
Last updated: 8 August 2026 · Version 2026-08-08.4
This policy describes what xNostr collects, why it collects it, how long it is kept and who it does not go to.
Two points are stated plainly because they matter more than the rest. The collection described in Section 4 is not optional and the app offers no switch to turn it off. The record of what an installation has asked to download is linked to a persistent identifier for that installation.
1.1 This Privacy Policy (the "POLICY") is issued by FIBER DATUM LLC, a Wyoming limited liability company ("FIBER DATUM", "WE", "US" or "OUR"), the publisher of the xNostr application for iOS.
1.2 It covers the xNostr application, published under the bundle identifier org.xnostr.app (the "APP"), the website at https://xnostr.org (the "SITE") and the application programming interface at https://api.xnostr.org (the "API"), together the "SERVICE". It forms part of our Terms of Service.
1.3 It does not cover any third party website, media host, Nostr relay or promoted application you may reach through or because of the Service. Those are operated by other people under their own policies. See Sections 11 and 12.
1.4 We are the controller of the information described in this Policy, except where this Policy says otherwise.
This summary is for orientation only. The sections that follow are the operative text.
The Service is offered from the United States and is intended for users in jurisdictions where its use is lawful. Our servers are in the United States, so everything described in this Policy is collected, stored and processed there. If you access the Service from somewhere else, you do so on your own initiative and you are responsible for compliance with the law that applies to you.
Everything in this Section is collected automatically by the App and recorded by our server. None of it requires a device permission, and none of it comes from a permission prompt you have answered.
One row exists for each installation of the App. It holds:
| What | Why we keep it |
|---|---|
| Installation identifier | A random identifier generated on the device the first time the App runs, so that the records below can be counted per installation rather than in aggregate only. See Section 6. |
| First seen | When that installation first contacted us, so we can count new installations over a period. |
| Last seen | When that installation last contacted us, so we can count installations still in use. |
| Downloads started | How many downloads that installation has begun, so we can understand how the App is actually used. |
| Device model identifier | The hardware identifier the operating system reports, for example iPhone17,1, so a fault can be traced to a class of device. It is read from the operating system and needs no permission. |
| iOS version | The operating system version, for the same reason. |
One row is written each time you submit an address for download. It holds:
| What | Why we keep it |
|---|---|
| Time | When the request was made. |
| Host | The hostname part of the address you submitted, so we can see which sites are in demand and which are failing. |
| The address you submitted | The full web address, or the Nostr identifier, that you asked us to resolve. This is what allows a failure to be reproduced and a broken site to be fixed. It is also, unavoidably, a record of what that installation asked for. |
| Storefront country | The country of the App Store account on the device. See Section 7. |
| Outcome | Whether the download succeeded or failed. |
| Error code | If it failed, which of a fixed list of failure kinds it was. It is a code from a closed set and never free text. |
| Installation identifier | Which installation asked. See Section 6. |
| App version and build | Which release of the App made the request, so a fault can be attributed to a release. |
| Quality setting | The maximum video height requested, so we can see what people choose. |
| Preparation time | How long it took us to find the media, in milliseconds. |
| Transfer time | How long the transfer took, in milliseconds. |
| Route | Whether the file came straight to your device or through our fallback path, which is the main measure of how well the Service is working. |
| File size | The size of the resulting file in bytes. |
When the App shows a promotional page, it increments a counter for that promotion and, if you tap it, a second counter. These are running totals per promotion and per position. They carry no identifier, no timestamp and nothing about the device or the person, and they cannot be connected to any installation, to any download, or to each other.
Like any internet service, our servers receive your device's internet protocol (IP) address in order to send a response to it. We do not store IP addresses in our records, and the web server in front of our API is configured to discard its request log.
On the fallback path described in Section 10, a video passes through our server. The file is written to temporary storage, sent to your device, and deleted when the response completes. A scheduled process removes anything that deletion missed. We do not keep a copy, we do not index the contents, and we do not associate the file with your installation record beyond the download record described in Section 4.2.
Some videos are saved in a format your device cannot play. If you choose Convert on a video in your Library, the App sends that file from your device to our server in pieces, our software re-encodes it so that your device can play it, and the App receives the result. Both the file you sent and the converted file are held on our server for as long as the conversion takes and are deleted when the App has received the result. If the App never collects the result, a scheduled process deletes both within twenty six (26) hours. Nothing about the file is kept after that, it is not indexed or catalogued, and it is not examined for what it depicts.
