Horus

Privacy Policy

In plain language: your chats stay on the phones in the conversation. We do not run a Horus inbox. Optional features (a wake ping, a findable @ handle) send only what those features need — never the message text. Uninstalling the app is how you delete what was on the device. This page is the long version of that, written so App Store and Play reviewers — and you — can see exactly what happens.

1. Who we are

This Privacy Policy describes how the Horus project (“we,” “us,” “our”) handles information when you use the Horus iOS and Android applications and this website (together, the “Service”).

Horus is a messenger. Identity is created on the device. We do not operate a cloud account for you, and we do not run a message store that holds the contents of your chats.

Important: This Policy describes our practices. It is not legal advice. If you have questions about your situation, consult a qualified professional.

2. Scope

This Policy applies to the Horus apps and to this public website. It does not apply to other apps, websites, or networks you may use alongside Horus — including the Tor network, Apple, Google, or a public blockchain used only for optional handle claims — except as those parties process data as described below.

The Service may be used in more than one country. Tor and optional third-party systems operate globally. If you use Horus, you understand that sealed traffic may transit networks outside your country.

3. What we do not collect

We do not require, and the apps are not designed to send us:

We do not sell personal data. We do not use your chats for advertising or training models.

4. What stays on your device

Depending on how you use the app, the following typically remain in the app’s sandbox on your phone:

4.1 Keys and identity

Cryptographic keys and session state created on first launch. They never leave the device for a Horus account server. If you uninstall or lose the phone, we cannot restore them.

4.2 Chat history

Transcripts you keep in the app, including text and media you chose to save. They are encrypted at rest on the device (platform keystore / Keychain-backed encryption). Optional App Lock can require biometrics or the device passcode before the UI opens.

4.3 Display name and local settings

A display name you type, appearance choices, and toggles such as Stay connected, Wake when closed, Share uplink, and App Lock. These are local preferences.

4.4 Optional handle salt

If you claim an @ handle, a secret needed to update that claim is held on the device. The public registry sees a commitment, not that secret, and not your messages.

5. How messaging works (and what others can see)

When you send a message, the app encrypts it on the device (end-to-end). The network carries an opaque blob. We do not receive a copy of the plaintext.

5.1 Tor

Production delivery uses Tor onion mailboxes published from the app. Tor relays are independent operators. They can observe that encrypted traffic is moving on circuits. They are not trusted with message contents. Using Tor is inherent to how Horus delivers mail; it is not a Horus analytics product.

5.2 Invites

An invite (link, QR, or nearby Bluetooth transfer) contains what the other device needs to start a session. Anyone who has an unused invite can attempt to join until it is accepted, expires, or is burned. Do not post an unused invite in public.

5.3 The other person in the chat

Your peer can see what you send them, including media and any handle you announce in that session. A malicious peer cannot decrypt your other chats. They can still spam or mislead you in the session you accepted.

6. Optional features that leave the phone

6.1 Wake when closed

Off by default. If you enable it, a wake host we operate may store:

That host does not receive message bodies, chat identifiers, keys, or your display name. When someone sends you mail, a peer may ask the host to ping your token with a generic banner (“You have a new message”) and no preview. Apple and Google process that notification as they do for other apps.

Knowing the wake identifier is enough to request a ping. Pings are rate-limited. You can turn the feature off. Uninstalling, or unregistering from the app, is intended to delete the token we hold. We retain wake records only as long as needed to provide the ping, then drop them.

6.2 Optional @ handle

If you claim a handle, a public registry on the Internet Computer stores a commitment lock for that name — not your messages, not a directory of encryption keys, and not a log of who searched for whom that we operate. Changing the handle frees the old name. Existing chats are invite sessions and stay put. One handle per install.

6.3 Nearby Bluetooth and uplink

Nearby pairing and optional “share uplink” happen between devices you choose. We do not collect Bluetooth identifiers or location from these features. On some Android versions the OS still asks for location permission in order to scan; that is an OS requirement, not a Horus location product.

7. Processors and other parties

Depending on the features you use, categories of parties include:

We may also disclose information if required by law, to protect rights and safety, or in connection with a transfer of the project, to the limited extent we hold anything to transfer (for example wake tokens). We cannot decrypt your chats in response to a request, because we do not have the keys.

8. Device permissions

You can revoke permissions in system settings. Some features will then stop working.

9. This website

This site is static. We do not run analytics or advertising pixels on it. The only storage it uses in your browser is localStorage for the light/dark preference you set with the control in the header. GitHub Pages (or whatever host serves these files) will see ordinary web logs such as IP address and user agent according to that host’s policy — that is not a Horus account, and we do not combine it with chats.

10. Retention

On-device data lasts until you delete a chat, clear app data, or uninstall. Wake tokens last until you disable Wake when closed, unregister, or uninstall, and for a short grace period if a request fails. Handle commitments last until you change or release the name. We do not keep a Horus-side copy of your transcript.

11. Security

Messages are end-to-end encrypted on the device. History is encrypted at rest on the phone. Transport is designed so intermediaries see blobs, not plaintext. No method of running software on a phone is perfectly secure. A compromised device, a stolen unused invite, or traffic analysis can still harm you. Horus has not completed an independent audit. Use is at your own risk except where liability cannot be limited by law.

12. Your rights and choices

Subject to applicable law, you may have rights to access, correct, delete, or restrict processing of personal data, and to object to certain processing. In practice:

For a request about data we might still hold (for example a wake token), open a GitHub issue as described in section 16. We may need enough information to identify the token; we will not ask you to paste message contents.

13. Children

The Service is not directed to children under 13, or under a higher age where local law requires it. We do not knowingly collect personal data from children. If you believe a child has used Horus in a way that sent us a wake token or a handle claim, contact us via GitHub Issues and we will take reasonable steps to delete what we hold.

14. International processing

Tor, Apple, Google, and the optional handle registry may process data in many countries. We do not operate a regional Horus message region you can pin. If that is unacceptable, do not enable optional wake or handles, and understand that Tor itself is still global.

15. Changes

We may update this Policy. We will post the revised text on this page and change the “Last updated” date. Where required, we will provide additional notice in the app. Continued use after the effective date means you accept the updated Policy, except where your express consent is required.

16. Contact

For privacy questions, open an issue on the public repository: github.com/julienlhk/horus/issues. Please do not attach chat transcripts, keys, or unused invites.

Data controller: the Horus project operator. We do not publish a postal address on this site.