Legal
Privacy Policy
What the app does with your information — and what it's built not to do.
Pre-publication draft: account deletion, backend erasure and a final retention schedule are release blockers. This policy must be updated and approved before the app is made public.
In one paragraph
Our Little Place does not ask for your name, email address or phone number. It assigns your installation a pseudonymous service account. The text of your messages, your photos and videos, your calls, your album names and your display names are end-to-end encrypted, so we and our providers cannot read them. The backend stores an encrypted copy of that data so it can sync between your two phones, plus a small amount of routing information — who is paired with whom, delivery ticks, a push token, and call start and end times. There is no advertising, analytics or tracking anywhere in the app.
1. The short version
- You do not sign up with personal details. The app assigns your installation a pseudonymous account identifier.
- Message text, photos, videos, voice notes, files, shared locations and contacts, album names, display names, and the audio and video of your calls are end-to-end encrypted. Only your two phones can read them.
- The backend stores an encrypted copy of that data to sync your phones, plus routing metadata (pairing, delivery state, a push token, call lifecycle times).
- Setting up calls and rooms, and all network traffic, reveals technical metadata (IP addresses, timing) to our servers and providers. That part is not end-to-end encrypted.
- No ads. No analytics. No trackers. No cookies in the app.
- You can unpair at any time. Account deletion and complete backend erasure are not finished in the current development build and must be completed before public release.
2. Who is responsible
Our Little Place is published by MissingLayer B.V., Korte Lijnbaanssteeg 1/4570, 1012 SL Amsterdam, Netherlands, KVK 97964840 ("we", "us"). For anything in this policy, write to [email protected].
Where data-protection law applies, we are the controller for the choices Our Little Place makes about processing, including operation of our backend and our call server. Our providers act as our processors, except where noted below.
3. What we built the app not to see
The following is encrypted on your device with keys that exist only on your two phones. We keep an encrypted copy purely so it can move between your devices. We cannot decrypt it, and neither can any of our providers:
- the text of your messages, and message reactions, replies and pins;
- photos, videos, voice notes and files you send, and their thumbnails;
- the display name each of you chooses;
- the names of your albums and which media is in them;
- contact cards and map locations you share;
- the audio and video of your voice calls, video calls and the door;
- the in-app record of your call history.
4. What the service holds, and why
To pair your phones and carry messages and calls between them, our backend processes:
- An anonymous device account. Created the first time you open the app — a random identifier and cryptographic keys, with no name, email or phone number. Two accounts that pair become one couple.
- Pairing data. A six-character pairing code (single use, valid one hour, rate-limited and not searchable), public keys, and an encrypted exchange of your chosen display names.
- Encrypted content. The scrambled messages, events and media objects from section 3, plus a server-side ledger that stops the same message being delivered twice.
- Delivery state. Whether a message has reached the other phone and been opened, so the app can show sending, delivered and read marks.
- A push token. A Firebase Cloud Messaging identifier for your device, so we can wake the app when a message or call arrives.
- Call and room metadata. For each call or door session: an identifier, whether it is voice or video, which two accounts took part, the start and end times, and how it ended (answered, missed, declined, cancelled or failed). The media itself is end-to-end encrypted.
- Network information. Like any internet service, our servers and providers receive your device's IP address and connection timing. The call server also sees when a session starts and ends and whether a microphone or camera is in use.
Legal basis (GDPR). Performance of our contract with you (Art. 6(1)(b)) — delivering the messaging and calling service — and our legitimate interests (Art. 6(1)(f)) in operating it securely and preventing abuse.
5. Who your phone talks to
We use a small number of providers. We do not sell personal data, and there is no data broker, ad network or third-party analytics service in the app.
- Supabase — Central EU (Frankfurt)
- DoesOur database, pseudonymous sign-in, encrypted file storage and server functions. The current hosted project is in the
eu-central-1region. - Can seeThe pseudonymous account and the encrypted content and metadata in section 4 — not the content itself.
- Google — Firebase Cloud Messaging
- DoesDelivers push notifications to wake your phone.
- Can seeYour device push token and a short routing payload (message type, call identifier, event). Never message text, names, media, keys or call tokens.
- Google — Maps SDK for Android
- DoesDraws the map when you open the location picker or view a location someone shared.
- Can seeThe coordinates, sent directly from your device to Google to render the map. No map image passes through our servers. Google's terms and privacy policy apply.
- LiveKit, run by us on Microsoft Azure
- DoesRelays the encrypted media and the signaling for voice, video and the door. We operate the server ourselves on an Azure VM in the "West Europe" region.
- Can seeIP addresses, which accounts are connected, session timing, and whether audio or video tracks exist. It cannot decrypt the media.
- Apple App Store / Google Play
- DoesDistribution and updates.
- Can seeYour download and, if you opted in at the operating-system level, crash and performance diagnostics. We add no separate analytics or crash-reporting code.
- Microsoft Azure — website
- DoesServes this static site from the same West Europe infrastructure as our self-hosted call relay.
- Can seeYour IP address and request information needed to deliver and protect the site. See section 11.
Apple and Google act under their own privacy notices for their app stores, device accounts and any diagnostics you choose to share with them. Google may also act independently when its Maps SDK receives coordinates to render a map.
6. Storage, retention and deletion
Current development behavior. The production retention and deletion lifecycle is not complete, so the app must not be released publicly on the promises in this section yet:
- Encrypted messages, shared-state events and media are stored in the Supabase project. Delivery and read receipts do not currently trigger automatic server deletion.
- Delete for me hides an item for that installation. Delete for both currently records a server tombstone, but complete erasure of the encrypted message and related media object is still unfinished.