When you accept these documents, the App sends our server your installation identifier and the version of each document you accepted. Our server records those, together with the time it received them, as proof that the agreement was entered into. Accepting a later version overwrites the previous record, so only your most recent acceptance is held.
5.1 The App offers no setting that turns off the collection described in Section 4, and there is no way to use the Service without it. An earlier version of the App offered such a setting. It was removed. If you do not want this information collected, do not use the Service, and delete the App.
5.2 The collection is a necessary part of providing and operating the Service. We rely on it to diagnose failures, to see which sites have stopped working, to understand load, and to detect abuse of an API that has no accounts behind it.
6.1 What it is. The first time the App runs, it generates a random universally unique identifier and stores it on the device. That identifier is sent with every request the App makes to our API.
6.2 What it is not. It is not the Apple advertising identifier (IDFA), it is not the identifier for vendors (IDFV), and it is not derived from anything about your device, your Apple Account or you. It requires no permission and raises no App Tracking Transparency prompt, because it is used only by us and is never combined with data from any other company.
6.3 It is persistent, and it resets in one way. The identifier survives for as long as the App is installed. Deleting the App deletes it, because it is stored in the App's own container. A later reinstallation generates a new identifier and counts as a new installation. Deleting videos inside the App does not reset it.
6.4 The link, stated plainly. The installation record described in Section 4.1 and the download record described in Section 4.2 both carry this identifier, and they are joined on it. The consequence is that a list of the addresses submitted by a particular installation exists, and we can read it. We are stating this because an earlier design deliberately kept those two records apart and this one does not.
6.5 What it is not connected to. We hold no name, email address, telephone number, postal address, payment instrument or account of any kind, so we have no ordinary means of connecting an installation identifier to a named person. We do not attempt to do so and we do not buy or receive data from anyone that would allow it.
7.1 The App reads the country of the App Store storefront the device buys from, using the operating system's own StoreKit interface, and sends that two letter country code with a download request.
7.2 It is not derived from your device's location, from your IP address, or from any address you have given anyone. It is the region of the App Store account. Somebody living in one country with an App Store account registered in another reports the account's country, and it does not change when they travel or use a virtual private network. The App makes no location API call of any kind, holds no location entitlement, and never asks for location permission.
7.3 We use it to understand where the Service is being used at country level, which affects which sites we support and which languages matter.
We do not collect, and the App does not ask for:
We use the information described in Section 4 to:
10.1 On your device. Videos you download are stored inside the App's own container on your device. We have no copy and no access to them, and we cannot recover them if you delete the App.
10.2 They usually do not touch our servers. Our server finds where the media is and tells the App. The App then fetches the media itself, directly from the site that holds it, over your own network connection. In that ordinary case not one byte of the video passes through our infrastructure.
10.3 What the site you download from sees. Our server's outbound requests relating to your download are relayed through your device, so the site that holds the media sees your network address rather than ours, and your device performs the name lookups. The privacy consequence runs both ways and is worth stating: it means we are not interposed between you and that site, and it means that site sees you.
10.4 The fallback path. Some formats cannot be assembled by the App alone. In those cases the file passes through our server in transit and is deleted when the response completes, as described in Section 4.5.
10.5 Copies in Photos. Copying a video into your device's Photos library is a separate action you take, one video at a time. If iCloud Photos is enabled on your device, the copy is uploaded to iCloud by Apple under Apple's terms and counts towards your iCloud storage. That is a matter between you and Apple. We are not involved in it and receive nothing from it.
11.1 When you submit a Nostr identifier, the App and our server look for the corresponding event. One relay we operate is asked first. If it does not have the event, the request goes to a number of public relays operated by unrelated third parties, and those connections are made from your device.
11.2 The consequence is that up to about ten relay operators can see that your network address asked for a particular event. This is inherent to how Nostr works and every Nostr client behaves this way. We do not send those operators anything else, we do not send them your installation identifier, and we do not receive anything back from them about you.
11.3 Relay operators are independent third parties. What they log, and for how long, is a matter for them and is outside our control.
12.1 What happens. After you have saved a few videos, the App may show a full screen page promoting another software application. The App fetches a manifest and the page itself from our own website at xnostr.org, and displays the page inside the App.
