OurSpace Privacy Policy

Effective: August 14, 2026

The short version

  • We don't run ads, we don't sell data, and there are no third-party trackers in the app or on this website.
  • Your private messages are end-to-end encrypted. We store ciphertext we cannot read.
  • Your posts, comments, and profile are social content — they are not end-to-end encrypted, and are visible according to the audiences you choose.
  • We collect the minimum needed to run the service, and we tell you exactly what that is below.
  • You can export your data and delete your account yourself, in the app, at any time.

Who we are

OurSpace is a small, independent social app built and operated by one person. You can reach the operator at contact@joinourspace.org.

OurSpace is in early beta. It is real software run by one person, and this policy describes what the system actually does — not aspirations.

What we collect, and why

Account information. When you sign up we collect your email address, a display name, a handle, and a password. Passwords are stored only as salted hashes — we cannot see them. If you joined through an invite, we record which invite code you used.

Profile. Your bio, avatar, profile theme, and profile song are profile content you choose to share. They are visible to other people according to the app's rules.

Social content. Posts (text, photos, videos, links), comments, reactions, ratings, and community groups are stored on our server so we can show them to the audiences you pick. Social content is not end-to-end encrypted — the server processes it to build feeds, previews, and search.

Private messages. One-to-one and group chats are end-to-end encrypted using the Signal protocol (via libsignal). Message text, voice messages, and attachments are encrypted on your device before they reach us; the server stores only ciphertext and cannot read it. To deliver messages, the server does handle conversation metadata: who is in a conversation, when messages were sent, and a group chat's name and photo (which are set in plaintext). We work to keep that metadata to the minimum the service needs.

Encrypted backups. Message backup is optional. Backups are encrypted on your device with a key derived from your recovery code. The recovery code never leaves your device and we never receive it — which means we cannot read your backups, and we also cannot recover them if you lose the code. You can delete your backups at any time.

Push notifications. Pushes are content-free. A notification never contains message text — only a signal that wakes the app so it can fetch and decrypt on your device. Delivery rides Apple's push service (APNs) and Google's Firebase Cloud Messaging, which handle a device token for routing.

Waitlist. If you join the waitlist on this site, we store your email address — nothing else. We use your IP address transiently to rate-limit submissions; it is not stored with your email.

Server logs. Like nearly every server on the internet, ours keeps standard access logs (IP address, requested endpoint, timestamp) for security, debugging, and abuse prevention. They are not used for profiling or marketing.

What we don't do

No advertising. No selling or sharing data for money. No analytics SDKs, tracking pixels, or third-party scripts — in the app or on this website (this page loads nothing from any server but ours). No engagement-ranked feed: you see your friends' posts, newest first. And we cannot read your private messages, because the system is built so that we can't.

Third-party services

We use a small number of providers, each for one job:

  • Apple APNs / Google Firebase Cloud Messaging — deliver content-free wake notifications to your device.
  • Resend — sends transactional email, such as password-reset codes, to your address.
  • GIPHY — only when you search for a GIF or sticker, your search terms and IP address go to GIPHY to fetch results. GIFs you receive in messages come from our server as encrypted attachments and never touch GIPHY.
  • TestFlight / Firebase App Distribution — beta installs are delivered through Apple's and Google's distribution services under their own policies.

We have no other data-sharing relationships.

Retention and deletion

Your content stays until you remove it. You can delete individual posts and messages, use disappearing messages to remove chat content automatically on a timer, and delete your backups whenever you like. Deleting your account — available in the app under Settings — permanently removes your account and content from our server. One narrow exception: reports filed through the in-app safety tools may be retained after the accounts involved are deleted, so abuse can't be erased by deleting the account that did it.

Your rights

You can do most of this yourself, in the app: export a copy of your data, correct your profile information, and delete your account. If you are in the EU/EEA or UK, you additionally have the rights the GDPR gives you — access, rectification, erasure, portability, restriction, and objection — and the right to complain to your supervisory authority. For anything you can't do in-app, email contact@joinourspace.org and a human (the only human here) will handle it.

Age

OurSpace is not directed at children and is not for anyone under 18. If we learn an account belongs to someone under that age, we will delete it.

Security

Private messages are end-to-end encrypted with the Signal protocol. Passwords are hashed. All traffic uses TLS. Backups are client-side encrypted with a key we never hold. That said: this is early-beta software maintained by one person. If you find a security problem, please tell us at contact@joinourspace.org — we take reports seriously and will respond honestly.

Changes to this policy

If this policy changes, we'll update this page and its effective date. If a change is material, we'll say so in the app. We will never quietly weaken what this document promises.

Contact

contact@joinourspace.org