boopr
About Security Roadmap Press Aug 15, 2026
Legal

Terms of Service

Effective April 25, 2026

The rules and guidelines for using boopr.


These Terms of Service (“Terms”) govern your use of boopr, an end-to-end encrypted social platform operated by Boopr LLC (“boopr,” “we,” “us,” or “our”). By creating an account or using boopr, you agree to these Terms and our Privacy Policy.

Important — please read carefully:

boopr uses end-to-end encryption (E2E). This fundamentally shapes how the service works:

We cannot read your posts, profile, or any content you share.

We cannot recover your account if you lose your 24-word recovery phrase.

We cannot moderate or review content because we cannot see it.

You are solely responsible for safeguarding your recovery phrase and device security.

These Terms include a binding arbitration clause and class action waiver in Section 20. You may opt out of arbitration within 30 days of creating your account (see Section 20 for details).

1. Acceptance, Eligibility, and Geographic Scope

Agreement to Terms

By creating an account, accessing, or using boopr, you agree to be bound by these Terms and our Privacy Policy. If you do not agree, do not use the service.

Electronic Agreement

By creating an account, you consent to these Terms in electronic form and agree that electronic acceptance has the same legal effect as a handwritten signature under the Electronic Signatures in Global and National Commerce Act (E-SIGN Act) and applicable state laws. You consent to receiving all notices, disclosures, and communications electronically through the app. If you contact us via email, we may respond to the email address you use to contact us. You may request a paper copy of these Terms by contacting [email protected]. To access and retain these Terms, you need a compatible smartphone with internet access and the boopr app installed.

Geographic Restriction — United States Only

boopr is currently available only to users located in the United States and its territories. By creating an account, you represent and warrant that you are physically located in the United States. We do not offer the service to users in other countries and make no representations that the service is appropriate or available for use in other jurisdictions. If you access boopr from outside the United States, you do so at your own risk and are solely responsible for compliance with local laws.

Age Requirement

You must be at least 13 years old to use boopr. By creating an account, you represent and warrant that you are at least 13. If you are between 13 and 17, you further represent that your parent or legal guardian has reviewed and consents to these Terms on your behalf.

boopr is invite-only and is not directed at children under 13. We do not knowingly collect personal information from children under 13 in compliance with the Children’s Online Privacy Protection Act (COPPA). If we discover or have reason to believe that a user is under 13, we will promptly terminate the account and delete all associated data. Parents or guardians who believe a child under 13 has created an account may contact us at [email protected]; we will investigate and, upon confirmation, delete the account and associated data within 30 days. The invite-only registration model serves as a supplementary barrier to underage access.

Invite-Only Access

boopr is invite-only. You may create an account only if you have a valid invite code (format: BOOP-XXXX-XXXX) from an existing user. Invite codes are cryptographically signed into a chain of accountability.

2. Description of Service

boopr is a private, end-to-end encrypted social platform. You connect with people you know in person, exchange friend codes, and communicate privately. All content is encrypted on your device before it reaches our servers.

Core Features (Free)

  • Friend connections via friend codes (FRND-XXXX-XXXX format) and QR codes
  • Photo sharing in posts (encrypted, EXIF-stripped)
  • Encrypted posts with audience controls (all friends, specific friend groups, or individual friends)
  • Reactions on posts (encrypted)
  • Comments on posts (private replies model — only the post author and commenter can see each comment)
  • Boops — lightweight, encrypted interactions between friends
  • Friend groups — client-side organization of friends for audience targeting (stored encrypted on your device; our server has zero knowledge of your groups)
  • Push notifications that contain no content (wake-up pings only; your device fetches and decrypts locally)
  • Device recovery via your 24-word recovery phrase (always free)
  • Blocking and muting (client-side; server has no knowledge of your block/mute lists)
  • Birthday reminders — store your birthday (month and day only, no year) in your encrypted profile with client-side reminders for your friends’ birthdays
  • Screenshot protection — the feed, individual posts, profiles, comments, and boops are blanked during screen capture (FLAG_SECURE on Android, screen capture detection on iOS). If a screenshot is detected on one of these screens, an E2E encrypted notification is sent to the other party. By using boopr, you consent to screenshot detection and notification. You acknowledge that screenshots you take may be detected and reported to the other party. Screenshot detection is a social deterrent and cannot guarantee prevention on all devices or modified clients.
  • Hardware-backed key storage — your private keys are protected by your device’s Secure Enclave (iOS) or StrongBox/TEE (Android), with additional key wrapping and optional biometric authentication

What boopr Does Not Provide

  • Access to emergency services (do not rely on boopr for emergency communications)
  • Content moderation or content review (we cannot see your encrypted content)
  • Account recovery without your recovery phrase
  • Multi-device support (currently one device per account)
  • Algorithmic feeds, content recommendations, or friend suggestions
  • Public profiles, hashtags, or discover/explore features
  • Server-side storage of your unencrypted private keys (your recovery phrase allows you to regenerate your keys on a new device, but we never hold your private key material)

Design Commitments

boopr is designed to occupy a different position in the social-media landscape from engagement-optimized platforms. The following design choices are commitments to you, not mere descriptions of the current product:

  • boopr does not employ algorithmic ranking, personalization, or recommendation systems for the feed. Posts appear in reverse chronological order from accounts you have explicitly added.
  • boopr does not run engagement-optimization heuristics, infinite scroll, autoplay of unsolicited content, or notification-timing models designed to maximize session duration or return frequency.
  • boopr does not display follower counts, like counts visible to other users, public metrics, or social-proof indicators intended to drive comparative engagement.
  • boopr does not surface or recommend strangers, run a discovery or explore feature, or let users find each other except through the friend-code exchange described in Section 9.
  • boopr does not show advertising, run third-party analytics or tracking, or share user data with advertisers or data brokers.
  • boopr does not train machine-learning models on user content (and structurally cannot, because user content is end-to-end encrypted).

