Temwen Privacy Policy
1. What Temwen does
Temwen lets adults keep fixed witness claims on an Android device and exchange requests, signed vouchers, revocations, and short-lived presentations with a co-present phone by QR. Temwen records what people say they personally know. It is not a government identity document, legal identity service, proof of citizenship, or official registry.
2. Data stored on your device
Temwen stores the following only on the device where the app is used:
- A randomly generated seal key pair and opaque seal fingerprint.
- Fixed relationship and duration choices contained in vouchers you receive or issue.
- Cryptographic voucher tokens, signatures, revocation state, presentation material, standing calculations, local reports, and blocked-issuer fingerprints.
- Your settings. If you set a Temwen PIN, the app stores a salted SHA-256 hash and a fresh random 16-byte salt. It never stores the plain PIN.
Temwen does not ask for or store a name, portrait, biometric template, government number, phone number, address, contact list, location, open profile text, or account credential.
3. Camera and biometric access
Camera: access is requested only when you open the QR scanner. Camera frames are examined in memory for a Temwen QR and are not saved or transmitted.
Biometric prompt: fingerprint or face unlock is optional. Android performs the biometric check and tells Temwen only whether it succeeded. Temwen never receives fingerprint or face data. The separate Temwen PIN is not your device PIN, and device credentials cannot unlock the app.
4. Registry collection, sharing, and providers
Temwen has no user account, analytics, advertising, public profile, or cloud copy of a credential. Its dedicated registry stores an app-generated public key and the server-day on which that key was first seen. During token preparation it processes the public key, a signed request proof, epoch and token count, blinded cryptographic challenges and responses, and a short-lived request identifier.
If both parties separately opt in to report the same in-person meeting, the registry stores the matching public-key edge and uses the graph to assign a coarse standing band. It does not receive the relationship, duration, credential, presentation, subject name, phone number, contact list, government identifier, or biometric data. Age alone does not grant standing, and a registered key is not proof of a distinct person or device.
Cloudflare provides the encrypted network transport and Durable Object infrastructure and necessarily processes ordinary network metadata such as IP address while carrying requests. Temwen does not sell registry data, use it for advertising, or intentionally link the public key to a name or account.
QR content moves directly from one visible phone screen to another phone's camera at the users' direction. Camera frames and the QR-carried credential are not uploaded to the registry.
5. Security and backup
Private seal records are encrypted with AES-GCM using a key protected by Android Keystore. Cloud backup and device-transfer backup are disabled. A person with access to an unlocked device may still be able to view app content, so Temwen offers an optional independent app lock.
6. Retention and deletion
Device-local records remain until you revoke, report, block, retire the seal, clear app storage, or uninstall Temwen. “Retire this seal” deletes the current local seal and its vouchers, reports, and block records, then creates a new local seal.
The registry retains its pseudonymous public-key first-seen record and mutually reported graph edges while the service operates so signed key age and graph calculations remain consistent. Retiring or uninstalling the app does not erase that remote history. There is no name-based account lookup or remote-delete feature, and this policy does not claim otherwise.
7. Reports and support email
Report and Block creates a local safety record and excludes that issuer from future presentations on the device; it is not uploaded to the registry. Email actions open your chosen email app using a mailto: link. Temwen does not send the email itself and does not attach voucher contents. If you choose to send an email, your email provider and the developer receive the information you type under their respective privacy practices.
8. Children and safety
Temwen is intended for adults and is not directed to children. Child sexual abuse and exploitation, grooming, trafficking, and content that sexualizes or exploits children are prohibited. Read the separate Temwen Child Safety Standards for reporting and response details.
9. Changes
If this policy changes, the updated version and effective date will be published on this page. Material data-practice changes will also be reflected in the app and Google Play disclosures before release.
10. Contact
Developer: Saifullah Ahad
Email: www.saifullah.ai@gmail.com
Website: https://saifullah.ai
Child-safety reports may use the same public email with the subject “Temwen child-safety report.” Contact local emergency services if someone is in immediate danger.