Privacy Policy
hoppin is built so that there is very little to write down here. This page says exactly what does exist.
Last updated: 27 September 2026
Who is responsible
hoppin (“the app”) is made by Rodrigo Loução, an individual developer based in Portugal (“we”, “us”). Under the EU General Data Protection Regulation (GDPR), we are the controller of the personal data described below. Write to rodrigoloucao570@gmail.com about anything on this page.
The short version
- Your messages and photos are end-to-end encrypted on your phone. We cannot read them, and we never receive a key that could.
- Your conversations are stored on your phone only, and are left out of iCloud and computer backups.
- Our server knows your phone number, because it verifies it and delivers messages to it. It sees the network address you connect from, but doesn’t store it.
- Many messages never reach our server: on the same Wi-Fi, directly across the internet, or over Bluetooth between nearby phones. When a message does wait on our server, it waits as ciphertext, for at most 7 days.
- No analytics, no tracking, no advertising and no third-party code, in the app or on this website.
What we process, and why
Your phone number
To use hoppin you verify one phone number with a code sent by SMS. We keep the number so we can issue your identity certificate and deliver messages to you. Verification codes are stored only as a salted hash, expire after ten minutes and never appear in our logs. Phone numbers appear in our logs only masked, for example +35191*****78.
Legal basis: performing our agreement with you (Article 6(1)(b) GDPR).
Your public keys and identity certificate
Your phone makes its own keys and sends us only the public halves. We sign a certificate that ties your number to those public keys, and hand it to people who want to message you. Your private keys are made on the phone, kept in the iOS Keychain, and never sent to us or anyone else.
Legal basis: performing our agreement with you (Article 6(1)(b) GDPR).
Network address and connection details
When your phone connects to our server, we necessarily see its IP address. We hold it in memory to apply rate limits that keep the service up and hard to abuse. It is not written to our logs or kept.
We also see when a message is deposited or collected, how large it is and which number it is for, but never what it says.
Legal basis: our legitimate interest in running a secure, available service (Article 6(1)(f) GDPR).
Messages waiting for delivery
When hoppin can’t reach the other phone any other way, the encrypted message waits on our relay. It is stored as ciphertext and deleted as soon as the other phone collects it, or after 7 days at the latest. We cannot decrypt it at any point.
Legal basis: performing our agreement with you (Article 6(1)(b) GDPR).
Direct delivery across the internet
When both phones can reach each other directly, hoppin sends the message straight from one to the other instead of through our relay. To make that possible, your phone tells the people you message how to reach it: its network address, which roughly reveals your city and internet provider. That address travels inside your encrypted messages, so only your contacts learn it, and our server never sees it. It’s on by default. Turn it off in Settings › Privacy & Security › Direct delivery to send everything through the relay instead.
Bluetooth, with no internet
When your phone has no internet connection and the Bluetooth mesh is on, text messages can be passed between nearby hoppin phones until one reaches the person they’re for. What those phones carry is sealed: it has no sender and no recipient written on it, and they can’t read it. Your phone may carry sealed messages for other people in the same way. Nothing is carried for more than 24 hours, and none of this involves our server. Photos never travel this way. Turn it off in Settings › Bluetooth mesh.
Notifications
If you allow notifications, iOS gives your phone a push token, and your phone gives it to our server so we can ask Apple to wake it when a message arrives. The notification we send says only that something arrived. It contains no sender, no text and nothing about the message. Your phone fills in the details itself after decrypting. Turning notifications off in hoppin deletes the token from our server.
Legal basis: performing our agreement with you (Article 6(1)(b) GDPR).
Reports of abuse
If you report someone, we receive their phone number, your phone number, the reason you give, and any messages you choose to attach (up to 20). Attaching messages is your choice. When you do, those messages reach us in readable form so that we can act on the report. We use reports to investigate abuse and to suspend or close accounts.
Legal basis: our legitimate interest, and that of other users, in preventing abuse and keeping hoppin safe (Article 6(1)(f) GDPR).
Crash reports
If you have turned on sharing with app developers in iOS Settings, Apple may pass us anonymous crash and performance reports. They contain no message content and are covered by Apple’s own privacy terms.
What we don’t collect
- Message content. Text and photos are encrypted on your phone before they leave it. We only ever hold ciphertext.
- Your contacts. Your address book is never uploaded. The app only asks our server about a number when you actually want to message it.
- Your message history. Conversations live in the app’s own storage on your iPhone, protected by iOS data protection and left out of backups.
- Your profile. Your name and photo go only to the people you talk to, inside encrypted messages.
- Analytics, tracking or advertising data. Neither the app nor this website contains analytics, trackers, ads or third-party scripts. This website sets no cookies.
- Your location, email address or payment details. hoppin never asks for them.
How long we keep things
- Phone number, public keys and certificate: for as long as your account exists.
- Messages waiting for delivery: until collected, and at most 7 days.
- Verification codes: 10 minutes, stored hashed.
- Push token: until you turn notifications off, delete your account, or Apple tells us the app is no longer installed.
- Server logs (masked phone numbers, no IP addresses): 30 days.
- Abuse reports: as long as needed to investigate and to act against repeat abuse.
Who else is involved
We don’t sell personal data and we don’t share it for advertising. These companies process data for us:
- Twilio sends the SMS verification code, so it receives your phone number and the code. It keeps its own delivery records under its own terms.
- Microsoft Azure hosts our server, in its France Central region (Paris).
- Apple delivers push notifications, and receives the push token and the contentless notification described above.
We may also disclose information when the law requires it. What we can disclose is limited to what we hold. We cannot hand over the content of messages, because we never have it in readable form.
International transfers
Our server is in the European Union. Twilio and Apple may process data in the United States. Those transfers rely on the EU-US Data Privacy Framework or the European Commission’s Standard Contractual Clauses.
Deleting your data
Settings › Account › Delete account deletes your certificate, your registration, your push token and any messages waiting for you from our server, and erases your keys and conversations from your phone. It cannot be undone.
Deleting the app alone erases your conversations, but not your registration on our server, and iOS keeps the app’s keys in the Keychain in case you reinstall. Use Delete account first if you want everything gone.
Your rights
Under the GDPR you can ask for a copy of the personal data we hold about you, have it corrected or erased, restrict or object to how we use it, and receive it in a portable form. Write to rodrigoloucao570@gmail.com and we’ll answer within one month.
If you think we’ve mishandled your data, you can complain to your local data protection authority. In Portugal that is the Comissão Nacional de Proteção de Dados (CNPD).
Children
hoppin isn’t made for children. You must be at least 13 to use it, and at least 16 in the European Union, or the age of digital consent in your country if that is higher. If we learn that an account belongs to someone younger, we delete it.
Security
Every message is encrypted with keys used for that message only, and signed, so a changed or unsigned message is rejected rather than shown. Connections to our server use TLS, pinned to our own certificate. Keys and certificates live in the iOS Keychain, and conversations on your phone are protected by iOS data protection. No system is perfect, but nothing we hold would let us read your messages.
Changes to this policy
When this policy changes, the date at the top of this page changes with it. For significant changes we’ll also tell you in the app.
Contact
Questions about this policy go to rodrigoloucao570@gmail.com, or see the support page.