We may modify these design commitments only by giving at least thirty (30) days’ advance notice in the app and requiring affirmative acceptance of the modified Terms before continued use, as described in Section 22. You may delete your account at any time before such a change takes effect with no liability.

3. Account Registration and Security

Registration

When you register with a valid invite code, your device generates cryptographic key pairs (Ed25519 for signing, X25519 for encryption) and a 24-word recovery phrase. Your recovery phrase is stored securely in your device’s Keychain and can be viewed at any time in Settings > Security > Recovery Phrase. This phrase is the only way to recover your account and is never stored on our servers.

Your Responsibilities

  • Recovery phrase: Write down your 24-word recovery phrase and store it in a secure, offline location. If you lose it, you will permanently lose access to your account and all associated data. We cannot recover it for you under any circumstances.
  • Device security: Your private keys are protected by hardware-backed security — Secure Enclave (iOS) or StrongBox/TEE (Android). Keys are additionally wrapped with hardware-derived encryption and require the device to be unlocked (After First Unlock enforcement). You may also enable biometric authentication in Settings > Security > App Lock. Anyone with physical access to your unlocked device and biometric credentials may be able to access your boopr account.
  • Single device: boopr currently supports one device per account. Restoring to a new device deactivates your old device’s session.
  • Accurate information: You agree to provide accurate information during registration and to maintain the security of your account.

Biometric Authentication

boopr does not collect, store, or process biometric data (such as fingerprints or facial geometry). Biometric authentication is handled entirely by your device’s operating system (iOS Face ID/Touch ID or Android BiometricPrompt). boopr receives only a success-or-failure result from the operating system. Your biometric data never leaves your device and is never transmitted to our servers.

What Recovery Restores

When you restore from your recovery phrase, the following are recovered for free:

  • Your identity keys (deterministically derived from the recovery phrase)
  • Your encrypted profile (name, bio, avatar, birthday)
  • Your posts (per-recipient key wrapping allows re-derivation of post keys from your identity keys)
  • Client data (friend groups, block/mute lists)

What We Cannot Do

Because of our E2E encryption architecture, we cannot:

  • Reset or recover your recovery phrase
  • Access, read, or decrypt your posts or profile
  • Provide copies of your decrypted data (we only store encrypted blobs)
  • Transfer your account between devices without your recovery phrase

4. Encryption and Privacy Architecture

Understanding how boopr’s encryption works is important to understanding these Terms. Our encryption model creates both strong protections and inherent limitations.

How Your Content Is Protected

  • Posts use per-recipient key wrapping: a random symmetric key is generated per post, content is encrypted with that key (XChaCha20-Poly1305), and the post key is then encrypted individually to each intended recipient’s public key (X25519).
  • Profiles are encrypted with a key derived deterministically from your recovery phrase. When you remove a friend, the profile key rotates so removed friends lose access.
  • Photos are re-encoded on your device, which strips EXIF metadata (GPS coordinates, camera model, timestamps). This processing occurs client-side; our servers receive only the encrypted result and cannot independently verify that metadata was stripped. Photos are encrypted with XChaCha20-Poly1305, and originals are deleted from your device immediately after processing.
  • Comments use per-comment key encryption to exactly two recipients (post author and commenter), preventing social graph leakage.
  • Reactions on posts are encrypted with the post’s session key.

What This Means in Practice

Our servers store only encrypted data. We cannot read, search, index, filter, or analyze your content. This provides strong privacy but means we cannot offer server-side search, algorithmic feeds, content moderation, or friend suggestions.

Privacy Limitations

Your friend list is not displayed to other users. However, as with any social platform, the presence of shared content may allow sophisticated analysis to infer some connection information. We minimize this exposure through rate limiting, pseudonymous identifiers, and the invite-only model. All user identifiers on our servers are pseudonymous UUIDs with no linkage to personally identifiable information.

Security Commitment

While we do not guarantee absolute security (no system is perfect), we commit to implementing and maintaining reasonable security measures commensurate with the sensitivity of encrypted communications, including regular review of our cryptographic implementations and prompt response to discovered vulnerabilities.

5. User Conduct

You agree not to use boopr to:

  • Create, store, or transmit any illegal content, including but not limited to child sexual abuse material (CSAM)
  • Share, distribute, or store non-consensual intimate imagery (NCII), including AI-generated or digitally altered intimate imagery of any person without their consent
  • Promote, facilitate, or engage in commercial sexual services, prostitution, or sex trafficking, in any manner that would violate 18 U.S.C. § 2421A or analogous state law
  • Sell, offer to sell, distribute, or facilitate the transfer of controlled substances, including without limitation fentanyl, fentanyl analogues, opioids, and counterfeit pills purporting to be prescription medication, in any manner that would violate 21 U.S.C. § 841, § 843(b), or analogous state law
  • Harass, threaten, stalk, or abuse other users
  • Impersonate any person or entity
  • Send spam, unsolicited bulk content, or automated posts
  • Attempt to circumvent, disable, or interfere with security measures or encryption
  • Reverse-engineer, decompile, or disassemble the app or its cryptographic protocols
  • Interfere with or disrupt the service or its infrastructure
  • Violate any applicable local, state, national, or international law or regulation
  • Publicly share, sell, or distribute invite codes (BOOP-XXXX-XXXX)
  • Create multiple accounts per person
  • Use the service if you are under the age of 13
  • Use modified clients to bypass safety controls (e.g., preserving EXIF data that the standard client strips)
  • Upload, share, or store sexually explicit material of any kind, including pornographic imagery, sexually explicit video, or sexual solicitation content

boopr is not an adult-content platform. The service is not designed or marketed for the distribution of sexually explicit material, and the upload of such material is a violation of these Terms. We are not a “commercial entity” that publishes or distributes “material harmful to minors” within the meaning of any state age-verification statute.

