Privacy Policy
Effective 2026-08-05
Johdoh (the "Application") is developed by Certo Partners (the "Service Provider"). This policy describes what the Application collects, what it deliberately does not collect, and where the data it does handle is stored.
Johdoh is built so that the Service Provider's servers hold as little about you as the product can function on. Several of the statements below are enforced by the Application's cryptography rather than by policy alone; where that is the case, it is said explicitly.
What the Application does not collect
The Application has no account fields for, and never asks you for, any of the following:
- No email address. There is no email sign-up, sign-in, or recovery.
- No phone number. There is no SMS verification and no telephony provider.
- No real name, date of birth, address, or payment details.
- No contact list, photo library, microphone, or camera access is requested for the purpose of collecting data about you.
- No advertising identifiers, no analytics SDK, and no crash-reporting service. Third-party error reporting was removed from the Application in June 2026 and has not been replaced.
What your account consists of
An account is a username you choose and a public key. When you register, the Application generates a cryptographic key pair on your device. The private key never leaves the device. The Service Provider stores only the username, the corresponding public key, and the times the account was created, updated, and last used.
Because there is no email address or phone number on the account, the Service Provider has no way to identify you personally, and no way to restore access on your behalf. Recovery works from a recovery phrase shown to you once at registration. If you lose both your device and that phrase, the account cannot be recovered by anyone, including the Service Provider.
Your interests are never sent to the server in readable form
Matching people by shared interests is the core of the Application, and it is done without the Service Provider ever learning what your interests are. The Application uses a cryptographic technique called Private Set Intersection: your interests are transformed on your device into values that cannot be reversed, and only those values are exchanged. The result tells you and the other person how many interests you share, and which ones — while the server sees only opaque data it cannot interpret.
This is a property of the mathematics, not a promise about server configuration. The Service Provider cannot read your interest list even if compelled to try.
Location
The Application uses location to find people near you. Before any location leaves your device it is snapped to a grid of roughly 100 metres; the precise coordinates from your device's GPS are never transmitted.
The Service Provider stores one current position per account, which is overwritten each time it updates. No location history or movement trail is kept. If you enable background location, this continues while the Application is not open; you can disable it at any time in the Application's settings or in your device's system settings.
Aggregate counts of how many people are active in an area are computed using differential privacy — statistical noise is added, and an area is only ever reported at all once enough distinct people are present for no individual to be identifiable from it.
Messages
Direct messages and broadcasts are end-to-end encrypted. The Service Provider's servers store only ciphertext, addressed by public-key fingerprints, and delete it automatically 30 days after it is sent. The Service Provider does not hold the keys and cannot read message content, attachments, or voice notes.
Notifications
If you enable push notifications, the Application stores a push token so it can alert you to a match or a message. Delivering a notification necessarily involves your device's platform operator — Apple on iOS and Google on Android — and the Expo push service, which relays to them. Notification payloads are kept minimal and do not contain message content or interest names. You can disable notifications at any time in your device's system settings.
Communities
Johdoh is used through communities — an event, an organisation, or a venue. Your username and shared-interest results are visible to other members of a community you have joined, within the discovery radius that community configures. Community administrators can see aggregate, differentially-private activity for their community. They cannot see your interests, your messages, or your precise location.
Where data is processed
The Application's backend runs on cloud infrastructure operated by the Service Provider's hosting providers, and traffic is served through Cloudflare. These providers process data on the Service Provider's behalf as infrastructure operators. No data is sold, rented, or shared with advertisers, data brokers, or analytics companies — the Application contains no such integrations.
Retention and deletion
- Messages are deleted automatically 30 days after being sent.
- Location is a single current value that is overwritten, not accumulated.
- Your account — username, public key, and everything linked to it — is deleted when you delete the account from within the Application. Deletion is immediate and cascading; there is no recovery window, because there is no identifier the Service Provider could use to verify a later restoration request.
- Interests, contacts, and message history stored on your device are removed when you uninstall the Application.
Children
The Application is not directed at children under 13, and the Service Provider does not knowingly collect information from them. Because no identifying information is collected, the Service Provider cannot determine a user's age. A parent or guardian who believes a child has used the Application should delete the account from within the Application and may contact the Service Provider at the address below.
Your rights
Depending on where you live, you may have rights to access, correct, export, or erase personal data held about you. In Johdoh's case, the practical answers are: the data held is your username, public key, one coarse current location, and undelivered ciphertext; erasure is available directly in the Application via account deletion; and the Service Provider cannot connect an account to a real-world identity in order to answer a request about a specific person, so requests should be made from within the Application itself.
Changes to this policy
This policy may be updated as the Application changes. Material changes will be reflected in the effective date above and, where they affect what is collected, surfaced in the Application.
Contact
Questions about this policy can be sent to [email protected].