Privacy Policy

Last updated: August 14, 2026

The short version

25|8 does not track you, does not run analytics, does not share your data with third parties, and does not show ads. Your cryptographic identity key is generated on your device and never leaves it. We cannot sign anything on your behalf because we never hold your key.

What we store on our servers

Business data you publish: your business name, handle, menu, hours, location, photos, updates, and event appearances. This is the content you choose to make public on your visitor page. It is stored on Cloudflare's infrastructure (D1 database and R2 object storage).

Session tokens: a random identifier stored as an HTTP-only cookie that keeps you logged in for up to 30 days. It contains no personal information — it is a random string that maps to your cryptographic identity on our server.

Visitor tokens: when someone visits your page, a random identifier (UUID) is stored as an HTTP-only cookie on their browser. This is not linked to any personal identity. It tracks visit count for your loyalty features and is never shared.

Connection events: a timestamp and method (QR scan, NFC tap, or manual save) each time a visitor interacts with your page. These are attributed to the anonymous visitor token, not to any personal identity.

Push notification tokens: if you enable notifications, your device's Expo push token is stored so we can send you alerts (new visitor, inquiry received). This is a device identifier, not a personal identifier.

What we do not collect

We do not collect your name, email address, phone number, or any personal contact information. We do not collect your physical location (the location permission is used only when you explicitly set coordinates for an event appearance). We do not use any analytics service. We do not use any advertising SDK. We do not use App Tracking Transparency because we do not track you.

Your identity key

Your 25|8 identity is an Ed25519 cryptographic keypair generated entirely on your device. The private key is encrypted at rest in your device's secure hardware (iOS Keychain) under biometric protection (Face ID or Touch ID). It is never transmitted to our servers, never stored in our database, and never accessible to us. When you publish or update your business information, your device signs it with your private key and our server verifies the signature — but we never hold the key itself.

Data retention and deletion

Your published business data remains on your page as long as you choose. If you stop paying for optional tools, your page freezes in its last state rather than disappearing — we do not delete your data as punishment for not paying. If you want your data removed entirely, contact us and we will delete it.

Third-party services

Cloudflare: our server infrastructure runs on Cloudflare Workers, D1, and R2. Cloudflare processes requests to serve your page. Their privacy policy applies to infrastructure-level data (IP addresses in server logs, etc.).

Apple: in-app purchases are processed by Apple. We receive a transaction confirmation but not your payment details. Apple Wallet passes for the Regulars feature are delivered through Apple's PassKit infrastructure.

Expo: push notifications are routed through Expo's notification service using a device-level push token. Expo does not receive your business data or personal information.

Children

25|8 is a business tool for business owners. It is not directed at children under 13 and we do not knowingly collect data from children.

Changes to this policy

If we change this policy, we will update the date at the top. Material changes will be communicated through the app.

Contact

Questions about this policy: hello@at258.app