Content Moderation Transparency:

All content on boopr is end-to-end encrypted. We do not monitor, scan, or review your content. We do not perform client-side scanning, perceptual hashing, or any form of on-device content analysis. You are solely responsible for your conduct and any content you create and share.

When you report a user or content, we receive only metadata: your user ID, the reported user’s ID, the content ID, the reason you selected, and a description you write in your own words. No encrypted content is decrypted or sent to our servers as part of the report process. We make enforcement decisions based on your description, report patterns, and account-level metadata.

See our Community Guidelines for details on reporting, enforcement, and appeals.

6. Child Safety and CSAM Reporting

boopr has zero tolerance for child sexual abuse material (CSAM) and the sexual exploitation of minors. In accordance with 18 U.S.C. § 2258A, if boopr obtains actual knowledge of apparent CSAM on the platform, we are required by federal law to report it to the National Center for Missing & Exploited Children (NCMEC) as soon as reasonably possible. Reports submitted in good faith are subject to the civil and criminal immunity provided by 18 U.S.C. § 2258B.

Accounts associated with CSAM or the sexual exploitation of minors will be immediately and permanently terminated without prior notice. We will cooperate fully with law enforcement investigations related to child exploitation, including preserving and disclosing available account metadata and encrypted data as required by law. Reported material and associated metadata are preserved for at least one year as required by the REPORT Act (Pub. L. 118-59), which amended 18 U.S.C. § 2258A(h).

Due to E2E encryption, we cannot proactively scan content for CSAM, and 18 U.S.C. § 2258A(f) does not require us to monitor, affirmatively search, or weaken our encryption. Our reporting obligations apply when we obtain actual knowledge through user reports, law enforcement referrals, or other means that do not involve decrypting user content.

If you become aware of CSAM or child exploitation on boopr, please report it immediately to [email protected] with the subject line “CSAM Report” and to the NCMEC CyberTipline.

7. Non-Consensual Intimate Imagery

In accordance with the TAKE IT DOWN Act (Pub. L. 119-12, codified at 47 U.S.C. § 223a and related provisions), boopr prohibits the sharing, distribution, or storage of non-consensual intimate visual depictions (NCII), including AI-generated, computer-generated, or digitally altered intimate imagery depicting any identifiable person without their consent.

Designated Point of Contact and Reporting Process

If you are an identifiable individual depicted in non-consensual intimate visual content on boopr, or you are authorized to act on behalf of such an individual, you may submit a removal request to our designated point of contact through any of the following channels:

Web form (preferred): boopr.com/ncii-removal
Email: [email protected] (subject line: “NCII Report”)
Mail: Boopr LLC, Attn: NCII Removal, 2810 N Church St, PMB 748102, Wilmington, DE 19802-4447

A valid removal request should include, to the extent reasonably available:

  • Identification of the specific content (post URL, message ID, screenshot, or other identifier sufficient to locate the content)
  • Identification of the depicted individual and a statement that you are that individual or are authorized to act on their behalf
  • A good-faith statement that the intimate visual depiction was published without the depicted individual’s consent
  • Your physical or electronic signature and contact information for follow-up

Our Response — 48-Hour Removal

Upon receiving a valid removal request, we will remove the specifically identified content and take reasonable steps to identify and remove known identical copies within forty-eight (48) hours. Where the content is end-to-end encrypted and we cannot independently identify duplicate copies, “reasonable steps” consist of deleting the encrypted content blob from our servers and revoking the associated decryption keys, which renders any distributed encrypted copies of that content undecryptable.

Consistent with the good-faith protection in the TAKE IT DOWN Act, boopr is not liable for the good-faith removal of, or disabling access to, material claimed to be a non-consensual intimate visual depiction based on facts or circumstances from which the unlawful publishing of the depiction is apparent.

Accounts that share NCII may be suspended or permanently terminated. NCII involving minors (persons under 18) will be treated with the utmost severity and may also be reported under our CSAM obligations (Section 6) and to NCMEC.

8. Invite System and Accountability

boopr is invite-only to maintain a genuine, accountable community. Every user is part of a cryptographically verifiable invite chain.

Your Invites

Each user receives 25 lifetime invites (100 for boopr+ subscribers). Invite codes use the BOOP-XXXX-XXXX format and are cryptographically signed into your account’s sigchain.

Invite Accountability

We track invite chains for accountability purposes. Each invite has two accountability windows that begin when your invitee creates their account: a full accountability period of 30 days, during which actions against your invitee may be weighed most heavily against your account, and a shared accountability period of 180 days, during which we may continue to consider patterns of enforcement against users in your invite chain.

When a user is warned, restricted, or banned, we record that enforcement action against their invite chain. If multiple users you invited are subject to enforcement actions, your account may be flagged for review. This creates a chain of accountability: you are responsible for exercising good judgment about whom you invite. Do not distribute invite codes to strangers or post them publicly.

