report to the person who filed it.
Where a report gives us actual knowledge of child sexual abuse material, United States law (18 U.S.C. § 2258A) requires us to report it to the National Center for Missing & Exploited Children, and to preserve the associated material. We comply with that obligation.
#3.4 Beta diagnostics — TestFlight only
Pre-release builds distributed through TestFlight include a feedback system: a bug-report button, crash and hang reports, and basic performance metrics. If you file a bug report, it includes a screenshot taken at the moment you tapped the button and, optionally, a diagnostic log — you see and confirm both before anything is sent.
This system is disabled in App Store builds and cannot be enabled. If you installed CHRP from the App Store, none of this applies to you.
#4. Permissions CHRP asks for, and why
| Permission | Why |
|---|---|
| Microphone | Push-to-talk, voice messages, voice commands, audio in videos |
| Camera | Taking photos and video to send in chats |
| Bluetooth | Reaching nearby contacts when Wi-Fi and internet are unavailable |
| Local network | Connecting to contacts on the same Wi-Fi, for lower latency |
| NFC | Exchanging pairing codes by tapping devices together |
| Ultra Wideband (Nearby Interaction) | Detecting that two devices are being held together to pair |
| Photo library (add only) | Saving images you receive to your camera roll |
| Speech recognition | Understanding voice commands. Processed for command recognition only |
| HomeKit | Controlling your own lights, locks, and thermostats hands-free during a call |
| Location (when in use) | Only attached to an SOS or a check-in that you initiate. Never captured in the background, never during ordinary calls |
| Notifications | Alerting you that a contact is reaching you |
Every one of these is optional at the operating-system level. CHRP degrades rather than refusing to run — for example, declining Bluetooth removes the offline mesh path but leaves Wi-Fi and relay working.
#5. Encryption
CHRP encrypts communication end-to-end using the Noise Protocol Framework (Noise_XX) with X25519 key agreement and authenticated encryption. Keys are negotiated directly between devices. We do not escrow keys, we do not hold a master key, and there is no mechanism by which we could decrypt your communication if compelled to.
#6. Children
CHRP is not directed at children under 13, and we do not knowingly collect personal information from them. Because CHRP has no accounts, we hold no age information and no profile that could identify a child. If you believe a child has been harmed through CHRP, use the in-app safety report or contact [email protected].
#7. Retention
| Data | How long we keep it |
|---|---|
| Push notification token | Until it expires, is replaced, or you uninstall |
| Relayed traffic | Not stored. Forwarded and discarded |
| Routine safety report | Not retained as a record |
| Serious safety report | Only while the case is active; purged when closed as unfounded. Material subject to a legal preservation obligation is retained as the law requires |
| Beta diagnostics (TestFlight only) | 30 days, then deleted from our server |
#8. Your rights
Because CHRP has no accounts, we generally hold nothing that identifies you, which limits both what we can disclose and what we can delete. What we can do:
- Access / portability — we can tell you whether we hold a push token for a device identifier you can demonstrate control of.
- Deletion — uninstalling CHRP invalidates the push token. You can also ask us to delete it at [email protected].
- Objection / restriction — you can disable notifications, which stops us receiving a token at all, and you can point CHRP at your own relay server in Settings, which removes us from the path entirely.
If you are in the European Economic Area or the United Kingdom, our lawful basis for processing a push token is legitimate interest in delivering the messaging function you asked for, and for safety reports, compliance with a legal obligation and the substantial public interest in preventing harm. You have the right to lodge a complaint with your national data protection authority.
If you are a California resident: we do not sell or share personal information, we do not use it for cross-context behavioural advertising, and we do not knowingly do either for anyone under 16.
#9. Service providers
Our relay and push infrastructure runs on Railway and uses Apple's Push Notification service. They process the limited data described in §3 on our instructions. We use no analytics, advertising, attribution, or tracking providers of any kind.
#10. Changes
If we change this policy materially, we will update the effective date and, where the change affects how CHRP handles your data, surface a notice in the app. Continuing to use CHRP after a change means you accept the updated policy.
#11. Contact
CHRP Communications Inc. 400 Rella Blvd, Ste 207 #5168, Montebello, NY 10901 Privacy: [email protected] Safety: [email protected] Support: [email protected]