# Privacy Policy

> How Knit handles your data. Short version: it stays on your phone. No accounts, no servers needed, and nothing is tracked or sold.

Last updated: September 2026

## Introduction

This Privacy Policy explains how Jeff Mixon, the independent developer of Knit, handles information in connection with the Knit Android application (package app.getknit.knit) and this website at getknit.app. Knit is an offline-first messenger that needs no servers, and this policy applies to both the app and the site. By downloading, installing or using Knit, or by visiting getknit.app, you acknowledge the practices described here.

## The short version

Knit is built so your data stays on your device. The mesh uses no accounts and no servers, so there is no central place where your messages or identity are kept, and nothing is sold or shared. The one optional exception is Internet relays: off until you turn them on, and described in their own section below. Everything else here spells the rest out in more detail.

## Who is responsible for your data

Knit is designed, published and maintained by Jeff Mixon as an individual, independent developer, not a company. Because the Knit mesh works without servers or user accounts, Jeff Mixon does not receive, store or have access to your messages, contacts or identity. The role of a "data controller" is therefore minimal in practice: the information the app works with lives on your own phone and under your own control. The one server Jeff Mixon operates is the default Internet relay, covered below: it is idle until you switch relays on, holds sealed copies it cannot read, and sees only connection metadata.

## Information collected by the Knit Android app

- **No account, no sign-up.** You are identified only by a randomly generated profile (a name, status and avatar, plus a friendly auto-generated alias) that is created and stored on your device. No email address, phone number or other real-world identifier is required or collected.
- **Messages travel directly between nearby devices** over Bluetooth and Wi-Fi. Message content, your profile and your chat history are stored locally on your phone. Nothing is sent to a server unless you switch on Internet relays, and then only as sealed copies the relay cannot read (see Internet relays, below).
- **Link previews are off by default.** If you turn them on in Settings, your phone fetches a page's title and picture over the internet when you paste a link, and sends that card along with your message. The website you linked sees your IP address, as it would if you opened it; the people you send to never contact it.
- **Location is sent only when you choose to share it.** Knit does not track your location. From 2.6.0 you can send where you are from a chat's menu: Knit reads your position only between that tap and the send, and it goes into that chat as a card that opens in any maps app. Android asks for the location permission the first time you do this, and never before. Older versions of Android may also require a location permission for Bluetooth and Wi-Fi scanning (see Android permissions below); that permission is never used to read where you are.
- **On-device AI moderation.** The optional content filter runs entirely on your phone using a bundled AI model: it screens for abusive text and blurs explicit images behind tap-to-reveal. Images and text are never uploaded for analysis, and you can switch the filter off.
- **No analytics or advertising.** Knit contains no third-party analytics, advertising or tracking SDKs, and does not build a profile of you for marketing.

## How information is used

Because information stays on your device, Knit uses it only to provide the app's core functions: to show and relay your messages to nearby devices, to carry a sealed copy through an Internet relay you have switched on, to display your profile and the profiles of people around you, and to run the optional on-device moderation filter. Your information is not used for advertising, is not sold, and is not shared with Jeff Mixon or any third party for their own purposes.

## How your messages are protected

**Direct and group chats are end-to-end encrypted.** The message body, mentions and image attachments in your one-to-one and group conversations are sealed so that only the participants can read them, even though each message relays hop-by-hop through other people's phones on the way. You can confirm you are talking to the right person by comparing a safety number or scanning a QR code together in person.

**The public Nearby broadcast room is plaintext by design.** It has no fixed set of recipients, so anyone within range can read what is posted there. Treat it like speaking out loud in a crowd: it is not a private or encrypted channel.

**Those chats are forward-secret, within limits.** Knit derives fresh keys as a conversation goes back and forth and deletes the ones it has finished with. Someone who records mesh traffic as it passes cannot decrypt it later, because the keys that would open it no longer exist on either phone. Two limits come with that. Keys turn over in blocks of messages rather than one key per message, so anything that is recovered covers the block around it. And a conversation with someone still running an older version of Knit falls back to the previous scheme, which has no forward secrecy at all, until they update.