12.2 What does not happen. The App contains no third party advertising network. There is no advertising network, no advertising software development kit, no real time bidding exchange, and no audience targeting. The App may show full screen promotions for other applications. We select those ourselves, we serve them from our own server, and we may be paid for installations that originate from them. Nothing about you, your device, your downloads or your library is sent to any advertiser, advertising intermediary, data broker or exchange. The promotion you see is not selected on the basis of anything about you: it is whatever our manifest currently says, the same for everyone.
12.3 What is measured. Only the counters described in Section 4.3: how many times a promotion was shown and how many times it was tapped, in total. Those counters carry no identifier of any kind.
12.4 If you tap through. Tapping a promotion opens the App Store, either in a sheet inside the App or in the App Store application. From that point Apple's own terms and privacy policy govern what happens. Where a promoted application's publisher has issued us App Store campaign tokens, those tokens are passed to the App Store so that the publisher can attribute an installation to the campaign. Those tokens identify the campaign, not you, and the resulting report goes to that publisher and not to us.
12.5 We do not detect installations. The App does not, and cannot, determine whether you installed a promoted application.
13.1 Both are present. AppsFlyer and Firebase are both integrated into the App as at the "Last updated" date of this Policy. Each was added in a version of the App published on that date, and because that is a material change under Section 21 you were asked to accept this Policy again before continuing to use the App.
13.2 AppsFlyer. AppsFlyer Ltd. provides mobile attribution and marketing analytics. It receives information about how an installation of the App came to exist and how it is used: the installation identifier described in Section 6, the device model and operating system version, the app version, the App Store storefront or country, coarse network information such as the IP address from which the request was made, the time of installation and first launch, referral and campaign parameters, and the in app events listed in Section 13.3. Where you allow it under Section 13.4, it also receives the Apple advertising identifier.
13.3 The events it receives, and the one thing it does not. The App sends AppsFlyer an event when a download is started, when one completes, when one fails, when a Nostr note resolves to a video, when a video is copied into Photos, when a video is converted, when a video or the App itself is shared, when a promotion for another application is tapped, and when these documents are accepted. A completed download carries the quality you chose, whether the file came directly or through our server, roughly how long it took and roughly how large it was. A failed one carries a short error code.
The address you asked to download is never sent to AppsFlyer. Neither is the site it points at, the name of any video, or anything about your Library. Those are described in Section 4.2 and stay between the App and our own server.
13.4 The advertising identifier, and the prompt. The App asks for permission to track using Apple's App Tracking Transparency prompt. If you allow it, the Apple advertising identifier is included in what AppsFlyer and Firebase receive, which lets an installation be matched to the advert or link it came from. If you refuse, no advertising identifier is collected and nothing else about the App changes. Everything else in this Section happens either way. You can change your answer at any time in the Settings app, under Privacy and Security, then Tracking.
13.5 Firebase. Firebase is a set of services provided by Google LLC. The App uses two of its parts, Google Analytics for Firebase and Firebase Crashlytics, for application analytics and crash reporting. Between them they receive an installation identifier, the device model and operating system version, the app version, coarse network information such as the IP address from which the request was made, the language and country associated with the device, the same in app events listed in Section 13.3, which screen of the App is on view, and, in the case of a crash, a stack trace and the device state at the time of it.
The address you asked to download is never sent to Firebase either. Neither is the site it points at. When a download fails, Firebase is told a short error code and nothing else. The App does not use Firebase Performance Monitoring, which is the part of Firebase that would record the network addresses the App contacts, and it was left out for that reason.
13.6 They are independent controllers of what they receive. AppsFlyer and Google each determine the purposes and means of their own processing of the information they receive, each act as an independent controller or business in respect of it, and each handle it under their own privacy policies, which we do not control. You should read those policies: AppsFlyer and Firebase.
13.7 What has not changed. Adding AppsFlyer has not introduced third party advertising into the App, and has not caused us to sell personal information. We still do neither. An earlier version of this Section said that adding these providers would not cause us to collect the Apple advertising identifier or to raise an App Tracking Transparency prompt. That is no longer accurate and this version says so plainly: both now happen, on the terms in Section 13.4, and you were asked to accept this Policy again because of it.
14.1 We do not sell it. We do not sell personal information, we have never sold personal information, and we do not share personal information for cross context behavioral advertising, as those terms are used in the California Consumer Privacy Act.
