Privacy
Privacy Policy
NostrBorg is a restore-drill and backup-coordination product. This policy describes what the hosted app at https://nostrborg.flowstate.market collects.
What we store
- ConsentKeys identity is pseudonymous. We treat `sub` as the account id and may display the provider’s generated name or email fields.
- The public restore drill uses short-lived synthetic ciphertext in a single request. Blob bytes are not written to a database.
- If you sign in, recent restore-drill pass/fail metadata may be saved for about 30 days so the operator dashboard can show history. That record is not ciphertext, recovery keys, or a Borg repository.
- Privacy-safe analytics events such as page views, CTA clicks, and drill completion may be sent to a first-party PostHog host.
What we do not store
- Borg passphrases, repository keys, Nostr secret keys, or plaintext backup contents.
- Real names or personal email addresses from ConsentKeys at the application layer.
Operator control
You can stop using the hosted drill at any time. If you signed in, signing out ends the session cookie. Contact the operator through the product site if you need a dashboard record removed after authentication is enabled.