top of page

Kalmni Privacy Policy

Last updated: October 4, 2026

This Privacy Policy explains how Kalmni ("Kalmni", "the app", "we") handles information when you use the Kalmni mobile application for Android. Kalmni is developed by inspectBits ("we", "us").

1. Summary

  • Kalmni does not require a phone number, an email address or an account.

  • We do not operate a central server that stores your messages, contacts or call history.

  • Your data is stored on your device, in a local database encrypted with SQLCipher.

  • Kalmni contains no advertising and no analytics or tracking SDKs.

  • We do not sell or share your personal data.

2. How Kalmni works

Kalmni is a peer-to-peer (P2P) messenger. Your secure identity is generated on your device when you install the app. Your messages and calls are sent directly to your contacts' devices, and contacts discover each other through the OpenDHT distributed network rather than through a central server. Messages are protected with end-to-end encryption using the open-source Signal Protocol (libsignal), and calls are encrypted and authenticated through your contact's identity.

3. Information stored on your device

The following data is created and stored locally on your device only:

  • Cryptographic identity: keys generated on your device to encrypt and authenticate your communications.

  • Profile: the name, short bio and avatar you choose to set. This information is shared with your contacts so they can see your profile.

  • Contacts: the contacts you add by scanning their QR code.

  • Messages and attachments: your conversations, including delivery and read status.

  • Call history: who called and when, including missed calls.

  • Voice messages: audio messages can be recorded before sending.

  • Audio files: a voice message received can be locally saved as audio file.

This data is stored in a local database encrypted with SQLCipher. We do not have access to it and do not receive a copy of it.

4. Information we do not collect

Kalmni does not ask for or collect your phone number, your email address, your real name, your phone contacts, your location, or any advertising identifier.

5. Information visible through the peer-to-peer network

Because Kalmni is peer-to-peer, some technical information is inevitably visible to other participants:

  • Your contacts can see your IP address during calls, as in any peer-to-peer application.

  • Nodes of the OpenDHT network relay encrypted data used to find contacts and to deliver messages when a contact is offline. This data is end-to-end encrypted and cannot be read by these nodes, but, as with any network, their operators may technically observe IP addresses and connection metadata.
     

Kalmni is a privacy-focused messenger, not an anonymity tool. If you need to hide your IP address from your contacts, consider using a VPN.

6. Permissions

Kalmni may request the following Android permissions, used only for the features described:

  • Microphone and Camera: to make voice and video calls, and to scan QR codes (camera).

  • Nearby devices (Bluetooth connect): optional, to use a Bluetooth headset during a call. Declining it does not prevent calls.

  • Notifications: to alert you of new messages and calls.

  • Full-screen notifications: to display the incoming call screen when your phone is locked.

  • Foreground service: to keep a persistent connection to the peer-to-peer network so you can receive messages and calls while the app is closed, and to keep calls active in the background. A notification is shown while these services run.

  • Network and Wi-Fi state, multicast, audio settings, wake lock: to connect to the peer-to-peer network, route call audio, and turn off the screen when held to your ear during an audio call.

  • Storage (Android 8 and earlier only): to save photos and videos you choose to download to your gallery.

Audio, video and camera data are transmitted only to the contact you are talking to, and are not recorded or stored by Kalmni on any server.

7. Third-party services and libraries

Kalmni uses open-source components, including libsignal (Signal Protocol), OpenDHT and SQLCipher. Kalmni is an independent project and is not affiliated with or endorsed by Signal. Kalmni contains no third-party advertising, analytics or tracking SDKs.
Kalmni does not use Firebase Cloud Messaging or any third-party push notification service. Notifications are generated locally on your device.

8. Data sharing and sale

We do not sell, rent, or share your personal data with third parties, and we do not use it for advertising or profiling.

9. Data retention and deletion

​Your data stays on your device until you delete it. You can delete individual messages, or reset an entire conversation with a contact, from within the app. Uninstalling Kalmni removes all locally stored data, including your identity, contacts, messages and call history. Because we hold no copy of your data, we cannot recover it if you lose your device or uninstall the app. Messages already delivered to a contact's device are stored on that device and are under that contact's control.

10. Security

We rely on end-to-end encryption (Signal Protocol), authenticated calls, and an encrypted local database (SQLCipher) to protect your data. No system is perfectly secure, and we cannot guarantee absolute security. Kalmni is under active development.

11. Children's privacy

Kalmni is not directed to children under 13 (or the minimum age required in your country). We do not knowingly collect personal information from children.

12. International users

Because Kalmni works peer-to-peer, your encrypted data may transit through network nodes located in various countries. We do not store it on our own servers.

13. Changes to this policy

We may update this Privacy Policy from time to time. The latest version will always be available at [policy URL], with the "Last updated" date revised accordingly. Significant changes may also be announced in the app.

14. Contact Us

If you have any questions regarding this privacy policy, you can contact us at the following address: “inspectbits@gmail.com”

bottom of page