14.2 Two third parties receive some of it. As at the "Last updated" date of this Policy, the only third parties that receive any of the information described in Section 4 are AppsFlyer and Google, and each receives only what Section 13 sets out. In particular it does not receive the addresses you asked to download. Nothing else in Section 4 is disclosed to any third party, other than as described in Section 14.3.
14.3 Infrastructure. Our servers run on infrastructure provided by a hosting company, which necessarily holds our data at rest and in transit on our behalf under its contract with us, and which is not permitted to use it for its own purposes.
14.4 Future service providers. If and when the providers described in Section 13 are added, they will receive the categories of information described there.
14.5 Law and safety. We may disclose information where we believe in good faith that it is necessary to comply with a law, regulation, subpoena, court order or other lawful request; to enforce our Terms of Service; to respond to a notice of claimed copyright infringement or to apply our repeat infringer policy; to detect, prevent or address fraud, abuse, security or technical issues; or to protect the rights, property or safety of any person.
14.6 Business transfer. If we are involved in a merger, acquisition, reorganization, financing, sale of assets or bankruptcy, information covered by this Policy may be transferred as part of that transaction. The recipient will remain bound by this Policy in respect of that information unless and until you are given notice of a change and, where the change is material, you accept it under Section 21.
14.7 Aggregated and de-identified information. We may create and use aggregated or de-identified information that cannot reasonably be used to identify any installation or person, and we may publish or share it. We will not attempt to re-identify it.
15.1 Download records. The records described in Section 4.2 are kept on a rolling window of thirty (30) days and are then deleted automatically. The window is a configuration value, and if we change it we will state the new period here.
15.2 Installation records. The records described in Section 4.1 are kept for as long as the installation remains in use and for a reasonable period afterwards, so that counts of active and new installations over time remain meaningful. They are deleted on request as described in Section 17.
15.3 Promotional counters. The counters described in Section 4.3 are running totals with no identifier and no timestamp. They are kept for as long as the promotion they describe is of interest.
15.4 Files in transit. Files on the fallback path are deleted when the response completes. A scheduled process removes anything missed, and in no case is such a file kept beyond twenty four (24) hours.
15.5 Files you send us for conversion. The files described in Section 4.6 are deleted when the App has received the converted file, and in any event within twenty six (26) hours.
15.6 Acceptance records. The record described in Section 4.7 is kept for as long as the installation record it belongs to, and is overwritten when you accept a later version. It is deleted on request as described in Section 17.
15.7 Longer retention where required. We may retain information for longer where we are required to do so by law, or where it is necessary to establish, exercise or defend a legal claim, and in that case we retain only what is necessary for that purpose.
16.1 Traffic between the App and our API is encrypted in transit using transport layer security. Access to our administrative interface requires authentication and a second factor. Our database is not exposed to the public internet.
16.2 We limit what we collect, which is itself a security measure. We hold no passwords, no payment instruments and no contact details, so there is nothing of that kind to lose.
16.3 No method of transmission over the internet and no method of electronic storage is completely secure. We cannot guarantee absolute security, and we do not warrant it. See the disclaimer in our Terms of Service.
16.4 The lock available inside the App is a gate on the App's interface, for the convenience of anyone who does not want their library readable over their shoulder. It is not encryption and it should not be relied on as a protection against anyone with access to the device's storage.
17.1 Deleting the App. Deleting the App from your device deletes the installation identifier and every video the App is holding. After that, nothing on the device connects you to any record we hold, and a later reinstallation is a new installation.
17.2 Requests. Subject to applicable law, you may ask us to tell you what information we hold that is associated with your installation, to give you a copy of it, to correct it, or to delete it. Write to hello@fiberdatum.com.
17.3 How we verify a request, and the limit on it. Because the Service has no accounts, the only key we hold is the installation identifier. To act on a request we must be able to match it to that identifier. Your installation identifier is shown in the App, in Settings, under About, and can be copied from there. If you cannot supply it, we may be unable to locate any records about you, and we will say so rather than act on a guess. We will not ask you for additional personal information for the sole purpose of verifying a request.
17.4 Authorized agents. You may use an authorized agent to make a request on your behalf. We may require written proof of the agent's authority and may contact you to confirm it.
