Terms
What you undertake by joining, what breaking it costs, and what Pods undertakes back. These are the conduct sections of the contract every member signs, printed from the same source the signature is taken over.
Part of version
2026-08-20.4. The whole agreement is at the data contract; the data-handling sections are at privacy.The covenant you sign
- I will treat a person's presence here as an invitation to be civil, not an invitation to be contacted twice.
- I will not screenshot, catalogue, or carry anyone's pods out of this app. Being visible in a pod here is not consent to be known for it anywhere else.
- I will not use proximity to work out where someone lives, works, or sleeps.
- If I break this, I accept that my key is revoked, the person who invited me is told, and I do not get another one.
Conduct, and what abusing this costs you
- Pods is for meeting people who are actually nearby. Harassment, sexual content directed at people who did not ask for it, and contact after someone blocks you are all grounds for removal.
- Attempting to determine anyone's precise location — by spoofing your own position, by automating queries, or by coordinating with others to do either — is a serious abuse of this service and is treated as one.
- Scraping, automating, or reselling access is prohibited. Pods holds itself to the same rule outward: the board only ever takes in listings from feeds their publishers put out to be read by other software, with attribution and a link back. It does not scrape sites that have not published one.
- The board is for notices about a place — what is on, what is wanted, what is going. Using it to advertise at a neighbourhood, to post about a person, or to pin things to squares you have nothing to do with is misuse and is treated as such.
- Nobody under 18.
- Reports are kept for six months so they can still be acted on when a pattern emerges. A report holds the two identifiers, your reason, and your note — no location, and no message content, because there is none to attach.
- You can report a notice as well as a person. Reporting an unsigned notice does not block anybody and never tells you who put it up — that would make reporting a way of finding out. If the notice is less than two days old the report reaches whoever posted it; after that it is recorded against the notice, because there is no longer anybody on the record for it to reach.
- Reporting someone blocks them in the same action and tears down every route between you: the knock, the doorway, and any handle either of you sealed to the other, in both directions.
- You accepted this by signing it with your device key. That signature is stored. It is what makes 'I did not agree to this' an unavailable answer.
How this is paid for
- Pods has no profit motive and no investors expecting a return from your attention.
- It is intended to be funded the way Signal is: donations, and possibly a small optional fee. If a fee ever appears it will be announced here first, and no feature that protects you will ever sit behind it.
- If Pods cannot be funded this way, it shuts down rather than changing this contract. There is no version of this that pivots to advertising.
What this contract cannot promise
- Pods runs on a server, and that server necessarily learns the rough cell you are in while you are on the grid. This design makes that knowledge coarse and short-lived. It does not make it impossible, and no proximity app can.
- Our hosting provider can see the IP address your requests come from. We do not log it or use it, but we do not control their infrastructure logs. Self-hosting is the real fix and it is not built yet.
- Pods does carry messages, within a bound: a doorway is five messages each, 280 characters, seven days, sealed on your device to one person and deleted at handoff. The server cannot read any of it and holds nothing once the doorway closes. Durable conversation moves to Signal, where it is end-to-end encrypted by an audited app — Pods stays deliberately too small to live in.
- The sealing is not the Signal protocol. It is one long-lived key pair per device with no ratchet, which means no forward secrecy and no post-compromise security: if your device key ever leaks, every box ever sealed to it becomes readable. For five short messages that expire in a week that is a trade worth making against hand-rolling a ratchet badly. It is not a trade we would make for durable conversation, and it is precisely why the doorway is bounded.
- Encryption hides what you said, not that you said it. The server still learns who knocked on whom, and who has a doorway open with whom. That is the relationship graph, no amount of sealing removes it, and it is the honest residual of running a server at all.
- Signal itself requires a phone number to register. Pods never sees it and nobody here ever learns it, so 'no phone numbers' is true of Pods — but it is not true of Signal's sign-up, and anyone unwilling or unable to give one is shut out of everything past the doorway. That is a real exclusion and we would rather name it than let you discover it.
- Sharing a handle cannot be fully undone. Withdrawing stops someone fetching it here, but not a copy they already saved. Only resetting the link inside Signal genuinely revokes it — which is why the link is worth preferring over a plain username.
- Pods cannot tell whether a Signal message was sent, delivered, or read. There is no API for that and there will not be one here, so there is no unread mark anywhere in this app — one would be permanently false.
- Pictures are not checked for what they show. This deployment has no image classifier configured and no human moderation queue, so the only controls on a bad picture are that somebody reports it, that it can be taken down, and that nobody joins without an invitation. Those are weaker for pictures than they were for text, and it is why Pods stays invite-only. If a checking service is ever switched on, pictures would be sent to that service — that changes who sees your content, so this contract would change first and name it.
- This code has not yet been reviewed by an independent security researcher — including the sealing code that every claim about your messages rests on. Until it has, treat every claim on this page as a stated intention backed by readable source, not as an audited guarantee.
- Stopping you signalling twice on one notice needs a marker that ties you to that notice, and there is no way around that. It is a keyed digest rather than your identifier, it cannot be read backwards, and markers from different notices cannot be joined — but somebody holding the key that makes them could test a guess about whether a particular person signalled on a particular notice. It is deleted with the notice. The cryptographic version that would remove even that was designed, reviewed by an adversarial pass, and abandoned with four separate fatal flaws; a small project should not ship cryptography it cannot afford to have reviewed properly.
- Severing your identifier from a notice after two days is a deletion we perform, in code you can read — it is not cryptography. For those two days the identifier is on the record and an operator with database access could read it. What the design guarantees is that afterwards there is no field left holding it and no index left to walk from you to your notices, not that it was never there.
- Two things stop working once a notice goes anonymous, and both are the price of it rather than oversights. Blocking someone hides their notices from you only while those notices still carry their identifier — older ones are no longer attached to anybody, so a block has nothing to act on. And deleting your account removes the notices still attached to you, but not the ones that no longer are; those stay up until their run ends, because nothing left connects them to you.
- A notice whose harm only shows up later — a listing for an event that turns out to be a scam after the fact — cannot be traced to whoever posted it. That follows directly from severing the link, it is not recoverable by any amount of engineering, and it is the honest cost of the board being anonymous.
- If any of this stops being true, this contract changes, its version changes, and you are asked to read and sign the new one. It does not change quietly.
Pods is 18+
- Nobody under 18, and no scraping, automation, or reselling access.
- No warranty of any kind. This is a prototype, it has not been audited, and it can be withdrawn or reset without notice.
Pods holds one approximate location for you, replaces it every time you move, and deletes it 45 minutes after you stop. It has never held your precise position: your phone rounds it off before sending. No advertising, no analytics, no data sales. Read the data contract · Terms · Privacy · See everything held about you