Privacy Policy for Knockbox
This Privacy Policy describes how miramiao (“we”, “us”; www.miramiao.com) handles your information when you use Knockbox (“the app”).
The short version
Knockbox delivers notifications from a server you choose. It has no accounts of ours, no analytics, no advertising and no tracking. Which server holds your messages is your choice, and it decides who can read them. Two cases, and they are genuinely different:
- Your own server. You run the open-source Knockbox server yourself. Your messages live on your machine. We never see them and have no way to.
- Our public server. If you connect to the instance we operate, your messages are stored there so they can be pushed and synced — which means we hold them. Details below.
What the app stores on your device
Messages you receive, their attachments, your channel settings and the credential that identifies your device are kept in the app's own storage on your phone. The device credential is kept in the iOS Keychain and is not synced to iCloud. Deleting the app removes all of it.
If you use our public server
To deliver and sync notifications, that server stores the messages sent to your channels, the attachments you include, your channel settings, and the technical records needed to deliver a push (a device token issued by Apple, your device model and OS version, and delivery logs). It also records the IP address a message was sent from, so that abuse can be traced.
Message content is not end-to-end encrypted. The server has to read it to build the notification preview, to run search and to show you your own history. That means a server operator can technically read message content. On our public instance, that operator is us. We do not read your messages except where strictly necessary to investigate abuse or to comply with a legal obligation, and we never use them for advertising, profiling or training any model.
Messages on the public server are deleted automatically after a retention period shown on that server's own pages. You can delete individual messages or clear a whole channel at any time from the app; deletion is physical, not a hidden flag.
You are never required to use our server. Running your own removes us from the picture entirely.
Notifications
Delivering a push requires Apple's service. Your server sends Apple a device token and the notification content, and Apple delivers it to your phone. Apple's handling of that is covered by Apple's own privacy policy.
Permissions
- Notifications — to show the messages you asked for.
- Camera — only to scan a pairing QR code. No image is stored or transmitted.
- Local network — only if you point the app at a server on your own network.
- Photo library (add only) — only when you choose to save an image you received.
What we do not do
No analytics SDK, no advertising SDK, no third-party trackers, no device advertising identifier, no location access, and no account with us. The app is free and contains no purchases.
Children
Knockbox is not directed at children under 13, and we do not knowingly collect their information.
Changes
If this policy changes materially we will update the date at the top of this page.
Contact
Questions or a deletion request: info@miramiao.com