- Pairing codes stop working after one hour. The database rows for expired sessions and unused pseudonymous accounts do not yet have a verified automatic cleanup schedule.
- Call and room lifecycle metadata remains on the server. A fixed retention period still has to be implemented and documented.
- Unpairing immediately revokes the couple and removes shared keys from the initiating device; the partner clears them when it learns of the revocation. Unpairing does not currently erase the couple's existing server rows or stored encrypted media.
- Deleting the app removes that installation's local app data and keys, but does not by itself erase server data.
Account-erasure requests. Development testers may ask us to erase their pseudonymous account and associated backend data by emailing [email protected]. We may need information from the app to verify control of the pseudonymous account. A clear in-app deletion control and a tested server-side cleanup process are required before public release.
International transfers. The primary Supabase project is in Frankfurt, Germany, and the self-hosted LiveKit relay and website are in Microsoft's Azure West Europe region. Google, Apple, Microsoft and Supabase may process limited service or diagnostic data in other countries. Where we make a restricted transfer from the EEA, we rely on an applicable adequacy decision or approved safeguards such as the European Commission's Standard Contractual Clauses.
7. No advertising, analytics or tracking
The app contains no advertising SDK, no behavioural analytics, no session-replay tool and no third-party content-moderation service. We do not build a profile of you, track you across other apps or websites, or use cookies inside the app. Our server logs and crash reports are stripped of message text, media, filenames, album names, pairing codes, tokens and keys.
We do not use your data for automated decisions that produce legal or similarly significant effects.
8. Notifications
Push notifications are delivered through Firebase Cloud Messaging. What appears on your screen is deliberately plain: "New message" or "New photo or video", for calls "Incoming private call" or "Incoming private video call", and for an ambient room "A private room is open". No partner name, message text, thumbnail, filename or album change is shown in a notification.
9. Permissions on your device
The app asks for a permission only when you use the feature that needs it. Content selected for sharing stays on your device or inside the end-to-end-encrypted conversation, except for the map disclosure described in section 5:
- Camera and microphone — for photos and videos you capture, voice notes, calls and the door.
- Contacts — when you open the in-app contact picker, the app reads names and phone numbers from the device so it can show the list. Only the contact you select is placed in the encrypted message; the rest are not uploaded.
- Location — only when you choose to share a location, to drop a pin. It is not tracked in the background.
- Notifications — to let you know about messages and calls.
- Nearby devices / Bluetooth — to route call audio to a headset or other audio device you already connected. The app does not use Bluetooth for advertising or contact discovery.
- Call integration — Android's telecom system coordinates Our Little Place calls with other calls. The app does not read your phone number or call log.
- Fingerprint, face or device PIN — checked by Android or iOS to unlock the app. The app never sees your biometric data.
The app does not request broad access to your photo library.
10. Encryption, and the limits of it
New chat-message envelopes use an Olm Double-Ratchet session established between your two devices through keys signed by the identity you verify when pairing. Media objects, album events, and call and room media use separate keys derived on your devices from the shared conversation root. Sensitive key material and ratchet state are held in encrypted device storage, hardware-backed where the device supports it, and kept out of ordinary backups.
Being straight about what this does not yet do:
- The Olm primitive comes from the vodozemac library, but our key distribution, session lifecycle and app integration have not had an independent cryptographic audit. Please don't treat Our Little Place as Signal-compatible or equivalent to an independently audited messenger.
- The ratchet improves protection for new chat messages as keys advance. Media files, albums, calls and rooms still derive their encryption from the static conversation root and do not yet have forward secrecy or post-compromise security. Compromise of that root could expose the content protected by keys derived from it.
- End-to-end encryption cannot protect content already visible on or exported from an unlocked or compromised device.
- Call and room signaling — the part that sets up a session — and all network metadata are not end-to-end encrypted. The call server and the network can see that a session happened, between which accounts, when, and whether audio or video was used.
We will update this section as the cryptography is reviewed and improved, and before we make any stronger public claim.
11. This website
ourlittleplace.app is a static site with no accounts, cookies or analytics. Fonts are system fonts, so nothing is loaded from a font provider. Microsoft Azure infrastructure necessarily processes your IP address and request metadata to deliver the site and may retain limited operational or security logs under our configured settings.
12. Children
Our Little Place is for adults in a relationship. You must be 18 or older to use it. It is not directed to children, and it has no public content, profiles or discovery features. If you believe someone under 18 is using it, contact us.
13. Your rights
Under the GDPR and similar laws you may have the right to access, correct, delete, restrict or object to the processing of your personal data, and to receive a portable copy. Because we hold so little:
- Access and portability. Your messages, media and albums are readable in the app while your installation has the required keys. We can tell you which pseudonymous account and metadata exist for you after verifying control.
- Deletion. You can unpair in the app. Until the account-deletion flow is finished, ask us to erase backend data using the address in section 6. Content already stored on your partner's device is also under their control.
- Objection and restriction. You can stop using network features, or stop using the app.
- Complaints. You may complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or to the supervisory authority where you live or work.
To make a request, write to [email protected]. We aim to respond within 30 days and may need to confirm that you control the relevant device or account.
14. Changes to this policy
If we change this policy we will update the date above and, for significant changes, give notice in the app or on this page. A privacy notice describes our processing; it is not a request to waive your rights. If a change requires consent, we will ask for it separately.
15. Contact
MissingLayer B.V.Korte Lijnbaanssteeg 1/4570
1012 SL Amsterdam, Netherlands
KVK 97964840
[email protected]