Invite Revocation

You may revoke any unused invite at any time. Revoked invites cannot be redeemed, and your invite quota is restored.

9. Friend Connections

Friend Codes

You connect with other users by exchanging friend codes (FRND-XXXX-XXXX format). Friend codes can be shared in person, via QR code, or through any method you choose. Friend codes are case-insensitive.

Connection Security Model

When someone redeems your friend code, they gain immediate access to your profile and posts, but you must approve the connection before they appear in your friend list. This protects against friend code interception (e.g., someone photographing your QR code without permission).

Removing Friends

You may remove friends at any time. When you do, your profile key rotates so the removed friend can no longer decrypt your profile or future posts. They are not notified of the removal.

10. Blocking and User Safety

Blocking

When you block a user:

  • The blocked user does not appear in your feed, friend list, or notifications
  • The blocked user is not notified
  • Blocks are immediate and persist until you choose to unblock

Blocking is currently enforced on your device only. The friend connection is not severed, your profile encryption key is not rotated, and our servers do not reject friend requests, boops, or other API calls from blocked users. To revoke a friend’s decryption access to your profile and future posts, use the Remove Friend action described in Section 9, which rotates your profile key. Your block list is encrypted on your device and synced to our servers as opaque ciphertext so it can be restored with your recovery phrase; we cannot read it. See our Privacy Policy Section 3.14 for details. We may add server-side block enforcement in the future.

Muting

Muting hides a user’s content from your feed without removing the friendship. Like the block list, your mute list is encrypted on your device and synced to our servers as opaque ciphertext for device recovery; we cannot read it. The muted user is not notified.

11. Content and Intellectual Property

Your Content

You retain full ownership of all content you create and share on boopr. By using the service, you grant us a limited, worldwide, non-exclusive, royalty-free, non-transferable license to transmit, store, and deliver your encrypted content solely for the purpose of operating and providing the service. This license terminates when you delete the content or your account. We cannot access the decrypted content of anything you share.

Encryption and Ownership

Your content is encrypted with keys that only you and your intended recipients control. The encrypted data stored on our servers is meaningless without the corresponding decryption keys, which we do not possess.

Image Processing

When you share photos, the boopr app on your device processes images before encryption: metadata (EXIF data including GPS coordinates, camera model, and timestamps) is stripped, images are re-encoded to JPEG, and thumbnails are generated. This processing happens entirely on your device. Our servers receive only the encrypted result and cannot independently verify that metadata was stripped. The original image is deleted from app memory immediately after processing. Only the encrypted, processed image is transmitted to our servers.

Copyright Compliance

You represent and warrant that you have the right to share any content you post, and that your content does not infringe the intellectual property rights of any third party.

Interactive Computer Service Status

boopr is an “interactive computer service” as defined in 47 U.S.C. § 230(f)(2). Users are solely responsible for the content they create, share, and transmit through the service. boopr is not the publisher or speaker of user content under 47 U.S.C. § 230(c)(1), and is not liable on account of any action voluntarily taken in good faith to restrict access to or availability of material that boopr or its users consider objectionable, under 47 U.S.C. § 230(c)(2). Our exercise (or non-exercise) of any moderation discretion does not waive, diminish, or otherwise affect any immunity available to us under Section 230 or any other law.

12. DMCA and Copyright

We respect intellectual property rights and comply with the Digital Millennium Copyright Act (DMCA). Our designated DMCA agent is identified below.

Limitations Due to Encryption

Due to end-to-end encryption, we cannot view, search, scan, or identify potentially infringing content on our platform. We cannot proactively detect or remove copyrighted material because all content is encrypted and inaccessible to us.

DMCA Designated Agent

If you believe your copyright has been infringed by a boopr user, you may submit a DMCA takedown notice to our designated agent:

Email: [email protected]
Mail: Boopr LLC, Attn: DMCA Agent, 2810 N Church St, PMB 748102, Wilmington, DE 19802-4447

Your notice must include all elements required under 17 U.S.C. § 512(c)(3):

  • Your physical or electronic signature
  • Identification of the copyrighted work claimed to have been infringed
  • Identification of the material alleged to be infringing and information reasonably sufficient to permit us to locate it
  • Your contact information (name, address, telephone number, email)
  • A statement that you have a good faith belief that the use is not authorized by the copyright owner, its agent, or the law
  • A statement, made under penalty of perjury, that the information in the notice is accurate and that you are the copyright owner or authorized to act on their behalf

Our Response Capabilities

Because we cannot decrypt or view content, our ability to respond to DMCA notices is limited to account-level actions where the claim can be verified through means other than inspecting the encrypted content (e.g., through the reporting user providing evidence, court orders, or account metadata).

Counter-Notification

If you believe your content was removed in error, you may submit a counter-notification to [email protected] containing:

  • Your physical or electronic signature
  • Identification of the material that was removed
  • A statement under penalty of perjury that the removal was a mistake or misidentification
  • Your name, address, and telephone number
  • Consent to jurisdiction of the federal court in your district (or any judicial district in which boopr is located, if you are outside the United States)

If we do not receive notice of a court action from the original complainant within 10–14 business days of forwarding the counter-notification, we may restore the removed content.

Repeat Infringers

We will terminate accounts of users who are determined to be repeat copyright infringers. Receipt of three (3) substantiated DMCA notices within any rolling twelve-month period against the same account, or any single court order or judgment of infringement, will result in account termination. We may also terminate accounts that show a pattern of evading enforcement (e.g., re-registering after a prior termination).

