The data contract
This is the whole agreement. Every member signs it with their own device key, over the exact wording below — change a word and the digest changes, which means old signatures stop matching and everyone is asked again.
Version
SHA-256
Machine-readable at
2026-08-20.4SHA-256
ZmgfkdU6mfvq2i2jHRnm8WRP_WcEaqkHVdaG5kQqjJMMachine-readable at
/api/contract.The covenant you sign
- I will treat a person's presence here as an invitation to be civil, not an invitation to be contacted twice.
- I will not screenshot, catalogue, or carry anyone's pods out of this app. Being visible in a pod here is not consent to be known for it anywhere else.
- I will not use proximity to work out where someone lives, works, or sleeps.
- If I break this, I accept that my key is revoked, the person who invited me is told, and I do not get another one.
Everything Pods holds about you
- A public key your phone generated, and an identifier derived from it. Not an email address, not a phone number, not a name.
- A second public key, held only so other people's devices can seal things to yours. On its own it reveals nothing, and without it nobody could send you anything.
- A display name you chose. It does not have to be your real one.
- An age band — never your age, never your date of birth.
- The pods you joined and the facets you put on your card.
- Your visibility settings: who may see each of those things.
- One approximate location: the ~300m cell you were in at your last heartbeat. It is replaced by the next heartbeat and deleted 45 minutes after the last one.
- The identifiers you have blocked.
- Sealed knock intros. The one line you write when you knock on someone is encrypted on your phone, to their key, before it is sent. Pods holds a box it has no key for, for 30 days or until it is answered or withdrawn.
- Sealed doorway messages. Every message inside an open doorway is ciphertext addressed to one person. Pods holds it for at most seven days, and loses it the moment either of you closes the doorway.
- Sealed Signal handles. Your handle itself is not stored here at all: it lives on your own device. When you hand it to someone, your phone seals it to them and Pods relays a box addressed to that one person.
- The fact of a knock and the fact of a doorway — that you knocked on someone, and who you have a doorway open with. Not what was said; who it was with. That part cannot be encrypted away, and the limits clause says so plainly.
- Notices you put on the board, for as long as their run lasts. A notice holds what you wrote on it and the ~300m square you pinned it to.
- Your identifier on a notice you put up — but only for the first two days. During those two days you can take it down by being yourself, a report about it reaches you, and your key can be revoked over it. Then your identifier is deleted from the notice, the index that pointed from you to it is deleted with it, and the notice carries on with nothing on it that says whose it was. If you signed it, your name comes off at the same moment.
- The venue a notice points at, when you picked one — an identifier for a public place, chosen from a list your browser already had. Never guessed from what you typed, and never a home: the venue lists are built from public map data with every residential tag excluded, so there is no identifier in Pods that could point at somebody's house.
- How many finished notices each public venue has had, per kind. A count against a place, never against a person: no dates, no notice identifiers, nothing about who posted. It moves only when a notice's run ends — take one down and nothing is ever counted — and it is only ever shown as a phrase like “hosts things like this regularly”, above a floor of five, so it can never republish a single occasion. Notices posted under a sensitive pod are never counted at all.
- Pictures you put on a notice — a photograph of a poster, or art you made. It is stored under a hash of its own contents, served only from this app's own address, and deleted when the notice comes down. The location, time and camera details a phone writes into a photo are destroyed on your device before it is sent: your phone redraws the picture, and a redrawn picture has nowhere to keep them.
- Signals you cast on other people's notices, as counters and nothing more. The record kept against a notice is: how many people said each thing, under which pod, how many distinct people signalled at all, and the first and last times anyone did. Not who. It is deleted when the notice comes down.
- One opaque marker per notice you have signalled on, so you cannot signal on the same notice twice. It is a keyed digest of the notice and your identifier — it cannot be read backwards into your identifier, markers from two notices cannot be linked to each other, and it is deleted with the notice. It is still a link, and the limits clause says exactly what that means.
- The version of this contract you accepted, and your signature over it.
- Not on this list, deliberately: the record of what the two of you connected over. That is written on your device and uploaded nowhere. Nor is anything about how you read the board — which view you use, what you searched for, or what you asked to be told about. Those live in your browser.
- That is the entire list. The /me/data screen prints the actual stored record, so you can check this paragraph against reality rather than trusting it.
