privacy policy · effective October 4, 2026
Nothing leaves your machine unless you point it somewhere.
The plain version first. Phosphor has no telemetry, no crash reporting, no analytics, no accounts and no ads. I have not built any of that in, first party or third party, and there is no server of mine for the app to talk to. Everything it remembers lives in a folder on your computer. The only things it ever sends go to places you chose yourself: the machine on your network, a Stash server you entered the address of, a page a plugin loads, a Bluetooth device you connected. What those endpoints and your operating system do with traffic is outside my control, and this page says where that line is.
The rest is the long version, written so that it is checkable. The source is public; every claim here can be read in the code.
What this covers
This policy covers the Phosphor application on Windows, macOS, Linux and Android, the valencesim device twin that ships with the desktop builds, the Nucleus firmware that runs on the machine, and this website, openvalence.org. All of it is published by AtlanticTM under the OpenValence name. "I" below means the one person who maintains it.
What the app stores, and where
Phosphor keeps its state in the per-user application data folder your operating system gives it: %APPDATA% and %LOCALAPPDATA% under com.phosphor.app on Windows, ~/Library/Application Support/com.phosphor.app on macOS, ~/.local/share/com.phosphor.app on Linux (inside ~/.var/app/org.openvalence.Phosphor for the Flatpak), and the app's private storage on Android. The Microsoft Store build may be redirected by Windows into the package's own LocalCache folder. In those folders you will find:
- Saved hubs: the address, name and session details of machines you connected to, so the app can reconnect.
- Plugin settings, including, if you set one up, the URL and API key of your Stash server. The key is stored as you typed it, protected only by your operating system's user account, and it is deliberately left out of the app's settings export so it never ends up in a backup file.
- Your themes, layouts, pages, enabled plugins and the simulator's saved state.
- A log file (
Phosphor.log) with technical events: connections, errors, the simulator's output. It stays on disk and is never uploaded. If you send it to me for a bug report, that is you sending it. - Media you open in the funscript player is read from where it already is. The app does not copy it anywhere.
Uninstalling removes the application. The data folder may stay behind depending on the platform; deleting it deletes everything the app ever knew about you.
What the app sends, and to whom
Every network connection Phosphor makes goes to an endpoint you chose. There is no endpoint of mine.
- Your machine. To find a hub, the app sends a short discovery broadcast on your local network and listens for replies; it only broadcasts when you ask it to scan, or when it reconnects to a hub you saved. Once connected, the app and the hub exchange machine state over a WebSocket on your network. An emergency stop is also sent as a broadcast so it reaches the hub even if the session has dropped.
- Stash. If you enter a Stash server in the funscript player, the app sends requests to that address with the API key you gave it, and streams video from it. That is your server, on whatever network you put it on; its own logs are its business.
- Plugins and the pages they load. The app allows plugins to fetch
httpandhttpsURLs. The plugins that ship with the app only contact addresses you configured. A plugin you install from elsewhere can contact whatever its author wrote it to; read its manifest before enabling it. - Other programs on your computer. Phosphor runs a ButtplugIO server so that other software can drive the machine and your toys through it. It listens on the loopback address only (
127.0.0.1, port 12345 by default), so only programs on the same computer can reach it. It never listens on your network unless you change that setting. - The simulator. valencesim runs as a child process on loopback. Nothing it does leaves the computer.
The app does not check for updates by itself. Updates arrive through whatever installed it: the Microsoft Store, Flathub, or a download from GitHub.
Bluetooth
Phosphor uses Bluetooth Low Energy for two things: finding and talking to a hub when Wi-Fi is not available, and, through ButtplugIO, finding and controlling toys. A scan runs when you press Scan, and the app connects only to the device you pick. It reads the advertising data the devices around you broadcast during a scan, keeps it in memory for the list you see, and discards it when the scan ends; it does not keep a record of devices you did not connect to.
On Android, the operating system requires the location permission before any app may scan for Bluetooth devices, because scan results can in principle be used to infer location. Phosphor asks for that permission for that reason only. It does not read your position and has no code that would.
The machine
Nucleus, the firmware on the hub, stores the machine's configuration and the names of the clients that are allowed to control it, on the board itself. It has no internet connection of its own and no server it reports to. It answers discovery on your local network and serves the clients that connect to it. Resetting the board's configuration clears it.
What is outside my control
The honest list of parties that may learn something about you while you use this software, none of which I run or receive anything from:
- Your operating system. Windows, macOS, Android and Linux distributions collect their own diagnostics about the applications you run, under their own settings and policies. On Windows the app renders through WebView2, which is Microsoft's component and follows Microsoft's telemetry settings for your account.
- Where you got the app. The Microsoft Store, Flathub and GitHub each count installs and downloads and may show me aggregate numbers. They do not give me who you are.
- Endpoints you configured. Your Stash server, any URL a plugin loads, and the hub itself all see the requests the app makes to them.
- Bluetooth devices. A connected device learns that something connected to it. What a toy's manufacturer does with that, if it has its own app or cloud, is theirs to disclose.
This website
openvalence.org is static files served by GitHub Pages. GitHub keeps standard server logs (IP address, pages requested, browser) under GitHub's privacy statement; I do not have access to them. The site sets no cookies, loads no analytics, and serves its fonts from its own folder rather than a third party. The documentation at /Valence/ is the same kind of static site.
Changes and contact
If any of the above changes, this page changes with it and the date at the top moves. The page is a file in a public repository, so its history is the changelog: every revision.
Questions, or something here that does not match what the code does: atlantic@openvalence.org. If the code and this page disagree, the code is the fact and this page is the bug.