13. boopr+ Subscription

boopr+ is an optional paid subscription that unlocks resource-intensive features. The core boopr experience is free and complete without a subscription.

Pricing

  • Monthly: $9.99/month
  • Annual: $79.99/year

Prices listed are in US dollars and are exclusive of any applicable taxes. Apple and Google are responsible for collecting and remitting any sales, use, value-added, or similar taxes on in-app purchases as marketplace facilitators under applicable state and federal law; the final amount charged at the time of purchase will be displayed by the App Store or Play Store and may include those taxes.

boopr+ Features

Feature availability may evolve as we continue to develop the platform. Subject to release on your platform and app version, boopr+ subscribers may have access to:

  • 100 lifetime invites instead of 25
  • Video posts
  • Albums (multiple photos per post)
  • Profile video (animated profile)
  • Alternate app icons (when available)
  • Early access to selected new features

Some boopr+ features may be released to limited test groups, employee builds, or specific platforms before general availability. The current list of subscriber benefits is reflected in the in-app subscription screen.

What Is Never Gated

The following are always free, regardless of subscription status:

  • Posts, feed, reactions, comments, and boops
  • Friend codes and connections
  • Friend groups
  • Push notifications
  • Full E2E encryption
  • Device recovery via recovery phrase
  • Client data sync (friend groups, block/mute lists)

Free and paid users are visually identical in the app. There are no cosmetic differences based on subscription status.

Auto-Renewal Disclosure (California Bus. & Prof. Code §§ 17600–17606; New York Gen. Bus. Law § 527-a; Maryland Commercial Law § 14-1226 et seq.)

Your boopr+ subscription is an automatically renewing subscription:

  • Renewal cadence: Monthly subscriptions renew every month on the anniversary of the original purchase date. Annual subscriptions renew every year on the anniversary of the original purchase date.
  • Recurring charge: Your Apple ID or Google account will be charged the then-current subscription price (currently $9.99 monthly or $79.99 annually, plus applicable taxes) at the start of each new billing period.
  • Renewal continues until cancelled: The subscription will keep renewing on this cadence until you cancel through the App Store or Play Store subscription settings. There is no fixed end date.
  • Cancellation deadline to avoid the next charge: You must cancel at least 24 hours before the end of your current billing period to prevent the next renewal charge.

By tapping the “Subscribe” or equivalent confirmation button on the boopr+ upgrade screen, you provide express affirmative consent to the auto-renewal terms set out above, separately from your acceptance of these Terms generally.

Cancellation — Same-Medium, At-Will

You may cancel your subscription at any time, without penalty or explanation, through your device’s subscription settings using the same medium in which you signed up. Cancellation through the platform settings is online, immediate, and does not require contacting boopr or any third party.

  • iOS: Settings > [Your Name] > Subscriptions > boopr+ > Cancel Subscription
  • Android: Google Play Store > Menu > Subscriptions > boopr+ > Cancel Subscription

Cancellation takes effect at the end of your current billing period. You retain access to boopr+ features until the period expires.

Pre-Renewal Reminder (Annual Subscriptions)

For the annual ($79.99/year) plan, Apple App Store or Google Play, as the merchant of record, sends a pre-renewal reminder to the email address associated with your Apple ID or Google account between fifteen (15) and forty-five (45) days before the renewal date, in compliance with Cal. Bus. & Prof. Code § 17602(b) and analogous state laws. The reminder identifies the renewal date and the amount that will be charged. You may cancel at any time before the renewal date.

Material Changes — Re-Consent Required

If we increase the price of your subscription or make any other material change to the auto-renewal terms (such as a change to the renewal cadence or to the features included in the subscription), we will provide you with at least thirty (30) days’ advance notice, and we will not apply the new price or terms to your renewal until you affirmatively consent to the change through the in-app subscription flow or the platform’s subscription consent mechanism. If you do not consent, your subscription will not renew at the new price; you may continue to use boopr+ until the end of your current paid period and then revert to the free tier, or you may cancel earlier without penalty.

Refunds

Subscriptions are billed through the Apple App Store (iOS) or Google Play Store (Android). All billing, payment processing, and refunds are governed by the respective platform’s policies. Refund requests should be directed to Apple or Google in accordance with their respective refund policies. boopr does not directly process payments, store payment information, or issue refunds.

Effect of Cancellation

When your subscription ends, boopr+ features become unavailable, but all your existing content (including content created with boopr+ features) remains accessible. Any unused invites you hold remain in your account; we do not claw back invites that have already been added to your quota. No content is deleted upon cancellation.

14. Account Suspension, Termination, and Deletion

Grounds for Suspension or Termination

We may suspend or terminate your account if:

  • You violate these Terms of Service
  • We receive valid legal process (court order, subpoena, or law enforcement request) requiring action
  • Your account is associated with verified illegal activity, including CSAM or NCII
  • Your account is associated with the sale, distribution, or facilitation of transfer of controlled substances (including fentanyl, fentanyl analogues, opioids, or counterfeit pills). Such accounts are subject to immediate permanent termination, and we will cooperate with law enforcement consistent with 21 U.S.C. § 841, § 843(b), and other applicable law.
  • Your account is associated with the promotion or facilitation of commercial sexual services, prostitution, or sex trafficking. Such accounts are subject to immediate permanent termination consistent with 18 U.S.C. § 2421A.
  • You engage in activity that disrupts or threatens the integrity of the service
  • We receive repeated valid DMCA claims against your account
  • You are accountable for an invitee’s violations within the accountability periods described in Section 8
  • We discover or have reason to believe you are under 13 years of age

Encryption and Enforcement

We cannot view your encrypted content. All enforcement actions are based on: user-submitted report descriptions and metadata, behavioral signals (e.g., abuse of rate limits, service disruption), account trust signals (report and block patterns, invite chain health), valid legal process, or information obtained through other lawful means. We do not perform client-side scanning or any form of automated content analysis.

