Privacy
Kafumu is built so that we know as little as possible. What we don't have, we can't leak, sell or hand over.
On your device only
Your cards and personas, the people you've connected with, your notes and tags about them, the keys of each connection, and where you've checked in. None of it is sent to us unencrypted. Your location becomes a ~5 km #geo cell on your phone; coordinates never leave it.
What our server keeps
| What | Why | Kept |
|---|---|---|
| Account: random id, a hash of your sign-in key, the name you choose | To sign you in and show your name | Until you delete it; unused accounts are removed |
| Findable profile (only if you switch it on): languages, interests, one line, where to find you, one area | So people nearby can find you | Visible for at most a week; you can hide it any time |
| Meetups you host, and a count of who's going | So others can find and join them | Until a day after the meetup ends |
| Encrypted messages between connected phones (cards, signals) | To deliver them; we can't read them | Until read, at most 7 days |
| Random-looking codes for “friends around” | So your connections — and only they — can tell you were nearby | 8 days |
| Request logs (address, page) | To keep the service running | As briefly as Google App Engine allows |
What we never have
Your coordinates. Who you're connected with. Your contacts' details. What matched you in your list — that ranking happens on your phone. No third-party trackers, no ad networks.
Honest caveats
A connect code holds a one-time key in the link; some QR-scanner apps keep a history, so scan with your camera app. Browsers can delete site data (Safari after a week without visits) — install Kafumu to your home screen and keep a backup. Posts you make on Bluesky are public there, not here.
You can see, export and delete everything we hold about you from your account. Account · Contact