What is never collected
- Your precise coordinates. Your phone rounds your position to a ~300m cell before anything is transmitted; exact coordinates never leave the device, so they cannot be stored, leaked, or demanded from us.
- Any history of where you have been. Presence is one value that gets overwritten. There is no table in which a second location for you could exist.
- A readable copy of anything you sent anyone. Knock intros, doorway messages and handles are sealed on your device to one named recipient. The server stores the box and holds no key to it, so a breach or a subpoena yields ciphertext.
- Your Signal handle, in any form anyone here could read. There is no field on your record that could hold one, so no query can produce a list of them.
- Your contacts, photo library, calendar, or microphone. Choosing a picture hands this app that one picture and nothing else.
- Where a photo was taken. A phone writes GPS into a photo file; Pods never receives it, because your device redraws the picture before sending and the redrawn copy has no field for it.
- A record of who you looked at, how long you looked, or what you tapped. On the board that also means: no view count, no score, and no field on a notice that one could ever be written into.
- A like, a favourite, or a 'not for me'. The signals you can cast are all claims somebody else could check — this belongs in that community, I know this is real, something on it is wrong, this is over. A taste signal is not on that list, because a record of what you liked is the profile this contract exists to prevent.
- The list of what you have signalled on. It is kept in your browser so the app does not offer you a button twice, and there is no route here that answers whether you have signalled on something.
- What you search the board for. Searching happens inside your browser, over notices it already has, so the words you type never leave the device.
- What you type when you are looking for a venue. There is no place-search service here — not a slow one, not our own: your browser downloads whole venue lists for the rough 2.4km square you are in and matches against them itself. There is no endpoint that could be asked what you typed, so there is no log of it that could exist.
- What you have asked to be told about. A watch is a filter you wrote, kept in your browser and checked there. There is no copy of it here and no push service behind it.
- Any identifier that follows you to another app or website.
The doorway, and what it is not
- Nobody arrives in your messages uninvited. Somebody knocks with one line — 280 characters, sealed to you — and you accept it or you do not.
- Ignoring is silent. There is no decline, no 'seen', no read receipt, and no timer that gives it away. Someone who knocks sees 'waiting' and never learns anything else. In a city small enough to run into each other again, that is worth more than closure.
- If you accept, a doorway opens: five messages each, 280 characters, seven days. Then it is gone, whether or not you were finished.
- Two of those bounds are structural rather than policy: the server counts sealed boxes and expires keys, so the five-message limit and the seven days hold without it reading a word. The 280 characters is not in that category and we will not pretend otherwise — the server sees ciphertext, so it cannot count your characters. It bounds the size of the box instead, which is a loose ceiling rather than an exact one. A modified client could put a longer message in a box; it could not send a sixth, and it could not make the doorway outlive its week.
- It is a doorway, not a room. It exists to answer one question — is this person worth moving to Signal for? When you swap handles the doorway is deleted, and Pods carries nothing after that.
- At handoff your own device reads the doorway one last time before deleting it, matches it against the same fixed list of pods and facets the app already uses, and offers you a few tags. That is keyword matching on your phone, not a model, and it could not run on a server even if we wanted it to — the server has only ciphertext.
- Nothing worked out that way is uploaded unless you tick it. Facets you accept go onto your own card under the ordinary audience rules, and that is the only effect a connection ever has on anything stored here.
- The record of what the two of you connected over stays on your device. A guessed relationship plus a guessed interest, attached to two named people, is the most dangerous thing this system could hold, so it is not held. A tag you share needs both of you to have picked it.
- Sensitive pods and facets are never suggested from what you typed. That rule is checked when the app loads, so an edit that broke it would break the build.
No extraction
- There is no advertising in Pods and no capacity to add any without breaking this contract.
- Nothing here is sold, licensed, brokered, or shared with a data partner. There are no data partners.
- There are no third-party analytics, trackers, pixels, session recorders, or advertising SDKs. The app makes no requests to any domain other than its own.
- Linking a social account is not available. It is not an unfinished feature: importing followers or photos would drag another company's tracking into a room built to keep it out.
