← PeddleNet

PRIVACY NOTICE

PeddleNet — community test (Tier C)

This notice explains what personal data PeddleNet processes in the beta and your rights. Controller: Bill Costello / Qvintessential Design · Contact: th3p3ddl3r@gmail.com.

1. Our privacy principle

PeddleNet is designed to be anonymous by default. You are shown to others only by a display name you choose (which can be a pseudonym); we do not require your real name, phone number, or email to use the beta.

2. What we process

Display name (self-chosen) and a cryptographic device/node identity used to sign and route messages.

Room membership and presence signals — that you are active in a room, and approximate proximity derived from Bluetooth signal strength (not precise GPS).

Message content — created, transmitted, relayed across other participants' devices, outposts and peddlers, and stored locally on those devices until it is delivered or expires. There is no server in the beta: messages are not uploaded to us and never pass through our systems.

Optional location — only if you enable a feature that uses it (e.g., a friend compass); off by default.

Crash reports and basic app-usage analytics — collected by Google Firebase (Crashlytics and Analytics) so we can find and fix faults during the test. These describe how the app behaves; they do not carry your message content.

3. Why, and our legal basis (GDPR)

To operate the Service — deliver and relay messages between participants' devices and show presence/rosters: performance of the terms you accept (contract), and our legitimate interest in a working network.

For crash reports, app-usage analytics, and any optional location features: your consent, which you can withdraw at any time.

4. How the mesh shares data — by design

PeddleNet is a mesh: to reach their destination, your messages pass through other participants' devices, outposts and peddlers, signed for authenticity. In the beta there is no server backbone — nothing is bridged or queued by us, and a message exists only on the devices carrying it. We do not sell your personal data, and we do not share it with advertisers.

5. Retention

Messages live on the participating devices that carry them and expire from the mesh on their own; there is no server-side queue and no copy held by us. Presence signals are ephemeral. Crash reports and analytics are retained by Google Firebase under its own retention settings and are kept only as long as needed for the test.

6. Security — and an important limit

Messages are cryptographically signed so recipients can verify who sent them. However, message contents are NOT end-to-end encrypted in the beta, and "private" rooms are code-gated access, not encryption. Please do not send confidential or sensitive information through the Service.

7. Your rights

Depending on where you live (e.g., EU/UK under GDPR, California under CCPA), you may have rights to access, correct, delete, or port your data, to withdraw consent, to object to or restrict processing, and to opt out of any "sale" or "sharing" (we do neither). To exercise them, email th3p3ddl3r@gmail.com. You may also complain to your local data-protection authority.

8. Children

The beta is for users 18 and older; we do not knowingly process data from children.

9. Changes to this notice

We may update this notice for the beta; the current version is dated below. Because the beta has no server, we do not process your messages in any country — they stay on the devices that carry them. Crash reports and analytics are processed by Google Firebase under Google's own terms.

Version date: 27 August 2026