TRUST BOUNDARY MAP

NO “MILITARY-GRADE” HAND WAVING

privacy, plainly.

Signal transport is encrypted. The trusted bot host still processes plaintext because software cannot respond to a command it cannot read.

where a command goes

your Signal appencrypted →bot Signal accountlocal API →trusted bot processscoped write →state service

stored

  • reminder text and schedule
  • scope identifiers and display names
  • linked calendar IDs
  • admission and support timestamps
  • Signal identity state on the host

not part of the deal

  • analytics or visitor tracking
  • advertising cookies
  • selling behavioral profiles
  • reading ordinary unprefixed DMs
  • donation-based service tiers

command minimization

Group commands require a real mention or leading 🐴/🐌 prefix. DMs require an explicit prefix. The bot ignores its own messages. Membership is checked live before group information is aggregated into a DM.

identity trust

The hosted bot trusts changed Signal identities only for current group members, plus an explicit standalone DM applicant while delivering their admission result. Unrelated identities remain untrusted.

choose your boundary

The shared service means trusting its operator and host. Self-hosting moves that trust to a machine and operator chosen by your group. Neither changes the basic truth that the bot endpoint processes plaintext.

read the private-host guide →

website privacy

This static site sets no cookies and loads no analytics, ads, web fonts, or social pixels. The capacity widget receives aggregate counts and host status—never Signal identifiers, names, reminders, or messages.

Questions or deletion requests: bot@snorse.com.