WORMIT

Privacy Policy

Last updated: April 16, 2026

🔒 No Personal Information Required
WORMIT does not require your name, email address, phone number, or any personal ID to create an account. Your identity is a cryptographic key-pair generated entirely on your own device. Your private key never leaves your device.

1. Who We Are

WORMIT is a decentralized communication and social platform. Direct messaging is end-to-end encrypted (E2EE), while public WORM Spaces operate as open, decentralized forums. All data travels through the GunDB peer-to-peer (P2P) mesh network. No central server — including ours — can read your private messages or control the network.

2. What Data We Process

We do NOT collect:

Limited data handled by the decentralized network:

3. End-to-End Encrypted Messaging (Private)

All direct WORMIT-to-WORMIT messages, mesh files, and attachments are strongly encrypted on your device using your recipient's public key before broadcast. Servers relay only the ciphertext (WORMIT_ENC[…]). We are technically incapable of reading your private messages or files.

4. WORM Spaces (Public by Design)

The WORM Spaces feature functions as a decentralized, public town square. Data handled here works fundamentally differently than private messaging:

5. Vault Posts & P2P Media (Access-Controlled)

Within WORM Spaces, users can create Vault Posts for exclusive media.

6. Local-First Storage

Decrypted messages, contacts, wallet ledger, and profile data are cached entirely locally in your device storage (IndexedDB / LocalStorage) and never transmitted in plaintext.

7. Data Retention & Account Deletion

Because WORMIT is a decentralized mesh app, you hold the ultimate power over your data:

Option A — Delete from the app: Go to Settings → Logout button and confirm. This wipes all local keys, messages, and profile data from your device permanently. Without your recovery phrase, the account is lost forever.

Option B — Mesh Data & Ghost Messages: Ghost Messages (messages with a timer) are automatically deleted from the mesh after expiration via tombstone mechanics. For public Space posts, deleting the post locally issues a logical delete command to the mesh, though complete erasure from all offline peers cannot be instantly guaranteed in a decentralized network.

8. Third-Party Services

9. Children's Privacy

WORMIT is not directed to children under 13. We do not knowingly collect data from children under 13. Since no personal information is required to register, parental guidance is advised.

10. Changes to This Policy

We may update this policy periodically and will notify you via an in-app notice for significant changes. Continued use constitutes acceptance.

11. Contact

Questions, data requests, or account deletion: privacy@wormit.online