Privacy Policy
Effective 2026-10-01
Johdoh (the "Application") is developed by Certo Partners (the "Service Provider"). This policy describes what the Application collects, what it deliberately does not collect, and where the data it does handle is stored.
Johdoh is built so that the Service Provider's servers hold as little about you as the product can function on. Several of the statements below are enforced by the Application's cryptography rather than by policy alone; where that is the case, it is said explicitly.
What the Application does not collect
The Application has no account fields for, and never asks you for, any of the following:
- No email address. There is no email sign-up, sign-in, or recovery.
- No phone number. There is no SMS verification and no telephony provider.
- No real name, date of birth, address, or payment details.
- No contact list, photo library, microphone, or camera access is requested for the purpose of collecting data about you.
- No advertising identifiers, no analytics SDK, and no crash-reporting service. Third-party error reporting was removed from the Application in June 2026 and has not been replaced.
What your account consists of
An account is a username you choose and a public key. When you register, the Application generates a cryptographic key pair on your device. The private key never reaches the Service Provider; the only copy outside the device is the end-to-end encrypted one described below. The Service Provider stores only the username, the corresponding public key, and the times the account was created, updated, and last used.
Because there is no email address or phone number on the account, the Service Provider has no way to identify you personally, and no way to restore access on your behalf.
Your account can follow you to a new phone, through your own Apple or Google account. The private key is held in your device's secure hardware. So that losing the phone does not mean losing the account, the Application also keeps one copy of your keys and your username with your Apple or Google account: in iCloud Keychain on iPhone, and in Google's Block Store on Android. Both are end-to-end encrypted by Apple and Google, so neither company can read the copy. On Android the copy is uploaded to Google only when that end-to-end encryption is available, which requires a screen lock; without one it stays on the phone, and reaches a new one only in a direct phone-to-phone transfer. The Service Provider never receives it.
The consequence is that anyone who controls your Apple or Google account, and can unlock its encrypted storage, could recover your Johdoh account the same way. There is no recovery phrase, and there is nothing the Service Provider can send you or reset. Your connections are not in that copy: the encrypted backup the Application can export preserves them, and it can be restored on any device that holds your key.
Your interests are never sent to the server in readable form
Matching people by shared interests is the core of the Application, and it is done without the Service Provider ever learning what your interests are. The Application uses a cryptographic technique called Private Set Intersection: your interests are transformed on your device into values that cannot be reversed, and only those values are exchanged. The result tells you and the other person how many interests you share, and which ones — while the server sees only opaque data it cannot interpret.
This is a property of the mathematics, not a promise about server configuration. The Service Provider cannot read your interest list even if compelled to try.
Location
The Application uses location to find people near you. Before any location leaves your device it is snapped to a grid of roughly 100 metres; the precise coordinates from your device's GPS are never transmitted.
The Service Provider stores one current position per account, which is overwritten each time it updates. No location history or movement trail is kept. If you enable background location, this continues while the Application is not open; you can disable it at any time in the Application's settings or in your device's system settings.
Aggregate counts of how many people are active in an area are computed using differential privacy — statistical noise is added, and an area is only ever reported at all once enough distinct people are present for no individual to be identifiable from it.
Messages
Direct messages, voice notes, and broadcasts to your connections are end-to-end encrypted. The Service Provider's servers store only ciphertext, addressed by public-key fingerprints, and delete it automatically — 30 days if undelivered, 7 days after delivery. The Service Provider does not hold the keys for these and cannot read their content.
Echoes are different, and are not private. An Echo — the short anonymous note you can leave at a location — is encrypted with a key derived from your community's public join code, which means the Service Provider can read Echo content, and so can anyone who holds that code. The interest tags attached to an Echo are likewise recoverable by anyone who receives it. Echoes carry no author record, so they are not linked to your account, but you should treat the text and tags of an Echo as public. Do not put anything in an Echo you would not post publicly.
Notifications
If you enable push notifications, the Application stores a push token so it can alert you to a match or a message. Delivering a notification necessarily involves your device's platform operator — Apple on iOS and Google on Android — and the Expo push service, which relays to them. Notification payloads are kept minimal and do not contain message content or interest names. You can disable notifications at any time in your device's system settings.
Communities
Johdoh is used through communities — an event, an organisation, or a venue. Your username and shared-interest results are visible to other members of a community you have joined, within the discovery radius that community configures. Community administrators can see the member list for their community — usernames, public keys, when each account joined, and when it was last active — along with activity totals and daily activity over time. If you file a report, the administrators of that community can read it, including anything you type into it. They cannot see your interests, the content of your direct messages, or your precise location.
What the servers necessarily learn
Some information cannot be hidden from a server that has to route between people. Being explicit about it is more useful than a blanket claim:
- Who interacted with whom. Waves, Spark signals, blocks, and reports are stored with both accounts named. So is the fact that two accounts were physically near each other, and when.
- Your approximate location while discovery is on — snapped to a grid of roughly 100 metres, stored as your current position and updated in place.
- Your IP address and device type, recorded against safety-related events such as blocks, and used to rate-limit abuse.
- The text of any report you file, stored unencrypted and readable by the administrators of that community and by the Service Provider.
Where data is processed
The Application's backend runs on cloud infrastructure operated by the Service Provider's hosting providers, and traffic is served through Cloudflare. These providers process data on the Service Provider's behalf as infrastructure operators. No data is sold, rented, or shared with advertisers, data brokers, or analytics companies — the Application contains no such integrations.
Retention and deletion
- Messages are deleted automatically 30 days after being sent.
- Location is a single current value that is overwritten, not accumulated.
- Your account. Account deletion from within the Application is not yet available. Uninstalling stops all further collection and destroys the private key, after which the account can never be used again — but the username, public key, and last-known grid position remain on the server. To have those erased, contact the Service Provider at the address below; because your device can prove control of the account by signing a challenge, an erasure request can be verified without any identifying information. Building this into the Application is tracked work.
- Interests, contacts, and message history stored on your device are removed when you uninstall the Application.
Children
The Application is not directed at children under 13, and the Service Provider does not knowingly collect information from them. Because no identifying information is collected, the Service Provider cannot determine a user's age. A parent or guardian who believes a child has used the Application should uninstall it, which stops all further collection, and contact the Service Provider at the address below to have the remaining account record erased.
Your rights
Depending on where you live, you may have rights to access, correct, export, or erase personal data held about you. In Johdoh's case, the practical answers are: the data held is your username, public key, one coarse current location, and undelivered ciphertext; erasure is available directly in the Application via account deletion; and the Service Provider cannot connect an account to a real-world identity in order to answer a request about a specific person, so requests should be made from within the Application itself.
Changes to this policy
This policy may be updated as the Application changes. Material changes will be reflected in the effective date above and, where they affect what is collected, surfaced in the Application.
Contact
Questions about this policy can be sent to [email protected].