NostrKeep is a managed infrastructure service developed by Humanjava Enterprises Inc. It provides a personal Nostr relay and Blossom media server dedicated to your account. This privacy policy explains how NostrKeep handles your data.
TL;DR: Your data is stored on dedicated infrastructure allocated to your account. We maintain the platform but do not access, read, or sell your content.
The Dedicated Infrastructure Model
NostrKeep provides dedicated infrastructure for each subscriber. This means:
Your Nostr events are stored on infrastructure allocated exclusively to your account
Your media files (images, video) live on your dedicated Blossom server
We maintain the platform but do not access, read, or analyze your content
Your private keys are never stored on our servers (use NostrKey for key management)
Your data is not shared with, sold to, or accessed by third parties
Data the Software Handles
NostrKeep stores and processes the following data on your dedicated infrastructure:
Nostr Relay
Nostr Events: Notes, metadata, contact lists, and other events published to your relay
Event Metadata: Timestamps, event kinds, public keys, and tags
Connection Logs: WebSocket connection information from clients that connect to your relay
Blossom Server
Media Files: Images, videos, and other files uploaded to your server
File Metadata: SHA-256 hashes, MIME types, upload timestamps, and public key of the uploader
App Server
Configuration: Your relay and blossom server settings
Session Data: Authentication sessions for the management interface
Data We Collect
We collect only what is necessary to operate the service:
Account Information
Email address (for account and billing communication)
Payment information (processed by our payment provider, not stored by us)
Your Nostr public key (to configure your relay)
Service Metrics
Storage usage (to enforce plan limits)
Connection counts (for service health monitoring)
What We Do NOT Access
Your Nostr events or content
Your media files
Your private keys (we never have them)
The content of your relay traffic
The software does not phone home. There are no analytics endpoints, no telemetry collectors, no usage tracking of any kind.
Data Transmission
NostrKeep only transmits data in the following circumstances:
Nostr Protocol Traffic
Clients (browsers, apps) connect to your relay via WebSocket
Events are received from and sent to connected clients
This traffic flows between clients and your dedicated relay
Blossom Protocol Traffic
Clients upload and download media via HTTP
File transfers occur between clients and your dedicated blossom server
Your Responsibilities
As a NostrKeep subscriber, you are responsible for:
Safeguarding your Nostr private keys
Managing who you authorize to publish to your relay
The content published through your relay
Maintaining your own exports of critical data
If you add other users' keys to your relay (allowing others to publish), you may have additional responsibilities under data protection regulations in your jurisdiction.
Security
NostrKeep is designed with security as a priority:
Dedicated Infrastructure: Your data is isolated on your own relay and blossom server
Nostr Protocol: Events are cryptographically signed and verifiable
Blossom Protocol: Uploads authenticated via Nostr event signatures
No Tracking: Zero analytics, telemetry, or data collection
Minimal Dependencies: Reduced attack surface
Security Best Practices:
Keep your server software updated
Use TLS (HTTPS/WSS) for all connections
Restrict relay access to authorized public keys if desired
Regularly backup your database and media files
Monitor server logs for unusual activity
Website and Landing Page
The NostrKeep website (nostrkeep.com) is a static site hosted on GitHub Pages. It does not:
Use cookies
Run JavaScript analytics
Collect form submissions
Track visitors
GitHub Pages may collect standard web server logs (IP addresses, user agents). See GitHub's privacy statement for details.
Children's Privacy
NostrKeep is not directed at children under the age of 13. The subscriber is responsible for ensuring compliance with applicable age restrictions.
Changes to This Policy
We may update this privacy policy from time to time. Any changes will be posted on this page with an updated "Last Updated" date.