The short version
- No phone number, no email: an account is a login you pick yourself, like
fox:prizrak.im. - Message text, files, voice notes and calls are end-to-end encrypted. The server holds ciphertext only.
- The server does see metadata: who exchanges messages with whom, when, and how large. That is the honest price of federation — or run your own server.
- Nothing is sold, handed to advertisers or used for profiling. The apps contain no advertising SDK and no analytics SDK.
- The prizrak.im website does use Matomo, Google Analytics and a support widget. The app does not.
Who we are and how to reach us
Prizrak is developed and published by Prizrak — an independent, non-commercial project run by one author. There is no company behind it, no investors, and nothing to gain from your data.
For anything about privacy — questions, complaints, requests to delete data — write to privacy@prizrak.im, or message fox:prizrak.im inside the messenger. We answer in Russian and English.
Who this covers
Prizrak is an independent project, not a company. This policy covers the Prizrak apps for Android, Windows, macOS and Linux, the home server software, the relay and VPN nodes, the Ghost Bank service and the website prizrak.im.
Prizrak is federated: anyone can run a server. If you register on a server someone else operates, that person controls the machine your ciphertext and your routing metadata sit on. They cannot read your messages, but they can see who exchanges messages with whom and when. Choose a server you trust — or run your own, which is the only configuration where even the metadata stays with you.
What an account needs
No phone number. No email address. No real name. An account is a login you choose yourself, in the form name:server — for example fox:prizrak.im.
Your keys are generated on your device the moment you register, and the private parts never leave it. The server receives only public key material. Recovery works through a seed phrase that is shown to you once: it is the only way back into an account. Nobody — including the author of this project — can reset it or restore an account without it. A display name and an avatar are optional and are whatever you type.
What stays on your device
Your message history, drafts, the record of what you deleted, a small journal of your own sent messages, the thumbnail cache, your traffic counters and the text of the last crash all live in the app's private storage on your device. The crash text is shown to you on the next launch and is not sent anywhere.
Uninstalling the app removes all of it. Nothing in that list is transmitted for analytics, because the apps contain no analytics SDK and no advertising SDK at all.
What the server stores
This is the part most policies skip, so here it is in full. Your home server holds:
- your public key bundle and the list of your devices — public material only;
- an encrypted envelope for every message addressed to you: ciphertext and a nonce;
- routing metadata — sender, recipient or room, timestamp, message id, size, and which of your devices a copy is aimed at;
- for a self-sync row (your own copy of a message you sent), an open hint naming the conversation it belongs to, so that erasing a chat can erase that row too;
- when you were last seen, which accounts you exchange messages with, and your room membership;
- a sealed blob of your own settings — contact names, avatars, folders — encrypted with your account key and unreadable to the server;
- attachments and voice notes as encrypted blobs;
- a pointer to your encrypted backup, if you made one.
The server software itself does not record IP addresses. Whatever web server, proxy or hosting provider sits in front of it may keep its own access logs — that is the operator's decision, not the app's.
What the server cannot read
Message text, file contents, file names, voice notes, and the audio and video of calls are encrypted end to end. The server stores them and forwards them, and cannot decrypt any of it. The same is true of your own settings blob and of your backup.
Calls connect directly between devices where the network allows it; when it does not, a relay passes already-encrypted packets without being able to open them.
How long things are kept, and deletion
The server administrator sets a maximum retention for history — anything from one day to forever. For a private chat you can choose a stricter timer, and messages then expire on both sides. Saved messages are never removed by a timer.
Deleting a message removes it from your device and asks the other side to remove their copy too, with a tombstone so it cannot come back through a re-sync. Deleting a chat wipes it locally and instructs the servers to erase their copies, including attachments; if there is no connection, the request is queued and repeated until it succeeds. Deleting the app removes everything stored on the device.
Deleting your account and your data
Everything on your device you can delete yourself: wipe a chat, erase a message for both sides, or uninstall the app, which removes the local database with it.
To have an account removed from the prizrak.im server, send a request from that account to privacy@prizrak.im or to fox:prizrak.im in the messenger. We delete the account record, its key material, the stored envelopes, attachments, settings blob, room membership and the backup pointer within 30 days; encrypted backup chunks in the storage network expire with it and are unreadable in any case. If your account lives on someone else's server, that operator performs the deletion — ask them.
Backups
A backup is encrypted on your device with a key derived from your seed phrase, split into two-megabyte chunks, and spread across the storage network. Only a small pointer is kept on your home server.