Effect of Termination

If your account is terminated, you lose access to your account and all associated encrypted data. Because your content is E2E encrypted with keys we do not possess, we cannot provide you with copies of your decrypted data. Encrypted data is deleted within 30 days of account termination, and may persist in encrypted backups for up to 90 days thereafter. Specific retention periods for each category of data are described in our Privacy Policy Section 10.

Voluntary Account Deletion

You may delete your account at any time through the app (Settings, scroll to the bottom and tap Delete Account) or by contacting [email protected]. We will confirm receipt of email deletion requests within 48 hours and complete deletion within 30 days. Account deletion is permanent and cannot be reversed.

Data Export

You may request an export of your data by contacting [email protected]. Due to E2E encryption, exported data will include only account metadata and encrypted blobs that you can decrypt with your keys. We are developing an in-app data export feature.

15. Push Notifications

boopr uses Apple Push Notification service (APNs) and Firebase Cloud Messaging (FCM) to deliver push notifications. These notifications function as content-free wake-up pings:

  • Push payloads never contain message content, sender identity, photos, ciphertext, or decryptable previews. The payload carries an event-type indicator (for example “new message,” “new boop,” “screenshot alert”) so the banner can be useful, plus a generic title and body chosen from a fixed list. No sender name, post text, photo caption, or other user-generated content is included.
  • When your device receives a ping, the app authenticates with our server, fetches your encrypted content, decrypts it locally, and updates the visible notification with any per-message details.
  • Your device token is encrypted at rest on our servers with AES-256-GCM, with the user’s ID and platform bound as additional authenticated data. The server must be able to decrypt tokens to send push notifications. Tokens are managed by Apple or Google and may be rotated by the operating system; we update our records when your device re-registers, and remove tokens that have been inactive for 90 days.

You may disable push notifications at any time through the app or your device settings.

16. Export Controls and Encryption

boopr uses strong encryption including Ed25519, X25519, and XChaCha20-Poly1305. The export, re-export, and transfer of encryption software and technology is subject to United States export control laws and regulations, including the Export Administration Regulations (EAR) administered by the Bureau of Industry and Security (BIS).

By using boopr, you represent and warrant that:

  • You are located in the United States (see Section 1)
  • You are not on any U.S. government list of prohibited or restricted parties, including the Treasury Department’s Specially Designated Nationals List or the Commerce Department’s Denied Persons List or Entity List
  • You will not use boopr for any purpose prohibited by U.S. export control laws
  • You will not export, re-export, or transfer the app or its encryption technology to any country or person subject to U.S. government embargo or sanctions. For the most current list of sanctioned countries and regions, refer to the U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) at ofac.treasury.gov

17. Law Enforcement and Legal Process

We may disclose account information as required by valid legal process (subpoenas, court orders, search warrants) in accordance with the Electronic Communications Privacy Act (ECPA) and the Stored Communications Act (SCA).

Due to E2E encryption, our disclosures are limited to account metadata and encrypted ciphertext that we cannot decrypt. In response to valid legal process we may disclose, for example: account creation date and last activity timestamp, public keys, connection metadata, post timestamps, encrypted content blobs, invite chain and accountability-period records, subscription status, enforcement-action history, and the other operational metadata described in our Privacy Policy Sections 7 and 21. The Privacy Policy contains the authoritative inventory.

We cannot provide: IP addresses (raw IPs are not retained; only salted HMAC hashes with a monthly-rotating salt are stored for abuse detection, and those are not reversible to an IP), post content, profile details, photos, friend lists, comment text, reaction types, or any other end-to-end encrypted data, because we do not hold the keys required to decrypt it.

In emergency situations involving imminent risk of death or serious physical injury, we may voluntarily disclose available account metadata to law enforcement without a court order, as permitted by 18 U.S.C. § 2702(b)(8) (content) and § 2702(c)(4) (non-content). Emergency disclosures are made at our discretion based on a good-faith belief that an emergency requires disclosure without delay. Requests must be submitted from a verified law-enforcement-domain email address to [email protected] with the subject line “Emergency Disclosure Request,” identify the requesting agency and requesting officer, describe the nature of the emergency, identify the specific account(s) and data sought, and include a senior-officer attestation. Because user content is end-to-end encrypted with keys we do not hold, an emergency disclosure can include only the account metadata enumerated above; we cannot produce decrypted post, profile, comment, reaction, or message content under any circumstances. We document every emergency disclosure request and the basis for our response, and may notify the affected user when notification is not prohibited by law.

Right to Test and Challenge Demands

We treat every demand for user information — subpoena, court order, search warrant, preservation request, national security letter, or emergency disclosure request — as a legal compulsion to be tested for statutory and constitutional sufficiency. We produce only what the specific instrument legally requires. We may decline or move to quash demands that exceed statutory authority, that are overbroad, that are not supported by the level of process the law requires for the data sought (for example, a subpoena seeking content that requires a search warrant under Carpenter v. United States, 138 S. Ct. 2206 (2018), or any successor authority), or that are otherwise legally deficient.

