Waev Privacy Policy
Effective July 14, 2026
Waev is a local-first MeshCore companion. Most data stays on the device running Waev or on the MeshCore companion/OpenHop repeater the user chooses to connect. This policy describes the limited cases in which data leaves the app.
Privacy questions, access requests, and deletion requests can be sent to admin@waev.app.
Data Waev handles
Waev may handle:
- the local profile and avatar a user creates;
- connection addresses, credentials, and device identifiers needed to connect to a MeshCore companion or OpenHop repeater;
- contacts, channels, cached messages, delivery/read state, and notification preferences;
- radio, route, RF, device-health, and other mesh telemetry received from connected hardware;
- contact, profile, or device locations present in mesh metadata;
- foreground device location when the user invokes a location feature or enables optional MeshBars auto-discovery;
- interface preferences, restoration state, and local location-label caches;
- Survey session files created on the device; and
- crash diagnostics only when the user has explicitly enabled Bugsnag crash reporting.
App-owned copies are stored locally unless this policy says otherwise. Saved API tokens, login passwords, pairing codes, transport keys, and channel secrets use the platform's protected credential store (such as Apple Keychain or Android Keystore-backed encrypted storage); non-secret settings and caches use ordinary app storage. Protected credentials are device-bound and do not sync through iCloud. Waev does not require a Waev cloud account and does not operate a central chat relay.
How data is used
Waev uses this data to connect to hardware, display mesh state, send and receive traffic the user requests, power chat/map/terrain/Survey tools, deliver enabled notifications, preserve app state, and troubleshoot reliability. Waev does not use personal data for advertising or behavioral profiling.
Local connection security
Waev's MeshCore companion TCP connection and OpenHop HTTP connection are not transport-encrypted by Waev. Credentials, channel secrets, transport keys, messages, commands, and telemetry sent to an endpoint may be observable to other parties on an untrusted network. Waev rejects public endpoints, mixed or public DNS results, proxies, and redirects for these hardware connections and pins permitted names to validated private addresses. Use these endpoints only on a trusted local network or through a trusted VPN. Never port-forward them or expose them directly to the public internet. These controls reduce exposure but do not encrypt traffic, authenticate the server, or replace a security review of the connected hardware, network, and companion software. The detailed engineering boundary is recorded in docs/LOCAL_ENDPOINT_SECURITY.md.
Mesh transmissions
When a user sends a message, profile or location advert, radio command, or other mesh action, the selected data leaves Waev through the configured companion or repeater. Mesh nodes may relay that traffic, recipients may retain it, and connected hardware may keep its own history. Waev cannot recall data already transmitted over the mesh.
Direct and channel messages include the content plus routing and protocol metadata needed for delivery. A direct message can carry a mesh public-key prefix that lets a recipient associate it with the currently observed mesh identity. The identity holder can rotate that key; a new key appears as a new observed identity, and Waev neither requires a cloud account nor knows the person's legal identity. Public channel text carries a sender-supplied display name and channel/routing metadata, but no authenticated stable sender identity; a sender can change or spoof that name. Advanced reply references may be transmitted through a compact Waev envelope and remain associated with the referenced message; that reference does not authenticate the sender.
Users should treat mesh transmissions as disclosures to the intended recipients and any infrastructure needed to relay them. Scope or transport-key features do not change the retention behavior of receiving devices.
Sharing and service providers
Waev does not sell personal data and includes no advertising or marketing analytics SDK. Data is disclosed only:
- to connected hardware and mesh participants when the user requests a mesh action;
- to operating-system services needed to perform a requested feature;
- to map and elevation providers when those features run;
- to Bugsnag after the user has enabled crash reporting; and
- to the user's mail provider when the user reviews and sends a message report.
Network services necessarily receive connection metadata such as the user's IP address and the details needed to answer a request. Mesh message content is not sent to map or elevation providers.
User-initiated message reports
Choosing Report on a message does not automatically submit data to Waev. The app prepares a reviewable email addressed to admin@waev.app. The generated report body contains the selected report reason, conversation kind, channel name or direct contact ID as applicable, sender display name, message ID, UTC message time, and up to 600 characters of the selected message text. It is sent only if the user reviews and sends it. The user's mail provider processes the email under that provider's privacy and retention terms. When sent, the Waev privacy mailbox receives the report and the sender email address supplied by the user's mail service. Waev uses that information to investigate the report, respond to the sender when necessary, enforce published safety terms where Waev has the ability to do so, and meet legal obligations. It is not used for advertising or tracking. Report emails are retained only as long as reasonably needed for those purposes and are then deleted under the mailbox's retention process. A user may request access or deletion through the privacy contact, subject to legal or safety-preservation requirements.
If the mail app cannot open, Waev copies the same report to the clipboard and clearly states that it has not been submitted. Clipboard contents remain under the user's and operating system's control until the user pastes or replaces them.