**Reactions and delivery receipts are sealed too.** In direct and group chats, an emoji reaction and the tick that says your message arrived are encrypted like the message itself, so a phone relaying them cannot tell who reacted to what, or when something reached you. Both fall back to their older cleartext form toward someone still running an older version of Knit, and in the public Nearby room they stay cleartext with the room.

**Your messages are encrypted on the phone as well.** Knit keeps conversations, contacts and key material in an encrypted database. Its key is wrapped by a hardware-backed key in Android's keystore, which never leaves the device and is excluded from cloud backup, so the files are unreadable if they are copied off the phone. That is not a substitute for your screen lock: someone who can unlock the device and open Knit sees what is in it, as with any messenger.

**A paired Meshtastic radio adds range on its own switch.** If you pair a Meshtastic board over Bluetooth, direct messages and the public Nearby room can cross it at kilometre range. A direct message stays end-to-end encrypted on the way; its sender, recipient, timing and size travel in the clear on a channel anyone in range can listen to, which is why LoRa for direct messages has a switch of its own. Group chats and attachments never ride the radio. Knit sets up its own channel on the board with position sharing turned off, and never reads your phone's location for it. The Meshtastic room mirrors the board's primary channel, which sits outside Knit's encryption like the Nearby room; nothing posted there crosses Knit's mesh or touches the internet.

**Encryption still has limits.** It hides what you say, not that you are saying something. An observer watching the mesh sees frames moving between phones, and can tell that your phone sent something shortly after a message reached it, without reading either one.

## Internet relays (optional)

**Relays are off until you turn them on.** Out of the box, Knit opens no connection to the internet: Internet relays and link previews (above) are each a switch in Settings that starts off. Relays are for keeping a direct or group chat moving when nobody is in radio range: with them on, Knit uploads sealed copies of those messages to the relays on your list, and a phone that connects later collects them. The public Nearby room never touches a relay.

**A relay cannot read what it holds.** It stores ciphertext it has no key for and no way to ask for one, so it cannot read your messages, reactions, receipts or attachments, and it does not know who is talking: no names, no numbers, no device identities, no contact list. What it can see is your IP address, that a conversation, identified by a random number, is active, and when you send and roughly how much. Knit shows you this before the switch goes on.

**Copies expire within 48 hours.** A relay deletes each sealed copy within 48 hours of receiving it, whether or not it was collected. Turning relays off stops new uploads immediately; copies already on a relay are unreadable to it and expire on the same clock. A relay holds recent traffic, not a backup of your conversation.

**The default relay is run by Jeff Mixon.** Knit comes with one relay on its list, lax.spool.getknit.app, which Jeff Mixon operates on a server rented from Linode in Los Angeles, United States. It runs Knit Spool, the open-source relay software (AGPL), and sealed copies sit on its disk only until they expire. The proxy in front of it keeps a short connection log that overwrites itself as it fills, with part of each IP address masked and no browser or device identifiers; that log exists to keep the service running and is not analysed, shared or sold. You can remove the default relay, add relays run by anyone else, or run your own.

**Knit Hosted is a separate, paid service.** Jeff Mixon also runs Spools for people who would rather not run their own, as Knit Hosted at hosted.getknit.app. If you sign up there, that service's own privacy policy and terms apply, and both are published on that site; this policy covers the Knit app and getknit.app. To Knit it is a relay like any other: it stays off until you add it, it holds sealed copies it cannot read, and it sees the same connection metadata described above. Knit works without it.

## Android permissions

To discover the phones around you, the Knit Android app requests the nearby-devices permission, and on older versions of Android a location permission as well, because the system ties Bluetooth and Wi-Fi scanning to it. Knit works best when allowed to run in the background so it can keep relaying messages for the people nearby. Sending your location from a chat asks for the location permission the first time you use it, and only then. You can review or revoke these permissions at any time in Android's settings, though doing so may prevent the app from finding nearby devices. Knit requires Android 10+.