We will notify affected users of law enforcement requests unless prohibited by law or court order (e.g., a non-disclosure order under 18 U.S.C. § 2705). Where permitted, we will challenge non-disclosure orders that exceed the duration consistent with current Department of Justice policy (generally one year absent exceptional circumstances), and will notify the affected user as soon as reasonably practicable after the non-disclosure period ends.

18. Disclaimers

SERVICE PROVIDED “AS IS”: BOOPR IS PROVIDED ON AN “AS IS” AND “AS AVAILABLE” BASIS WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT.

NO EMERGENCY SERVICES: boopr is not a telecommunications service and does not provide access to emergency services (police, fire, medical). Never rely on boopr for emergency communications. If you are in the United States and need emergency assistance, call 911. If you or someone you know is in mental-health crisis, the 988 Suicide & Crisis Lifeline is available 24/7 by calling or texting 988, and the Crisis Text Line is reachable by texting HOME to 741741. boopr is not a crisis service and is not a substitute for professional help.

ENCRYPTION LIMITATIONS: While we use well-audited, industry-standard cryptographic libraries and protocols, no security system is perfect. We do not guarantee that your communications will never be intercepted, compromised, or subject to vulnerabilities discovered in the future. Our cryptographic implementations use @noble/curves, @noble/ciphers, and Go standard library crypto packages.

SERVICE AVAILABILITY: We may interrupt, modify, or discontinue the service (or any features) at any time for maintenance, upgrades, security patches, or due to circumstances beyond our control. We will make reasonable efforts to provide advance notice of planned disruptions.

NO DATA RECOVERY: We cannot recover your account, content, or any data if you lose your recovery phrase. This is an inherent consequence of our E2E encryption design, not a service limitation we can remedy.

THIRD-PARTY PLATFORMS: boopr is distributed through Apple’s App Store and Google Play. Your use of those platforms is subject to their respective terms of service. We are not responsible for the availability, policies, or actions of those platforms.

19. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW:

  • THE AGGREGATE LIABILITY OF BOOPR LLC AND ITS OFFICERS, DIRECTORS, EMPLOYEES, AND AGENTS FOR ALL CLAIMS ARISING OUT OF OR RELATED TO THESE TERMS OR THE SERVICE SHALL NOT EXCEED THE GREATER OF (A) ONE HUNDRED DOLLARS ($100) OR (B) THE TOTAL AMOUNT YOU PAID TO BOOPR IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM.
  • IN NO EVENT SHALL BOOPR BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, INCLUDING BUT NOT LIMITED TO LOSS OF PROFITS, DATA, GOODWILL, USE, OR OTHER INTANGIBLE LOSSES.
  • WE SHALL NOT BE LIABLE FOR ANY DAMAGES RESULTING FROM YOUR FAILURE TO SAFEGUARD YOUR RECOVERY PHRASE, PRIVATE KEYS, OR DEVICE SECURITY.
  • WE SHALL NOT BE LIABLE FOR THE CONDUCT OF OTHER USERS OR ANY CONTENT THEY SHARE, AS WE CANNOT ACCESS OR REVIEW ENCRYPTED CONTENT.
  • WE SHALL NOT BE LIABLE FOR ANY LOSS RESULTING FROM UNAUTHORIZED ACCESS TO YOUR DEVICE OR ACCOUNT.

Nothing in these Terms limits our liability for gross negligence, willful misconduct, fraud, fraudulent misrepresentation, death, or personal injury caused by negligence, or any other liability that cannot be excluded or limited by applicable law. Some jurisdictions do not allow the exclusion or limitation of certain warranties or damages. In such jurisdictions, our liability shall be limited to the fullest extent permitted by law.

20. Dispute Resolution

Governing Law

These Terms and any dispute arising from or relating to them or the service shall be governed by and construed in accordance with the laws of the State of Delaware, United States, without regard to its conflict of law provisions.

California consumer carveout: If you are a California resident, nothing in this Section limits your right to bring claims under California consumer-protection statutes (including without limitation the California Consumers Legal Remedies Act, Unfair Competition Law, False Advertising Law, and California Consumer Privacy Act) in California state court under California substantive law, consistent with California Civil Code § 1799.208 and other applicable California law. The Delaware choice-of-law provision above does not waive or limit any non-waivable rights you have under California law.

Informal Resolution

Before initiating any formal dispute resolution, you agree to first contact us at [email protected] and attempt to resolve the dispute informally for at least thirty (30) days. Most concerns can be resolved this way.

Binding Arbitration

If we cannot resolve a dispute informally, any dispute, claim, or controversy arising out of or relating to these Terms or the service (except as set forth below) will be resolved through binding arbitration administered by JAMS under its Streamlined Arbitration Rules and Procedures. You may instead assert claims in small claims court if your claims qualify and remain in small claims court.

Arbitration Opt-Out

You may opt out of this arbitration agreement by sending written notice to [email protected] within 30 days of creating your account. Your notice must include your name, account identifier, and a clear statement that you wish to opt out of arbitration. If you opt out, you and boopr may litigate disputes in court, but all other provisions of these Terms remain in effect. If you do not opt out within 30 days, you agree to be bound by this arbitration agreement.

Class Action Waiver

YOU AND BOOPR AGREE THAT EACH MAY BRING CLAIMS AGAINST THE OTHER ONLY IN YOUR OR ITS INDIVIDUAL CAPACITY AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS, CONSOLIDATED, OR REPRESENTATIVE ACTION OR PROCEEDING. THE ARBITRATOR MAY NOT CONSOLIDATE MORE THAN ONE PERSON’S CLAIMS AND MAY NOT PRESIDE OVER ANY FORM OF CLASS OR REPRESENTATIVE PROCEEDING.