- Handing someone your Signal handle is the one place Pods touches another service, and it is worth naming exactly. Pods never contacts Signal — no integration, no login, no contact import, no lookup. Your handle sits on your own device; when you give it to someone, your phone seals it to them and Pods passes on a box it cannot open. Signal has no advertising and no tracking to import.
- There is no engagement optimisation. Nothing is ranked to hold your attention: the grid is ordered by rough proximity and then arbitrarily, and it does not reorder to keep you looking. The board is ordered by what is soonest, then by whether people in your own pods have said it belongs there, then by roughly how near it is — and then shuffled per person the same way the grid is.
- That middle step is the only thing on the board that responds to what anybody thinks, and it is bounded in four ways. It never leaves a day-bucket, so nothing is promoted past what is happening sooner. It resolves to one of three levels, which is all the server keeps and none of which is ever sent to your device — there is no total to see anywhere in Pods. Saying something is wrong can only pull a notice back to where it would have been if nobody had spoken, never below, so no group can bury a notice. And on a quiet board it is switched off entirely, so a handful of people cannot decide a whole page.
- A notice cannot be bumped, renewed, extended, or pushed to the top, by you or by anybody paying. It stays up for the run you chose and then it comes down. A paid pin would be advertising, which this contract prohibits outright and permanently.
- There are no streaks, no badges, no read receipts, no 'active now' indicator, and no notification designed to pull you back. The doorway has no typing indicator and no delivery state either — a knock that is ignored looks exactly like one that has not been opened yet.
- The one notification Pods will send is the board digest, and only if you wrote a watch asking for it. At most one a day, only when something matched, and it never tells you how many — because a number is a thing to clear, and clearing things is a habit rather than a use.
What you can do, at any time, without asking
- Download everything held about you as a single JSON file.
- Delete your account outright. It is immediate, it is not a soft delete, and there is no recovery flow — nothing is retained to recover from.
- Step off the grid without deleting anything.
- Close a doorway whenever you want. It closes for both of you and the messages are deleted from the server rather than hidden from you.
- Withdraw a handle you sealed to someone. Read the limits clause first for what that can and cannot reach.
- Take any notice of yours off the board, immediately. It goes for everyone, and there is nothing kept to restore it from. In the first two days you do that just by being signed in. After that Pods no longer knows the notice is yours, so taking it down uses a key your browser kept when you posted it — which means clearing this browser's storage costs you that ability, and the notice runs to its end instead.
- Turn any pod or facet invisible, or restrict it to specific pods.
- Hide sensitive memberships. They start hidden, and they are never inferred from anything you tap.
Conduct, and what abusing this costs you
- Pods is for meeting people who are actually nearby. Harassment, sexual content directed at people who did not ask for it, and contact after someone blocks you are all grounds for removal.
- Attempting to determine anyone's precise location — by spoofing your own position, by automating queries, or by coordinating with others to do either — is a serious abuse of this service and is treated as one.
- Scraping, automating, or reselling access is prohibited. Pods holds itself to the same rule outward: the board only ever takes in listings from feeds their publishers put out to be read by other software, with attribution and a link back. It does not scrape sites that have not published one.
- The board is for notices about a place — what is on, what is wanted, what is going. Using it to advertise at a neighbourhood, to post about a person, or to pin things to squares you have nothing to do with is misuse and is treated as such.
- Nobody under 18.
- Reports are kept for six months so they can still be acted on when a pattern emerges. A report holds the two identifiers, your reason, and your note — no location, and no message content, because there is none to attach.
- You can report a notice as well as a person. Reporting an unsigned notice does not block anybody and never tells you who put it up — that would make reporting a way of finding out. If the notice is less than two days old the report reaches whoever posted it; after that it is recorded against the notice, because there is no longer anybody on the record for it to reach.
- Reporting someone blocks them in the same action and tears down every route between you: the knock, the doorway, and any handle either of you sealed to the other, in both directions.
- You accepted this by signing it with your device key. That signature is stored. It is what makes 'I did not agree to this' an unavailable answer.
How this is paid for
- Pods has no profit motive and no investors expecting a return from your attention.
- It is intended to be funded the way Signal is: donations, and possibly a small optional fee. If a fee ever appears it will be announced here first, and no feature that protects you will ever sit behind it.
- If Pods cannot be funded this way, it shuts down rather than changing this contract. There is no version of this that pivots to advertising.
