Privacy Policy - Okugabana
Who provides Okugabana
Saifullah Ahad provides Okugabana to help households declare power-use timetables, review changes and record signed agreements. Contact [email protected].
What the app does
Members enter their own demand, acceptable complete alternatives and protected needs. A steward enters a declared supply envelope. The app compares revisions and collects the required signatures. It does not measure electricity, control equipment, take payments or establish electrical safety. There is no public feed, advertising, analytics SDK or account-password service.
Data on your device
The app stores your group name, member nicknames and public identifiers, declared profiles, supply values, signed history, consents, objections, burden values, encrypted exchange material, local reports and form drafts. Group records and private identity keys are encrypted using a device-specific Android Keystore wrapping key. Language, appearance and app-lock settings are stored locally. A PIN is stored as a salted hash, not readable PIN text. Biometric checks use Android; the app does not receive fingerprint or face data.
Data visible to your group
Enrolled members can read the group's normalized declarations, alternatives, nicknames, signatures and history. Encryption does not hide those values from authorized members. The app uses randomly generated cryptographic identities, not your phone number or an external wallet. Group signatures use a bundled cryptographic implementation; they are not claimed to be hardware-backed signatures.
Internet and nearby exchange
Internet exchange is optional and happens while the app is open. The Cloudflare relay stores encrypted envelopes, random room IDs, enrolled public-key identifiers, ciphertext sizes and timing metadata. It cannot read the encrypted household content. Cloudflare processes network IP addresses to deliver and protect the service. We do not enable application request-body logging or content analytics. Provider security and operational records are governed by the provider's retention policies.
Nearby exchange uses a foreground TLS connection pinned through an invitation. File exchange uses Android's document picker. These transfers disclose the selected encrypted material to the recipient or storage provider you choose. The app needs internet/network-state permissions for relay, local TLS and optional timestamp checks. No location, contacts, microphone or broad storage permission is requested.
Camera and documents
The optional camera permission is used only to capture a full-resolution invitation QR image with your chosen camera app. The app decodes it locally and deletes its temporary private image. It does not measure equipment or upload camera images. CSV import reads only the file you select and previews the declared values before signing. Export writes only to a destination you choose.
Optional public timestamp
Only after you select the timestamp action, a relayer submits a salted 32-byte commitment on Base Sepolia, a public test network. The commitment and transaction/block metadata are public and cannot be deleted. Raw plans, member names and private keys are not submitted. The public relayer address belongs to the app, not to a household. Users do not provide wallets or gas payments. A timestamp proves only that a commitment existed; it does not prove correct inputs, consent beyond the verified certificate, electrical safety or permanent testnet availability.
Retention and deletion
Local records remain until you use the app's local deletion control, clear its storage or uninstall it. Relay envelopes expire after 180 days without activity in the room. A steward can explicitly delete the relay room and that device's local group copy; the app waits for server confirmation before local deletion. Other members' devices and exports are independent copies. Deletion cannot remove their copies, provider backups outside their retention process, or public timestamp records. Local deletion alone does not contact or delete the relay. To request help, email the public contact above without sending private keys or recovery secrets.
Recovery and device transfer
An encrypted recovery pack contains group history and group encryption keys, but excludes the member's private signing and identity keys. Keep the recovery secret separate and private. Restoration uses a fresh device identity and is read-only until you rejoin through the group's membership approval process. Android automatic cloud backup and device-transfer backup of the app's stored data are explicitly excluded. The app cannot recover a lost secret through an account.
Reporting and child safety
You can report a record or member inside the app and block that identity on your device. A local report is encrypted locally; it is not automatically uploaded. The separate Review email action opens your email app for you to review and send. We receive only what you choose to send. Do not include exploitative images, private keys or entire private group histories. See Okugabana's Child Safety Standards.
Providers, international processing and your choices
Cloudflare and public Base Sepolia RPC services may process requests in other countries. Their policies apply to their infrastructure: Cloudflare privacy policy and Coinbase privacy policy. Your selected camera, email and document-storage apps have their own policies. Local/file workflows remain available when the relay or testnet is unavailable; pending changes stay local. You may revoke camera permission, turn off internet exchange, leave a group, export your data or delete your local copy.
Children and policy changes
Okugabana is intended for adults organizing a shared supply, not children. Do not enter children's personal information. We will update this page and its effective date when the app's data handling changes. Questions or data requests: [email protected].