mist — Privacy Policy

Last updated 6 August 2026

mist is a two-person app. You pair with one partner, and the two of you can see each other's daily step count and send each other a short nudge. This policy explains exactly what data that involves, where it goes, and what we keep.

Who we are

mist is developed by Muhammad Atif Ali. For any privacy question, or to request deletion of your data, contact mist@matifali.dev.

What the app collects, and why

DataWhyLeaves your device?
Daily step count So your partner can see it, and so you can compare the two counts Only if you turn on sharing
Nudges you send (a short emoji or name) To deliver the nudge to your partner Yes — sent to your partner
A pair ID and a device ID generated by the app To route messages between exactly your two devices Yes — stored on our relay
A Firebase Cloud Messaging token To wake your phone when your partner sends something Yes — stored on our relay

That is the complete list. mist does not collect your name, email address, phone number, contacts, location, photos, files, microphone audio, or camera input. There is no account to create and no sign-in. The identifiers above are generated by the app itself and are not linked to your Google account or to your real-world identity.

Health and fitness data

Your step count is health and fitness data, and mist shares it with one other person: the partner you pair with. This is the entire purpose of the app.

On the watch, step counts come from Android Health Services. mist reads only your daily step total. It does not read heart rate, sleep, workouts, location traces, or any other health metric.

Sharing your step count is off until you turn it on. After you pair, mist asks whether you want to share your step count with your partner, and nothing is sent unless you agree. You can turn sharing off again at any time with the Share my step count switch on the app's main screen; when it is off, your step count stays on your own devices. Pairing with a new partner always asks again — consent is never carried over.

How your data travels

Step counts and nudges are end-to-end encrypted on your device before they are sent. They pass through a relay server we operate, but the relay does not hold the encryption key and cannot read their contents. Only your partner's device can decrypt them. All network connections use HTTPS.

The encryption key is created when you pair and is shared only between your two devices. It is stored in the app's private storage on each device.

What the relay can see

Even though message contents are encrypted, operating the relay means we necessarily hold some metadata:

We do not use this metadata for advertising, profiling, or analytics, and we do not sell it or share it with third parties. Google is involved only as infrastructure: Firebase Cloud Messaging delivers the wake notification, and the relay runs on Google Cloud.

No advertising, no analytics

mist contains no advertising, no advertising identifier, no analytics SDK, and no crash-reporting SDK. Nothing about how you use the app is measured or reported back to us.

How long we keep things

Please be aware: tapping Unpair currently clears mist's data from your own device, but it does not yet automatically delete your pair and device records from the relay. Until that is automated, email mist@matifali.dev and we will delete them for you.

Deleting your data

To have your data erased, email mist@matifali.dev from any address and say you would like your mist data deleted. We will purge your pair record, both device registrations, the messaging tokens, and any queued messages. If you can include the pair ID shown in the app it will be quicker, but it is not required.

You can also remove everything held on your own device at any time by tapping Unpair, or by uninstalling the app.

Children

mist is not directed at children under 13 and we do not knowingly collect data from them. If you believe a child under 13 has used mist, contact us and we will delete the associated data.

Security

Message contents are end-to-end encrypted and all connections use HTTPS. No system is perfectly secure, and mist is early software developed by one person; we cannot guarantee absolute security. If you find a security problem, please report it to mist@matifali.dev.

Changes to this policy

If this policy changes in a way that affects what we collect or who we share it with, we will update the date at the top of this page. Significant changes will also be noted in the app.