What this contract cannot promise
- Pods runs on a server, and that server necessarily learns the rough cell you are in while you are on the grid. This design makes that knowledge coarse and short-lived. It does not make it impossible, and no proximity app can.
- Our hosting provider can see the IP address your requests come from. We do not log it or use it, but we do not control their infrastructure logs. Self-hosting is the real fix and it is not built yet.
- Pods does carry messages, within a bound: a doorway is five messages each, 280 characters, seven days, sealed on your device to one person and deleted at handoff. The server cannot read any of it and holds nothing once the doorway closes. Durable conversation moves to Signal, where it is end-to-end encrypted by an audited app — Pods stays deliberately too small to live in.
- The sealing is not the Signal protocol. It is one long-lived key pair per device with no ratchet, which means no forward secrecy and no post-compromise security: if your device key ever leaks, every box ever sealed to it becomes readable. For five short messages that expire in a week that is a trade worth making against hand-rolling a ratchet badly. It is not a trade we would make for durable conversation, and it is precisely why the doorway is bounded.
- Encryption hides what you said, not that you said it. The server still learns who knocked on whom, and who has a doorway open with whom. That is the relationship graph, no amount of sealing removes it, and it is the honest residual of running a server at all.
- Signal itself requires a phone number to register. Pods never sees it and nobody here ever learns it, so 'no phone numbers' is true of Pods — but it is not true of Signal's sign-up, and anyone unwilling or unable to give one is shut out of everything past the doorway. That is a real exclusion and we would rather name it than let you discover it.
- Sharing a handle cannot be fully undone. Withdrawing stops someone fetching it here, but not a copy they already saved. Only resetting the link inside Signal genuinely revokes it — which is why the link is worth preferring over a plain username.
- Pods cannot tell whether a Signal message was sent, delivered, or read. There is no API for that and there will not be one here, so there is no unread mark anywhere in this app — one would be permanently false.
- Pictures are not checked for what they show. This deployment has no image classifier configured and no human moderation queue, so the only controls on a bad picture are that somebody reports it, that it can be taken down, and that nobody joins without an invitation. Those are weaker for pictures than they were for text, and it is why Pods stays invite-only. If a checking service is ever switched on, pictures would be sent to that service — that changes who sees your content, so this contract would change first and name it.
- This code has not yet been reviewed by an independent security researcher — including the sealing code that every claim about your messages rests on. Until it has, treat every claim on this page as a stated intention backed by readable source, not as an audited guarantee.
- Stopping you signalling twice on one notice needs a marker that ties you to that notice, and there is no way around that. It is a keyed digest rather than your identifier, it cannot be read backwards, and markers from different notices cannot be joined — but somebody holding the key that makes them could test a guess about whether a particular person signalled on a particular notice. It is deleted with the notice. The cryptographic version that would remove even that was designed, reviewed by an adversarial pass, and abandoned with four separate fatal flaws; a small project should not ship cryptography it cannot afford to have reviewed properly.
- Severing your identifier from a notice after two days is a deletion we perform, in code you can read — it is not cryptography. For those two days the identifier is on the record and an operator with database access could read it. What the design guarantees is that afterwards there is no field left holding it and no index left to walk from you to your notices, not that it was never there.
- Two things stop working once a notice goes anonymous, and both are the price of it rather than oversights. Blocking someone hides their notices from you only while those notices still carry their identifier — older ones are no longer attached to anybody, so a block has nothing to act on. And deleting your account removes the notices still attached to you, but not the ones that no longer are; those stay up until their run ends, because nothing left connects them to you.
- A notice whose harm only shows up later — a listing for an event that turns out to be a scam after the fact — cannot be traced to whoever posted it. That follows directly from severing the link, it is not recoverable by any amount of engineering, and it is the honest cost of the board being anonymous.
- If any of this stops being true, this contract changes, its version changes, and you are asked to read and sign the new one. It does not change quietly.
Nothing on this page has been checked by an independent security reviewer yet. The source is readable and the claims are specific so that it can be checked — but until someone has, treat this as a stated intention rather than an audited guarantee.
Pods holds one approximate location for you, replaces it every time you move, and deletes it 45 minutes after you stop. It has never held your precise position — your phone rounds it off before sending. No advertising, no analytics, no data sales. Read the data contract · See everything held about you