The questions a careful evaluator asks about any app, answered plainly and before you ask. Every answer here is a summary; the binding documents are the Privacy Policy and the Terms of Service, and the Law Enforcement Guidelines describe how we handle legal process.
boopr is built by Boopr LLC, a Delaware company based in Maryland, run by a small self-funded team. There are no advertisers and no data buyers; the only money in the product is the subscription described below.
One way: an optional subscription called boopr+ ($9.99 a month or $79.99 a year) that unlocks resource-intensive features like video posts and albums. The core experience is free and complete without it, and free and paid accounts look identical in the app.
We show no advertising of any kind, ever: a written commitment in our Terms that cannot change without 30 days of notice and your affirmative acceptance. And under our Privacy Policy we do not sell personal information to anyone, for any purpose; material changes there also require notice and your affirmative acceptance.
Because trust does not scale through signup forms. Every account was vouched for by someone who already had one, and the Terms commit to no stranger discovery: there are no public profiles, no search, and no way to browse people you do not know. Your friend list is never shown to other users.
Creating an account requires no email address, no phone number, and no real name. Your account is a random identifier plus encryption keys. Posts, photos, comments, and profile details are encrypted on your device before they reach us, and we cannot read them.
Section 3 of the Privacy Policy is an exhaustive inventory of everything we hold. It is short, and it is meant to be read.
Metadata. We can see that an account exists, when it was created and last active, who is connected to whom, when something was posted and which accounts could receive it, and similar timing and delivery records. We are plain about this because it matters: under valid legal process, metadata can be compelled even though content cannot. Sections 3 and 7 of the Privacy Policy list it all.
Delete your account and your data is permanently removed within 30 days. Encrypted content can persist in server backups for up to 90 days after deletion, and it stays unreadable to us for that entire window. A small set of de-identified records survives longer, such as the legal-acceptance audit trail (kept at least ten years, with identifying details redacted on deletion) and anything we are legally required to preserve; the Privacy Policy retention section has the complete list. Raw IP addresses are never written to disk, to a database, or to persistent logs; what we store is a salted hash that rotates monthly and cannot be correlated across months.
The waitlist is the only place boopr ever collects an email address, and it belongs to people who are not users yet. It is reviewed by hand, there is no automated mailing system behind it, and the address is never used for marketing, never shared, never sold, and deleted on request.
What we can produce is limited by design, not by policy. With valid US legal process we can produce the metadata described above: account records, connection metadata, timing, and the other items in Section 21 of the Privacy Policy. We cannot produce your posts, photos, comments, or profile details in readable form for anyone, under any process, because they are encrypted with keys we do not hold. The full picture, including how we handle each kind of request, is in our Law Enforcement Guidelines.
No. There is no backdoor, master key, or escrow mechanism, and we will not build one. We do not implement client-side scanning, server-side scanning, or any other content-inspection technology. We comply with mandatory reporting laws when we gain actual knowledge of illegal content, but we cannot and do not search for it.
No. As of July 28, 2026, we have received no legal process of any kind: no subpoenas, no court orders, no search warrants, and no emergency requests. This answer is updated as that changes, and the annual transparency report will carry the running totals.
We notify affected users unless we are legally prohibited from doing so, with the narrow exceptions the Privacy Policy spells out (such as reports we are required to make to NCMEC), and we commit to challenging overbroad demands. Starting August 15, 2027, one year after public launch, we will publish an annual transparency report covering the requests we receive.
No. What we publish instead: a full security whitepaper that documents how the system works down to the construction level, with a candid limitations section for every component, and a vulnerability disclosure policy with safe harbor for good-faith research. The whitepaper states it plainly: if the software's behavior contradicts the document, that discrepancy is itself a reportable issue.
Not yet. A formal third-party review is planned within twelve months of public launch, and its findings will be published. Until then, the whitepaper exists precisely so that an audit has something specific to confirm or contradict.
Email security@boopr.com. We acknowledge reports within 48 hours and triage within 7 days, and we will never threaten legal action against good-faith research. Details, including scope and rewards, are on the security page, and machine-readable contact information lives at /.well-known/security.txt.
Your 24-word recovery phrase already restores your account on a new device. A full encrypted export feature is on the post-launch roadmap, designed so the bundle can be decrypted independently of boopr using documented standard building blocks rather than a proprietary format.
Everything above is a summary. The full documents: Privacy Policy · Terms of Service · Law Enforcement Guidelines · Security · Whitepaper