Privacy Policy - Nirokh
1) What Nirokh does
Nirokh is provided by Saifullah Ahad. It lets people build a trusted circle by pairing phones face to face, then exchange an expiring cryptographically signed Yes or No presence check during a suspicious live voice call. It also provides a saved-number callback action.
2) Data Nirokh handles
To provide pairing and live verification, Nirokh sends the following to its protocol service:
- a random device identifier, Ed25519 signing public key, X25519 agreement public key, and a label describing how private-key material is protected;
- a Firebase Cloud Messaging routing token;
- the opaque relationship identifier and six-word fingerprint associated with a pairing;
- one-time session identifiers, random challenges, signed Yes/No answers, and timestamps;
- request timestamps used to enforce limits of six checks per ten minutes and twenty per day.
Nirokh does not send contact names, phone numbers, call audio, call content, camera images, private cryptographic keys, the local display name, App PIN, or proof-history notes to the protocol service.
The display name, one callback contact selected through Android's single-contact picker, paired public identity, and up to 100 proof-history results are kept in encrypted app storage on the device. The App PIN is stored only as a salted SHA-256 hash with a random 16-byte salt. The plain PIN is never stored.
3) Camera, notifications, and phone access
- Camera: used only after you choose to scan an in-person pairing QR. Frames are analyzed on the device and are not saved or uploaded.
- Microphone: not requested by this release. Nirokh never records, analyzes, saves, or uploads call audio.
- Phone permissions: requested only when you use the saved-number callback shield, so the app can try to end the suspicious call and dial the one contact you selected. If Android cannot end the call, Nirokh opens the dialer instead.
- Notifications: used to alert a paired phone about an expiring presence request and to deliver a quiet, signed warning to the responder's other paired phones after a No answer.
4) How data is used
Protocol data is used only to register a device's public identity and push route, prove reciprocal pairing, route signed verification messages between paired devices, deliver verified trusted-circle warnings, evaluate session evidence, prevent abuse, and fulfill deletion or unpairing requests. Nirokh does not build advertising profiles, sell data, use data for cross-app tracking, or analyze call content.
5) Service providers and sharing
- Cloudflare Workers and D1 host the Nirokh protocol API and the data described above.
- Firebase Cloud Messaging delivers data-only presence requests and signed quiet No warnings to paired phones. Firebase receives the routing token and technical delivery information needed for push delivery.
- Web3Forms is used only if you open About Developer, choose Send feedback, and submit the form. It receives your message, optional reply email, app version, device manufacturer/model, and Android version so it can relay the message to www.saifullah.ai@gmail.com.
No feedback is sent until you press Send. Nirokh includes no advertising, analytics, social-media, or crash-reporting SDK.
6) Retention and deletion
Verification envelopes are retained for no more than 24 hours so the service can deliver results and enforce daily abuse limits, then deleted automatically. Active public-key records, push tokens, and pairing edges remain while the device identity is active.
Choose More → Delete Nirokh identity → Delete permanently to remove the phone's local keys, pairing, callback contact, proof history, and App Lock material and to immediately erase its server-side public keys, push token, verification sessions, and pairing edges. The service retains only a minimal opaque deleted-device tombstone for up to 30 days to prevent accidental resurrection and complete cleanup; it contains no public key, push token, relationship, contact detail, or message. Uninstalling without first using in-app deletion removes local data but cannot notify the server, so use the in-app control first.
7) Security boundaries
Transport uses HTTPS. On Android 9 and 10, the required Ed25519 and X25519 private seeds are encrypted with an AES-256-GCM key generated by Android Keystore; Nirokh describes this accurately as KEYSTORE_WRAPPED, not as native non-exportable Ed25519/X25519. This release has no production Green path: a valid signed Yes is Amber because it does not prove the familiar voice is on the exact live channel.
8) Children
Nirokh is intended for adults and is not directed to children under 13. It has no public profile, chat, feed, discovery, or user-generated-content feature. If you believe a child provided personal information through optional feedback, contact us so it can be removed.
9) International processing
Cloudflare, Google Firebase, and Web3Forms may process technical data in countries other than yours. Data is limited to what is described here and protected in transit.
10) Changes
This policy may change when Nirokh's behavior or legal requirements change. The current version will remain at https://privacy.saifullah.ai/nirokh.html with a revised effective date.
11) Contact
Saifullah Ahad
Email: www.saifullah.ai@gmail.com
Website: https://saifullah.ai
Phone: +880 1711-134346
Location: Dhaka, Bangladesh