Without your seed phrase the chunks are noise, and without the pointer they cannot even be located. Nobody can read your backup but you — which also means that losing the seed phrase loses the backup.
Notifications without Google
Prizrak does not use Google Firebase Cloud Messaging or any other push service. There is no google-services.json in the build and no Google messaging library. The app keeps its own connection to your server and runs a foreground service to stay reachable.
The benefit is that no third party learns who is messaging you or when. The cost is a permanent notification while the app is in the background, and somewhat more battery use. That trade is deliberate.
Android permissions and why each one exists
- Internet — talking to your server and to VPN nodes.
- Notifications — showing incoming messages and calls.
- Microphone — voice notes and calls. Used only while you are recording or in a call.
- Camera — taking a photo to send and video calls.
- Foreground service (delivery, and a special-use type for the VPN) — staying connected without a push service, and running the VPN tunnel.
- Wake lock, start at boot, ignore battery optimisation — so messages and calls still arrive when the phone is idle.
- Updates — the app does not install packages itself. Installed from Google Play, it is updated by Google Play; installed from prizrak.im, it checks the signed update feed and opens the download in your browser, and the system installer asks you to confirm.
- Query installed apps — the VPN can route selected apps through the tunnel and leave the rest alone; building that list requires knowing which apps exist. The list stays on the device.
- Storage (Android 9 and older) — saving received files where you can find them.
Prizrak does not ask for your address book, your location, or your phone identity. The contact list you see in the app is built from your own chats and the names you assigned, never from the phone's contacts.
The VPN, honestly
Access is granted by a ticket: a short-lived permission signed by the Ghost Bank that carries an opaque identifier and limits, not your login. A node checks the signature and does not learn who you are.
Nodes are ordinary servers, run by different people. Since node software 2.1.14, a relay does not record the address that connected to it, and an exit node does not record which hosts and ports connections go to: the node journal keeps only technical events without addresses. An operator can switch on a debug mode that records them, or change the software on their own machine, and we cannot control that. If that is not acceptable for what you are doing, run your own node — the software is yours to deploy.
Traffic inside the tunnel is encrypted between your device and the exit. Your traffic counters are kept on your device only.
On Android the VPN uses the system VpnService. Before it is turned on for the first time, the app shows how it works and what the nodes see, and asks for your consent; you can withdraw it on the VPN screen. Prizrak does not collect personal data through the VPN, does not show ads, does not redirect or modify your traffic for monetization and does not share it with anyone.
The device fingerprint for the free VPN period
The free trial is one per device, so the device has to be recognisable. The app reads a handful of system identifiers, hashes each of them with SHA-256 — salted, repeated ten thousand times — and sends only the hashes. Raw serial numbers never leave the device, and the hashes cannot be turned back into them.
The Bank considers a device as having used its trial if any one hash matches. That is the only purpose these hashes serve.
The Ghost Bank
The Bank issues VPN tickets and runs the 👻 wallet. It stores your login, your public wallet key, the display name you chose, whether you asked to appear in the public directory, your balance and transactions, and the device hashes described above. Being listed in the directory is your choice and can be turned off.
The Bank is a web service, so like any web service it sees the IP address a request comes from.
The delivered-message counter
Servers count how many messages they delivered and report that number to the Bank every few minutes, signed with the server's own key. The report contains a count, a user count, the server's domain and version — and nothing else. No content, no senders, no recipients, nothing tied to a person.
The website is not the app
The apps contain no trackers. The website does, and pretending otherwise would be dishonest. prizrak.im loads a self-hosted Matomo analytics script from stat.webcluster.org, Google Analytics, and a live-support chat widget from chat.phoenix.lol. Between them they can see your IP address, your browser, and which pages you opened — the ordinary web-analytics picture.
None of that follows you into the messenger. If you would rather not be counted on the site, block the scripts or simply use the apps.
Children
Prizrak is not directed at children and is not designed for them. We do not knowingly collect anything about a child, and there is nothing to collect: no profiles, no advertising, no behavioural data.
Your data, your keys
The keys are on your devices, so most of what a privacy law calls your rights you can simply exercise yourself: read your history, delete a message everywhere, wipe a chat from the servers, export a backup, or delete the app and take everything with you. If you want an account removed from a server, ask whoever runs that server; on prizrak.im that is us.
Questions, complaints and requests: write to fox:prizrak.im inside the messenger, or to privacy@prizrak.im.
Changes to this policy
If what the software does changes, this page changes with it and the date at the top moves. We do not quietly widen what we collect — the list above is meant to be checkable against the source code, and the apps and servers are what they are described to be here.