Exceptions to Arbitration

The following disputes are excluded from arbitration:

  • Injunctive relief: Either party may seek injunctive or other equitable relief in any court of competent jurisdiction to prevent the actual or threatened infringement, misappropriation, or violation of intellectual property rights or confidential information.
  • Sexual assault and harassment claims: In accordance with the Ending Forced Arbitration of Sexual Assault and Sexual Harassment Act (9 U.S.C. §§ 401–402), this arbitration agreement does not apply to claims arising from sexual assault or sexual harassment. Such claims may be brought in court at the claimant’s election.
  • California public injunctive relief: Consistent with McGill v. Citibank, N.A., 2 Cal. 5th 945 (2017), claims for public injunctive relief under California law (including without limitation under the California Consumers Legal Remedies Act, Unfair Competition Law, and False Advertising Law) are not subject to arbitration and may be brought in California court. If any portion of the class-action waiver above is held unenforceable as applied to a claim for public injunctive relief, that claim shall be severed and proceed in court while the remainder of this arbitration agreement applies to all other claims.
  • Small claims court: Either party may bring qualifying claims in small claims court.

Arbitration Location and Procedure

Unless you and boopr agree otherwise, arbitration will take place in New Castle County, Delaware, or may be conducted by telephone, video conference, or based on written submissions if agreed by both parties. The arbitrator’s decision is final and binding and may be entered as a judgment in any court of competent jurisdiction.

Arbitration Fees

If the arbitrator finds that your claim is not frivolous, we will pay all JAMS filing, administration, and arbitrator fees. Each party bears the cost of its own attorneys’ fees unless the arbitrator awards fees to the prevailing party.

21. Indemnification

To the extent caused by your actions, you agree to indemnify, defend, and hold harmless Boopr LLC, its officers, directors, employees, agents, and affiliates from and against any and all claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys’ fees) arising from or related to:

  • Your use of or access to the service
  • Content you create, share, or transmit through the service
  • Your violation of these Terms
  • Your violation of any third-party rights, including intellectual property rights
  • Your violation of any applicable law, rule, or regulation
  • Actions taken by users you invited, during the accountability periods described in Section 8

22. Changes to These Terms

We may modify these Terms from time to time. When we make material changes, we will notify you through the app at least thirty (30) days before the changes take effect and ask you to review and affirmatively accept the updated Terms before continuing to use the service. Non-material changes (such as clarifications or formatting) may take effect immediately upon posting.

If you do not agree to the modified Terms, you must stop using boopr and may delete your account.

We will maintain an archive of prior versions of these Terms, available upon request at [email protected].

23. Security Incidents

In the event of a data breach or security incident that may affect your account, we will notify affected users in accordance with applicable state breach notification laws. Due to E2E encryption, a breach of our servers would expose only encrypted data and metadata, not your posts or profile details. For full details on our breach notification procedures, see our Privacy Policy.

24. Accessibility

boopr is committed to digital accessibility. We use the Web Content Accessibility Guidelines (WCAG) 2.1 Level AA as our target standard and design toward it on an ongoing basis. We do not represent that the service is fully conformant with WCAG at any given moment, and accessibility is a continuing effort rather than a guaranteed state. If you encounter accessibility barriers or need assistance, please contact us at [email protected] with the subject line “Accessibility” so we can assist you and improve the experience.

25. General Provisions

Entire Agreement: These Terms, together with our Privacy Policy, constitute the entire agreement between you and Boopr LLC regarding the service, superseding any prior agreements or understandings.

Severability: If any provision of these Terms is held to be invalid, illegal, or unenforceable by a court of competent jurisdiction, the remaining provisions shall continue in full force and effect. The invalid provision shall be modified to the minimum extent necessary to make it valid and enforceable.

No Waiver: Our failure to enforce any provision of these Terms shall not constitute a waiver of that provision or any other provision. Any waiver must be in writing and signed by Boopr LLC.

Assignment: You may not assign or transfer these Terms or any rights or obligations under them without our prior written consent. We may assign these Terms in connection with a merger, acquisition, reorganization, or sale of substantially all of our assets, provided the assignee agrees to honor these Terms.

Force Majeure: We shall not be liable for any failure or delay in performing our obligations where such failure or delay results from circumstances beyond our reasonable control, including but not limited to natural disasters, acts of government, internet outages, or cyberattacks.

Notices: We may provide notices to you through the app or by posting updates on our website. You may provide notices to us at [email protected] or by mail to Boopr LLC, 2810 N Church St, PMB 748102, Wilmington, DE 19802-4447.

Headings: Section headings are for convenience only and do not affect the interpretation of these Terms.

26. Open Source and Third-Party Software

boopr incorporates open source software components, including cryptographic libraries. These components are subject to their respective open source licenses, which may be reviewed within the app or upon request. Nothing in these Terms restricts your rights under applicable open source licenses.

27. Contact Us

If you have questions, concerns, or feedback about these Terms of Service, please contact us:

General and legal inquiries: [email protected]
Privacy inquiries: [email protected]
DMCA notices: [email protected] (subject line: “DMCA”)
CSAM reports: [email protected] (subject line: “CSAM Report”)
NCII reports: [email protected] (subject line: “NCII Report”)
Security inquiries: [email protected]
Mail: Boopr LLC, 2810 N Church St, PMB 748102, Wilmington, DE 19802-4447

boopr
Home About Roadmap Privacy Terms Guidelines Security Press

We can't see your posts or view your photos. We built it that way.

© 2026 Boopr LLC