Privacy Policy
Effective Date: March 25, 2026
Last Updated: March 25, 2026
HermitX (the "App") is a free and open-source mobile client for Spacebar. This Privacy Policy explains our approach to privacy and how we handle information.
1. Decentralized Nature of Spacebar
HermitX is a client application. It does not own, operate, or control the Spacebar instances (servers) that you connect to.
Your personal data (including account info, messages, and profile data) is primarily processed and stored by the Spacebar instance you choose to join. We encourage you to review the privacy policy of each instance you use.
2. Information Handled by the App
2.1 Local Storage
To provide a seamless experience, HermitX stores the following data locally on your device:
- Authentication Tokens: To keep you logged into your chosen instances.
- Cache: Images, avatars, and message history to reduce data usage and improve performance.
- Settings: Your theme preferences, notification settings, and custom instance URLs.
2.2 Account and Message Data
When you use HermitX to communicate, your data (messages, media, reactions) is transmitted directly between your device and the Spacebar instance API. HermitX developers do not have access to this data unless they also operate the instance you are connected to.
2.3 Multi-Factor Authentication (MFA)
HermitX supports TOTP-based MFA. If enabled, the app processes your authentication codes locally to facilitate secure login.
3. Permissions
The App may request the following permissions to enable specific features:
- Camera/Gallery: To allow you to upload and share images or videos.
- Notifications: To alert you of new messages and mentions.
- Storage: To save downloaded files and maintain the local cache.
4. No Data Collection by Developers
The developers of HermitX:
- Do not collect analytics or tracking data.
- Do not sell your personal information.
- Do not have a centralized database of users.
5. Security
HermitX implements security features such as:
- External Link Warnings: Alerts you before opening links in an external browser.
- Secure Storage: Uses platform-specific secure storage for sensitive tokens where available.
6. Open Source and Transparency
As an open-source project (licensed under GPL-3.0), the source code for HermitX is available for public audit at our Git Repository.
7. Contact
Since HermitX is a community-driven project, if you have privacy concerns or find a security vulnerability, please contact us via our issue tracker:
- Git Repository: https://git.disroot.org/hermit/mobile
- Support: https://git.disroot.org/hermit/mobile/issues