Privacy Policy
Last updated:
In short. Nepheral has no accounts on our servers, no ads, and no trackers or analytics in its apps. Your account, your password and your recovery words never leave your device. Your questions leave it encrypted and split into pieces, and the one computer on the network that answers a question can read it, so do not write in a question anything you would not let a stranger's computer read. The network keeps a public, permanent record of credits and services between pseudonymous keys, never of what was asked.
Who is responsible
Nepheral is developed and published by Javier Hernandez, an individual ("we", "us"). This policy covers the Nepheral apps for Windows, Linux and Android, the Nepheral node software, and the websites nepheral.net and dl.nepheral.net. Write to privacy@nepheral.net about anything in it.
How Nepheral is different
Nepheral is a peer-to-peer network, not a service we run. Each installation is a node that talks to other nodes directly. We run some nodes ourselves to help the network along, but your questions are not routed through a server of ours, and we keep no database of users.
What stays on your device
- Your account. It is created on your device and encrypted with your password. The password is never sent anywhere and is not stored.
- Your 24 recovery words. Shown once, on your device. We never see them and cannot recover them for you.
- Your conversations. Saved on your device, encrypted with your account's key, so only your account opens them; they are never sent to us. You can delete any of them, or turn offKeep conversations on this device: they then stay in the app's memory only, and closing the app discards them. A message you mark private never leaves your device.
- Your node's key, which identifies your device on the network, sealed by the device's security hardware where it has one (the Android Keystore; the TPM on Windows). The Android app excludes all of its data from cloud backups and from transfers to a new phone.
What leaves your device, and who sees it
Your questions
Before a question leaves your device, the app replaces the personal data it recognizes (email addresses, phone numbers, bank account and card numbers, IP addresses, identifiers, secrets and keys, file paths, web addresses, and names you have marked) with placeholders, and puts them back into the answer on your device. It then encrypts the question and splits it into fragments held by different devices. No fragment, and no device holding one, can read the question.
One node, picked by a draw among those running an AI model, puts the fragments back together, reads the question and answers it. That node is run by another participant, not by us, and it sees the text of your question (with the placeholders) and the public key of the device that asked. It does not learn your name, email or phone number. Depending on how the network connects the two of you, it may see your device's IP address. The answer comes back encrypted so that only your device can read it.
A question carries the last messages of its conversation and older passages that your device picks as related to it. Your device picks them, with a small model that runs on the device (NAI's private memory); the network never asks for more. When those older passages are a large part of the conversation, or touch on health, money or identity, the app shows them to you before sending, and you can take any of them out or cancel.
Recognizing personal data is automatic and cannot catch everything. Do not put in a question anything you would not let a stranger's computer read.
Taking part in the network
As with any peer-to-peer software, your device's IP address and public key are visible to the devices it connects to, including the nodes we run. Our nodes keep connection records, which include IP addresses, in their system logs for a limited time, to keep the network running and to fix problems. We use them for nothing else.
Your device also holds encrypted fragments of other people's questions. It cannot read them.
The public ledger
The network keeps a public, permanent record, a ledger every node holds a copy of, of: credits earned, spent and transferred; receipts of answered questions, saying which node answered which device, when, with what size of model and how long an answer; ratings of answers; and the network's own settings. Entries are tied to public keys, not to names. They never contain what was asked or answered. Because every node keeps a copy, no one, including us, can change or delete an entry.
Ratings and reports
When you rate an answer, or mark it as harmful, the rating goes on the ledger against the node that answered. It does not include the question or the answer. If you add a written note to a rating, the note is published on the ledger with it, so do not put personal data in it.
Updates and AI models
The desktop app checks dl.nepheral.net for updates and downloads them from there; so does the Android app installed from our website (from Google Play, it updates through Google Play). That server keeps no record of who downloads. Both apps also download from there the model behind NAI's private memory; the Android app asks first. The desktop app can also download AI models from Hugging Face, which applies its own privacy policy.
Buying credits
Where the desktop app sells credits for Litecoin, the payment is a Litecoin transaction: public and permanent on Litecoin's own blockchain, including the address it came from and a note tying the payment to your Nepheral account. We do not ask for your name or email to sell you credits.
What we do not do
- No advertising, and no advertising or analytics code in the apps.
- No selling, renting or trading of anyone's data.
- No accounts, profiles or tracking on our side.
This website
nepheral.net is hosted by Vercel and uses Vercel Web Analytics, which counts page views without cookies and without following you to other sites: it records the page, the site you came from, your country and your type of device, as aggregated statistics. Vercel processes your IP address to deliver the pages. The site sets no cookies of its own.
Google Play
If you install the Android app from Google Play, Google collects data about that installation under its own privacy policy.
Legal bases (EEA and UK)
Where data protection law such as the GDPR applies, we keep IP addresses in our nodes' logs on the basis of our legitimate interest in running a secure, working network, and what your device sends to the network is sent to provide the service you ask it for.
Children
Nepheral is not meant for anyone under 18.
Your data, and deleting it
We hold no account or profile of you, so there is normally nothing on our side to show you, correct or delete. To delete everything on your device, uninstall the app: on Android its data goes with it; on a computer, also delete the .nepheral folder in your home folder. Entries on the public ledger cannot be deleted, by us or anyone; that is what makes them trustworthy. Our nodes' logs expire on their own.Deleting your account goes through it step by step.
Write to privacy@nepheral.net with any question about this, or to exercise the rights the law gives you where you live. You can also complain to your data protection authority.
Security
Nepheral is in beta, on a test network. We work to keep it secure, but no software is free of faults. Keep your recovery words offline and your device locked.
Changes
Any change to this policy will be published on this page, with a new date at the top.