## Data sharing and third parties

Jeff Mixon does not sell, rent or share your personal information. The Knit mesh holds nothing on a server, and the default relay holds nothing it can read, so there is nothing to hand over. Links from the app or this website take you to services run by others, each governed by its own privacy policy; Jeff Mixon has no control over, and is not responsible for, how they handle your data. They are:

- **Ko-fi, Liberapay and GitHub Sponsors.** Where you can support development. A contribution is made on that platform, under its terms; getknit.app takes no payment itself and never sees your card or bank details.
- **Google Play and F-Droid.** Where you install Knit. A store may collect information about the download in accordance with its own policies.
- **GitHub.** Where the Knit source code is published.
- **Mastodon.** Where Knit posts news, at mastodon.social.
- **What's New (whatsnew.fyi).** An index of every Knit release.
- **YouTube.** Where the trailer plays from, and only once you press play (see This website, below).
- **Linode.** The hosting provider for the default Internet relay. When you have relays switched on, it carries the server's network traffic under its own terms; it has no access to what the relay holds.

## Data retention

Your Knit profile, messages and settings are kept on your device for as long as the app is installed. Clearing the app's data or uninstalling it removes that information from your phone. Jeff Mixon keeps no server-side copy or backup of your data, so once it is removed from your device it is gone from everything he operates; a sealed copy on an Internet relay, if you had relays on, expires within 48 hours regardless. Messages you have already sent may still exist on the devices of the people who received them.

## This website

getknit.app is a static page served from a standard web host. It sets no cookies and runs no analytics or trackers. If you use the light/dark switch, your choice is kept in your browser's local storage, one value read only by this site, and nothing else is stored.

The trailer loads from YouTube only when you press play, through YouTube's privacy-enhanced embed. From that moment the player is Google's, and Google's privacy policy applies to what it does.

The host may keep standard server access logs (such as IP address, timestamp and requested URL) for security and operations, as is typical for any website. These logs are not used to identify or profile visitors.

## Children's privacy

Knit is not directed to children under the age of 13 (or the equivalent minimum age in your jurisdiction), and Jeff Mixon does not knowingly collect personal information from children. The app keeps its data on the device and the mesh sends nothing to a server, so Jeff Mixon gathers no personal information about any user, child or adult, beyond the connection metadata a relay sees if relays are switched on.

## Your privacy rights

Depending on where you live, you may have rights to access, correct or delete personal information an organisation holds about you. Jeff Mixon holds no account, profile, message or contact data for you on any server, so there is nothing on his side to look up, export or delete, and the default relay's connection log holds only masked addresses that cannot be searched by person. You remain fully in control of the data on your device: you can edit your profile inside the app, and clear or uninstall the app to erase it. Questions about your rights are welcome at the contact below.

## International users

Knit can be used anywhere. The mesh keeps your data on your own device and sends nothing to a central server, so using it does not involve Jeff Mixon transferring your information across borders. The one exception is the default Internet relay, which is in the United States: if you switch relays on from another country, your connection metadata reaches a server there. Choose a different relay, or run your own, if you would rather it did not.

## Supporting Knit

Knit is free. It is built and published by Jeff Mixon as an individual, not a company, charity or non-profit. Contributions through Ko-fi, Liberapay and GitHub Sponsors are voluntary support for development: they are not tax-deductible, they do not purchase goods, services or perks, and nothing is owed in return. Each payment is made on that platform, under its terms and whatever refund or cancellation policy it offers. getknit.app takes no payment itself and never sees your card or bank details.

## Changes to this policy

Jeff Mixon may update this policy from time to time, for example to reflect new features or legal requirements. When the policy changes, the "Last updated" date at the top of this page will be revised, and continued use of Knit or getknit.app after a change means you accept the updated policy.

## Contact

This policy, the Knit Android app and this website are maintained by Jeff Mixon. If you have any questions about your privacy or about how Knit works, you can reach out by email at hello@getknit.app.

Canonical page: https://getknit.app/privacy/
