Privacy Policy for Handbill

Effective 8 September 2026.

The short version. Handbill has no servers and no accounts. It collects nothing about you, because there is nowhere for it to send anything. Everything it does, it does with your own email account, on your own phone. The only time anything reaches us is when you deliberately tap a button to send it.

Where your data lives

On your phone. A cache of the mail Handbill has read, so the feed opens without waiting for the network; your settings; and your encryption key and your mail password, both in the iOS keychain.

In your own email account. Handbill creates two folders there, handbill-content and handbill-meta. The first holds every post, reply and like, as email. The second holds your friend list, profile, filters and circles, each encrypted so that only your own key can read it, plus a copy of that key locked with a passphrase only you know. Your mail provider stores these folders under the same terms as the rest of your mail.

Nowhere else. There is no Handbill server. We cannot see your posts, your friends, your photos or your password, and we could not hand them to anyone if asked.

What Handbill sends, and to whom

Handbill sends email from your account, to people you chose, and nothing else.

  • Posts, replies and likes go to the friends you pick, from your own address. When the friend also runs Handbill and you hold each other's keys, the mail is signed and encrypted end to end. Everyone else gets ordinary, readable email. The app shows you which, before you tap Post.

  • A welcome goes to each new friend before any post does, asking whether they want your posts at all.

  • Update letters go to friends who do not have the app. They contain your posts and the comments others have made on them. Commenters without the app are shown as "Anonymous" unless they have chosen to share their name.

  • To friends who also run Handbill, Handbill shares three more things so the network works without a server: your public key, so they can encrypt to you; your profile photo, if you set one; and the part of your friend list that runs Handbill, so that "People you may know" can be suggested. Only friends who run the app are ever in that list; a friend who reads you by ordinary email is never passed on to anyone. For each friend it carries their email address, the name you have for them, their public key and their photo. Mark a friend as private and they are left out of every list you share. Switch off "Let friends share my Handbill account so other users can find me" and your own friends leave you out of theirs. Your friend list is never sent to anyone who does not run Handbill.

What Handbill fetches from the internet

  • Your mail provider, over IMAP and SMTP with the app password you gave it. This is the only service Handbill talks to on its own.

  • YouTube, once, from your phone, when you paste a YouTube link into a post: the title, channel, length and a few preview frames, which are attached to the post. Your readers fetch nothing. Nobody learns that a post was opened.

  • Link shorteners, once, from your phone, when you paste a shortened link and "Strip tracking info from forwarded links" is on: Handbill follows the short link to find where it goes, so the tracking token in it can be dropped before your friends see it. You can switch this off in Settings.

Nothing is fetched when you read. Photos and previews arrive inside the mail itself.

What reaches us

Nothing, unless you send it. There is no analytics, no crash reporting, no usage statistics and no advertising.

Two buttons in Settings send us email, from your own account, after a confirmation:

  • Send log to developer sends the diagnostic log shown on that screen: a list of what the app did and when, with no message text, no subjects and no email addresses, since friends appear only as short hashes. It also carries the app version, the iOS version and anything you typed into the "What were you doing?" box.

  • Send feedback to developer sends your words, the app version and the iOS version.

Both go to debug-report@handbill.org. We keep what you send for as long as it is useful for fixing the problem and share it with nobody.

Your mail password

Handbill asks for an app-specific password, not your main one. It is stored in the iOS keychain and sent only to your mail provider, never to us. An app password gives full access to the mailbox, which is what IMAP and SMTP are; we suggest a spare account while the app is young. The keychain keeps the password even after the app is deleted, so if you stop using Handbill, revoke the app password at your provider.

Permissions

  • Camera and photo library, only when you choose to attach a photo or set a profile picture. Photos are scaled on your phone before they go anywhere.

  • The share sheet, so photos, links and text can be sent to Handbill from other apps. They go straight into the composer and nowhere else.

  • Background refresh, so the app can check your mailbox occasionally and put a count on its icon.

Children

Handbill is not directed at children under 13 and does not knowingly collect anything from anyone, of any age.

Deleting your data

Delete the app and the cache on your phone goes with it. Delete the two handbill- folders in your email account and the rest goes too. Revoke the app password at your provider. We hold nothing to delete, except any log or feedback you mailed us; write to the address below and we will delete that as well.

Other people's policies

Your mail is stored by your provider under their policy, and mail you send to friends is stored by theirs. Your email provider will have access to all message “metadata” - who you are emailing and when. They will be able to read all your messages sent to plain email users. They will NOT be able to read the content to messages send between handbill app users (since it is all encrypted). What they will do with that data depends on the email provider.

If you install Handbill through Apple's App Store or TestFlight, Apple's own privacy policy covers what Apple collects; Handbill receives none of it.

Questions and changes

Questions about privacy go to security@handbill.org, the same address that takes security reports; it is read by the one person who makes Handbill. If this policy changes, the date at the top changes with it and the new version is published here.