17.5 Timing and fees. We will acknowledge a request within ten (10) business days and respond within forty five (45) calendar days, and we may extend that period by a further forty five (45) days where reasonably necessary, in which case we will tell you. There is no fee for a reasonable request. We may refuse a request that is manifestly unfounded, excessive or repetitive, and we will tell you why.
17.6 No discrimination. We will not deny you the Service, charge you a different price, or provide you a different level of quality because you exercised a privacy right.
17.7 Notifications. Notifications from the App are local to the device and are controlled in the App's settings and in the iOS Settings application. Turning them off sends nothing to us and does not affect what is described in Section 4.
This Section supplements the rest of this Policy and applies to residents of California under the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"). Terms used in this Section have the meanings given to them in the CCPA.
| CCPA category | What we collect | Disclosed for a business purpose to |
|---|---|---|
| Identifiers | The installation identifier described in Section 6. We do not collect a name, postal address, email address, account name, social security number, driver's license number, passport number, IDFA or similar identifier. | Our hosting provider only. |
| Internet or other electronic network activity information | The addresses you submit for download and their hostnames, the outcome and error code, the route taken, the quality requested, the preparation and transfer times, the file size, and the count of downloads started. See Sections 4.1 and 4.2. | Our hosting provider only. |
| Geolocation data | Country only, and only in the form of the App Store storefront country described in Section 7. We do not collect precise geolocation and we make no location API call. | Our hosting provider only. |
| Other information about your device | The device model identifier, the iOS version, and the App version and build. | Our hosting provider only. |
We collect all of it directly from the App on your device. We collect it for the purposes listed in Section 9, which are the business purposes for which it is used. We do not collect the categories not listed above, which are customer records information, characteristics of protected classifications, commercial information, biometric information, audio, electronic, visual, thermal, olfactory or similar information, professional or employment information, education information, or inferences drawn to create a profile.
We do not collect sensitive personal information as defined by the CCPA. We therefore make no use of sensitive personal information beyond the purposes permitted by section 1798.121(a), and the right to limit its use and disclosure is not engaged.
We do not sell personal information and we do not share personal information for cross context behavioral advertising, and we have not done so in the preceding twelve months. We do not sell or share the personal information of any consumer we know to be under sixteen years of age, and the Service is not offered to anyone under eighteen.
Write to hello@fiberdatum.com with the subject line "California Privacy Request", stating which right you wish to exercise. Section 17.3 explains how we verify a request and the practical limit on that verification in a service with no accounts. Section 17.5 gives our timings. You may appeal a refusal by replying to our response and asking for it to be reviewed.
California Civil Code section 1798.83 permits residents of California to request information about disclosure of personal information to third parties for their direct marketing purposes. We make no such disclosures.
19.1 Residents of other states that have enacted comprehensive consumer privacy legislation may have rights to confirm whether we process their personal data, to access it, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, of the sale of personal data, and of profiling with legal or similarly significant effects.
19.2 We do not engage in targeted advertising, we do not sell personal data, and we do not carry out profiling of that kind. To exercise any other right, write to hello@fiberdatum.com. Sections 17.3 to 17.5 apply. Where the law of your state provides a right to appeal a refusal, you may appeal by replying to our response, and we will respond to the appeal in writing within the period that law allows.
19.3 Nevada residents may submit a request that we not sell certain personal information. We do not sell personal information.
20.1 The App is rated 18+ and is intended only for adults. It is not directed to children, and we do not knowingly collect personal information from anyone under thirteen (13) years of age, nor do we permit anyone under eighteen (18) to use the Service.
20.2 If we learn that we have collected personal information from a child under thirteen, we will delete it. If you believe a child has provided us with personal information, write to hello@fiberdatum.com and we will act promptly.
21.1 We may update this Policy. When we do, we will change the "Last updated" date and the version identifier at the head of this document, publish the new version at this address, and record it in the version file at https://xnostr.org/legal.json.
21.2 A material change requires your express acceptance in the App before you may continue to use the affected features. A material change includes any expansion of the categories we collect, any new disclosure to a third party, including the addition of the providers described in Section 13, and any new purpose that is not compatible with those in Section 9. Changes that are not material take effect when posted.
21.3 We will not apply a materially different treatment to information already collected without giving you notice and, where the change is material, obtaining your acceptance.
Fiber Datum LLC, a Wyoming limited liability company
Everything hello@fiberdatum.com
We will acknowledge a privacy request within ten (10) business days.