Maps and elevation
- On iOS and macOS, every map view uses Apple MapKit. The Apple builds do not construct or request CARTO tiles. On other platforms, optional maps may load CARTO tiles based on OpenStreetMap data only after the user explicitly allows that third-party map-region sharing. The active provider receives network metadata such as the user's IP address and the map region needed to return the view.
- Terrain and coverage tools send latitude/longitude coordinate batches to OpenTopoData only after the user starts a calculation. The affected tools disclose this next to their calculation action. Elevation results are kept in a bounded in-memory cache for the current app process.
Those providers process requests under their own privacy and retention terms. Users who do not want a coordinate disclosed to those services should not run the corresponding network-backed map or terrain action.
Provider information is available from Apple, CARTO, OpenStreetMap, and OpenTopoData. Waev's App Store privacy response must reflect the production providers' actual logging and retention behavior, not only the local cache behavior described above.
Optional Bugsnag crash reporting
Crash reporting is off by default. In supported mobile builds, Bugsnag starts only after the user opts in and restarts the app. If enabled, the Bugsnag SDK receives unhandled Dart error stack frames and app version, operating-system version, device model, runtime, timing, and performance diagnostics needed to diagnose a failure. Native persisted crash capture remains disabled so withdrawing consent cannot leave a native crash on disk for a later opt-in to upload.
Waev deliberately disables Bugsnag's persistent user, automatic session, interaction/request breadcrumb, and SDK-usage telemetry features. Before an event is sent, Waev removes the SDK-generated device identifier, user fields, navigation context, feature flags, breadcrumbs, exception text, and the whole Flutter-generated metadata section. Any remaining metadata is recursively redacted for keys associated with messages, identities, addresses, locations, and credentials. Exception text is removed because a transport or parser error can otherwise contain user-authored or connection data. Waev does not correlate diagnostics with a mesh public key, profile, support record, or legal identity. It uses reports only to diagnose reliability and app-functionality problems, not for advertising, profiling, or cross-company tracking.
Bugsnag retains reports under the project's configured service retention. A user can turn crash reporting off in Settings > Privacy; new reports stop immediately in the current process. A report the SDK already accepted for upload cannot always be recalled. Reports already delivered remain subject to the project's service retention. Questions about access to or deletion of crash diagnostics can be sent to the privacy contact above. Bugsnag's privacy information is available at bugsnag.com/privacy.
Retention and deletion
Local data remains until one of the following occurs:
- the user deletes it through a feature-specific action;
- a bounded cache or configured cleanup rule expires it;
- the user runs Restart Setup;
- the app is uninstalled, subject to operating-system backup behavior; or
- transient in-memory data is discarded when the process ends.
Restart Setup clears Waev's protected credential-store namespace, ordinary app preferences (including connection settings, cached contacts/channels/messages, and restoration state), local Survey files, local-notification state, and app-owned Apple BLE restoration keys. It also schedules Bugsnag's local retry and device-identifier data for deletion before the next process can start the SDK; the deletion is deferred so it cannot race an active uploader. The only ordinary-storage value it preserves is an anonymous UTC date and request count until day rollover, solely to prevent Restart Setup from resetting OpenTopoData's public daily quota. The counter contains no identity, coordinates, or feature content. On Apple platforms, Waev also detects a fresh install before reading Keychain data and removes credentials left by a prior installation. Non-secret app data may be included in operating-system device backups according to the user's backup settings; protected Apple credentials remain device-bound and do not sync through iCloud. Restart Setup does not revoke operating-system permissions or Bluetooth bonds, erase data stored on connected hardware or other clients, or recall traffic already sent over the mesh. Data received by a third-party service follows that provider's retention rules.
Permissions
Waev requests permissions only when a related feature needs them:
- Bluetooth to discover and connect to MeshCore companions;
- Local Network to discover and connect to companion gateways and OpenHop repeaters;
- Foreground Location for maps, Survey, location-based organization, and terrain/route tools;
- Notifications for message, mesh, connection, and storage alerts the user enables; and
- Motion for the optional responsive visual treatment on the OpenHop control.
Optional MeshBars auto-discovery is off by default. After the user enables it, Waev may use an existing foreground-location grant while the app is active to coordinate requested mesh discovery sweeps; it does not convert that grant into background location access.
If Auto-switch on Home Wi-Fi is enabled, Waev reads the current Wi-Fi network name on the device to select the saved local connection profile. Some operating systems require foreground location permission before an app can read that name. The Wi-Fi name is retained in local app preferences and is not sent to Waev.
Supported platforms may also use background Bluetooth or background fetch to maintain requested connectivity and notifications. Permissions can be denied or revoked in system settings; the related feature may stop working.
Policy updates
Material changes will be reflected in the policy bundled with a subsequent Waev release, including a revised effective date. The current policy is always available in Settings > Privacy and Settings > About.
Use of live mesh features is also governed by the Waev Communication Safety & Acceptable Use, which describes prohibited content, local safety controls, reporting, and the limits of decentralized content removal.