PRIVACY

Privacy is built into how Hashi communicates.

Hashi combines encrypted communication with local processing where practical, explicit feature controls and limited server-side retention for delivery and synchronization.

Last updated: 9 October 2026

MESSAGES & MEDIA

Encrypted communication

Hashi uses end-to-end encryption for one-to-one message content and encrypted media transfer. The backend routes and synchronizes encrypted application data together with delivery/read state, message actions and other metadata needed to operate the service.

Images, ordinary files, audio and video are transferred through authenticated encrypted media workflows. Fresh media transfers use authenticated encrypted chunks so content remains protected while it is being transferred.

LOCAL DATA

Sensitive app data is protected on the device.

Hashi uses Android Keystore-backed protection for multiple local stores, including chat-related data and several privacy and productivity features. Private Chat Topics remain local to the device. Contact PIN records are derived from the PIN rather than storing the raw PIN value.

Local clear-chat workflows also include safeguards designed to stop cleared history from immediately reappearing during later synchronization.

PERMISSIONS

Permissions are tied to features that need them.

Depending on the features you use, Hashi may request access to camera, microphone, notifications, Bluetooth connectivity, activity recognition, location or related Android capabilities. Camera and microphone access support calls, conferences and other features that explicitly require those sensors.

Optional features remain under user control. For example, Live Expression is off by default and does not perform camera analysis while disabled.

LOCATION & ACTIVITY

Location sharing is optional and contact-specific.

Hashi can provide per-contact location sharing and distance information when you choose to enable it. Backend location state and permission state are separated so the presence of a stored location does not by itself authorize another contact to receive it.

Optional activity presence can show states such as Driving or Running. This feature is off by default and depends on Android activity-recognition permission.

ON-DEVICE FEATURES

Several intelligent features run locally.

Hashi uses on-device language identification and Google ML Kit translation models for message translation. Translation models are downloaded as needed and can be managed from Hashi settings.

The current conversation-tone analysis implementation operates locally in the Android app. Adaptive Chat Readability also uses device sensors locally while the relevant feature is enabled and active.

SERVER RETENTION

The backend is not designed as a permanent archive of delivered chat history.

Current production maintenance removes delivered message rows after approximately 24 hours. Undelivered non-media text may remain for up to seven days so delivery can be retried. Deleted-message tombstones are retained briefly so deletion can propagate correctly.

Encrypted physical media follows a separate transfer lifecycle. Completed or reusable media may be retained for up to 30 days before scheduled cleanup. These periods describe the current production retention jobs and may change as the service evolves.

SUPPORTING SERVICES

Services used to operate Hashi

Hashi uses Firebase Cloud Messaging for push and background wake behavior. Google ML Kit is used for on-device language identification and translation. WebRTC provides real-time audio/video communication, with relay infrastructure available when direct peer connectivity is not possible.

YOUR CHOICES

You control optional communication and privacy features.

You can turn optional location sharing, activity presence, translation-related features, Live Expression, adaptive readability and other configurable features on or off. Hashi also provides local chat-history management, including calendar navigation, clearing selected dates or ranges, and Clear All.

Per-contact PIN locks, incoming-message filtering, parental controls and availability or Automatic Reply policies can be configured independently in the app.

SECURITY

Technical safeguards

Hashi uses Android Keystore-backed key material, authenticated short-lived API sessions, AES-256-GCM protection, contact identity-change checks, encrypted media-transfer keys and layered backend abuse and capacity controls. No security system can guarantee absolute protection, but the application is designed around multiple independent safeguards.

For a higher-level technical overview, see the Security page.

CONTACT

Privacy and support questions

Email hashi@icommsys.com.