COM1_
TERMINAL MODEGET STARTED →
LEGAL://PRIVACY

Privacy policy.

How COM1 handles identity, chat content, third-party requests and account deletion.

1. Who operates COM1

COM1 is a communication application developed by Najad (website: najad.dev). This policy covers COM1 app functions and the informational website at com1.najad.dev. Questions or privacy requests can be sent to mail@najad.dev.

2. Information processed

  • Account and profile: chosen COM1 user ID, a system-generated internal authentication alias, authentication records, display name, handle, optional bio/status, and account settings. Passwords are used for authentication, not published as profile fields.
  • Communications: messages, attachments, group membership, delivery/read status, replies, and permitted metadata needed to route chats. Standard chat content is server-readable; Secure Link content is encrypted on client devices where enabled.
  • Device and operations: push notification tokens, device-installation identifiers, app/notification state, security and rate-limit events, connection/session logs, and technical metadata such as timestamps and IP addresses that infrastructure providers may handle.
  • Files and media: photos, recordings and other files that you choose to send. Camera/microphone access is used for actions you initiate and subject to platform permission controls.
  • Optional integrations: AI provider keys, bot tokens, HTTP profile settings, SSH host details, and relevant commands or payloads. Some of these are stored on the device via secure storage; external services you contact will receive the requests you initiate.
  • Support requests: the information you email to us when requesting assistance or account deletion.

3. How information is used

To create and authenticate accounts; connect participants; transmit, deliver and display content; support device caching and optional backups; send notifications; prevent abuse; protect the service; troubleshoot errors; and execute user-initiated integrations.

4. Content privacy, encryption and local retention

Standard COM1 conversations are not end-to-end encrypted. They use encrypted transport and backend access controls, but service infrastructure can process their content. Secure Link is an opt-in manual shared-secret scheme that encrypts supported content on devices. It does not hide all metadata and is not a substitute for an audited forward-secret protocol.

Free users' delivered message history may be removed from general server message storage after durable delivery to intended participants and retained primarily in the recipient's encrypted local cache. If other participants qualify for cloud backup, server rows may remain for those accounts; stored attachment objects can also outlive message metadata. Clearing app data or uninstalling may permanently delete local-only history. Deletion/expiry features cannot recall screenshots or copies saved by recipients.

5. Sharing and service providers

  • Supabase: hosts authentication, database/realtime services, Edge Functions and file storage used by COM1.
  • Firebase Cloud Messaging / Apple push services: deliver notifications and process push-token/device routing as applicable.
  • AI providers chosen by the user: Google Gemini, OpenAI, Anthropic, xAI, DeepSeek, OpenRouter, Mistral, Ollama services (including user-provided servers). The content selected as context, tagged images or speech transcription inputs may be sent when you invoke the feature.
  • Other destinations you configure: HTTP APIs, SSH hosts and bot/callback services receive the requests and data you explicitly send to them.
  • Hosting and infrastructure: app and website hosting providers may process standard technical logs needed to operate and secure the service.

COM1's application design does not require publicly listing a personal email or phone number. We do not promise that configured third-party endpoints share COM1's privacy practices; review their policies separately. We do not make a blanket claim that no data is ever shared, because optional integrations can share data at your direction.

6. Choices and control

You can edit certain profile settings, disable notifications via app/device controls, avoid optional integrations, choose whether to enable Secure Link, revoke bot tokens and manage local keys. AI settings and HTTP secrets use device secure storage where implemented. Device permissions (camera, microphone, notifications) can be adjusted through your OS.

7. Retention and deletion

Retention depends on message delivery/acknowledgment, account tier, configured backups, attachment lifetime, security/operational logging and any legal obligations. We do not state a single universal automatic deletion period because the supplied implementation does not guarantee one across all data categories.

You can initiate permanent account deletion in COM1 → Settings → Delete Account, or request it without installing the app at com1.najad.dev/delete-account/ by email. After appropriate verification, the request covers account records and associated server-held data except information we are legally required to retain. The application deletion flow intends to remove direct conversations involving the account and the user's own group messages while leaving groups for remaining members. Copies already delivered to other devices cannot necessarily be recalled. Support will explain any verification steps or legally necessary retention.

8. Site analytics, security and cookies

The COM1 informational website includes no advertising tags, third-party analytics scripts or tracking cookies. Ordinary server access/security logs may still be recorded by your host. Email links launch your own email client; the site does not submit passwords or deletion credentials to a web form. This policy should be updated if hosting or site integrations change.

9. Children and location-specific rights

COM1 is a general-purpose communication service. Parents and guardians should assess suitability for minors, especially because messaging and external integrations may expose user-generated content. Depending on local law, you may have access, correction or deletion rights. Email the privacy contact with your request; identification may be needed to prevent another person controlling your account.

10. Updates

This policy may change as the app or backend changes. Material revisions should be shown with an updated effective date. If you need clarification, contact mail@najad.dev.