Privacy Policy
Baadhis compares fixed connection checks from devices in an invite-only room. It does not inspect browsing content, scan a local network, or collect a Wi-Fi name or location.
1. What Baadhis does
Baadhis lets two to four people who know each other compare internet connection evidence. One person creates a short-lived room, another joins with an eight-character code, and each device runs focused reachability checks. The Baadhis service combines those measurements into a shared, ranked explanation and next action.
2. Data we collect
| Data | Why it is used |
|---|---|
| Anonymous device account Random account identifier, public signing key, account timestamps | Authenticate requests without an email/password and prevent another device from changing a room. |
| Room state Random room identifier, hashed invitation code, participant ordinal, same/different-connection choice, revision, status, expiry | Join the devices, apply host/participant permissions, and keep one authoritative result. |
| Diagnostic measurements Connection transport category, Android validated/captive state, DNS/direct/HTTPS success or timeout, latency, completeness, capture time, random round identifier | Compare independent observations and calculate the ranked explanation. |
| Security and abuse controls Short-lived request nonce/timestamp, signature status, and a keyed one-way rate-limit hash derived from the connecting IP address | Reject replayed requests and rate-limit code guessing or automated abuse. The raw IP address is not written to the Baadhis database. |
| Local app data Non-exportable private signing key, cached room/result, queued submission, display preferences | Sign requests, show the latest result during an interruption, and retry one completed submission safely. |
Data Baadhis does not ask for
Baadhis does not ask for or store your name, phone number, postal address, contacts, precise or approximate location, Wi-Fi SSID, BSSID, router address, raw public IP in its database, browsing history, URLs you visit, message history, photos, videos, audio, files, advertising identifier, payment information, or health data.
3. How we use the data
- Register and verify the anonymous device account.
- Create, join, update, leave, erase, and expire invite-only rooms under server-enforced owner and participant permissions.
- Calculate and display one shared diagnosis revision, confidence, evidence, and next action.
- Queue a completed check during a connection interruption and prevent duplicate writes.
- Protect the service against replay, code guessing, excessive requests, and unauthorized room access.
We do not use this data for advertising, behavioural profiling, sale, credit decisions, or training a general-purpose model. There is no advertising or analytics SDK in the app.
4. Services and data sharing
Cloudflare Workers and D1
The production API and short-lived database run on Cloudflare. Cloudflare processes network requests and may automatically handle technical information such as an IP address to deliver and protect the service. Baadhis stores only the one-way rate-limit hash described above, not the raw IP address. Cloudflare acts as an infrastructure/service provider. See Cloudflare's privacy policy.
Android network services
The app uses Android's connection capability APIs and performs small DNS/direct/HTTPS reachability checks. Network operators, DNS resolvers, and the destinations necessarily receive ordinary network traffic and the source IP used for any internet request. The diagnostic payload sent to Baadhis contains only the normalized result, not a browsing request or network name.
We do not sell personal data. We do not share it with advertisers or data brokers. Service providers process it only to deliver the functions described here or where required by law.
5. Retention and deletion
- Active rooms and their measurements expire no later than 24 hours after creation.
- If the room owner chooses Leave room, the room ends and its dependent records expire no later than 2 hours afterward. A non-owner who leaves is removed from active participation and their probe evidence is deleted; the room remains active for the others.
- Used request nonces expire after 10 minutes. Rate-limit buckets expire after their rate-limit window plus 1 hour; the longest current retention is about 70 minutes.
- An anonymous device identity expires after 30 days without activity.
- Expired rooms are unavailable immediately. Bounded physical cleanup runs during service request activity; no scheduled task is used.
The room owner can choose Erase this room to send an authenticated DELETE request that immediately removes the room and its dependent records. Any participant can choose Delete this device account; a successful authenticated DELETE immediately removes the server identity, its memberships and evidence, then the app clears its local room cache and signing key. Deleting the owner's device account also deletes rooms owned by that identity. Otherwise, the anonymous device identity expires after 30 days without activity. Uninstalling clears local app data but cannot send a server deletion request; active or ended room records still expire as described above.
6. Contact by email
The About Developer screen can open your chosen email app with the developer address and a Baadhis subject line. Baadhis does not collect, relay, or store that message through its app or service. Nothing is sent unless you choose to send it from your email app; your email provider then handles it under its own terms and privacy policy.
7. Security
Requests use HTTPS. The app creates a P-256 signing key in Android Keystore and sends only its public key. Signed requests include a timestamp, nonce, and body hash. Server permissions, prepared database statements, code-attempt limits, participant caps, payload limits, idempotency keys, and automatic expiry reduce unauthorized access and abuse. No internet service can be guaranteed risk-free; please report a suspected issue to the contact below.
8. Children's privacy
Baadhis is a general household utility and is not directed to children under 13. It has no profiles, chat, public posts, media sharing, contact discovery, or location sharing. We do not knowingly collect personal information from a child under 13. A parent or guardian with a privacy question may contact us at the address below.
9. Changes to this policy
We may update this policy when the app, its service providers, or legal requirements change. The effective date at the top will be updated, and material changes will be described on this page before they apply.
10. Contact
Developer: Saifullah Ahad
Email: www.saifullah.ai@gmail.com
Website: saifullah.ai