Terms & Conditions

Last updated: 29 August 2026

⚖️ Terms summary: HushHush is a local-only encrypted vault. Your messages and your keys live on your own device and are decrypted there — we never receive them, there is no HushHush account, and there is no way for us to reset or recover anything. That is the point, and it means you alone are responsible for your password and your device: if you lose either, nobody can get your data back, including us. These Terms cover the app, this website, and the community forum. The forum is different from the app — it is public, and what you type into it is stored by us.

1. What these Terms cover

These Terms & Conditions ("Terms") apply to everything we publish. In these Terms:

  • the App means the HushHush application, on any platform we release it for;
  • the Site means the website at thehushhush.com and every page on it, including this one;
  • the Forum means the community forum on the Site;
  • the Services means the App, the Site and the Forum together;
  • HushHush means the Services collectively, unless the context makes clear that only the App is meant;
  • a post means anything you submit to the Forum, including a reply.

By downloading, installing or using the App, by browsing the Site, or by posting on the Forum, you agree to these Terms. If you do not agree, do not use the Services — uninstall the App and stop using the Site.

Different parts of these Terms apply to different parts of the Services. Where a section is about only the App, or only the Forum, it says so.

Which versions this covers. These Terms cover the App on every platform we release it for. Today that is iOS, from the App Store. Versions for Android and for desktop computers are in development; when we release them, these Terms apply to them too. Where we describe a build as a preview, a beta or a test build, expect it to be less stable than a released version.

Cost. HushHush is currently provided free of charge; any paid features we add in future will carry additional terms shown to you at the time.

2. Who we are

HushHush is currently an independent personal project, not a registered company. It is intended to be based in the EEA and operates internationally. In these Terms, "we", "us" and "our" mean the individual who builds and maintains HushHush, reachable at support@thehushhush.com.

We say that plainly rather than implying a corporate counterparty that does not exist. That address is the contact point for everything in these Terms.

We apply the principles of the EU General Data Protection Regulation as our baseline for the personal data the Site and the Forum collect, as described in our Privacy Policy.

3. Who can use HushHush

HushHush is made for adults.

  • The App. You must be old enough, where you live, to agree to these Terms. If you are under 18, use HushHush only with the agreement of a parent or guardian, who accepts these Terms on your behalf.
  • The Forum. You must be at least 16 to post on the Forum. Anything you post there is public and you cannot take it back, so we set a higher bar for it than for the App. Do not post about anyone younger than that either.
  • Sanctions and export rules. You confirm that you are not barred from receiving or using cryptographic software under the laws that apply to you. See section 14.

4. Your licence to use HushHush

We grant you a personal, non-exclusive, non-transferable, non-sublicensable and revocable licence to install and use the App on devices you own or control, and to use the Site and the Forum, for your own personal or internal business purposes, in line with these Terms.

That is all this licence gives you. It transfers no ownership of anything, and it ends automatically if you stop meeting these Terms. We may suspend or end it if you seriously or repeatedly break them.

You may not rent, lease, lend, sell, redistribute or sublicense the App, or make it available to anyone else as a service.

5. What HushHush is — and is not

The App is a local encrypted vault, not a hosted messaging service.

  • No HushHush account. Using the App does not require you to register with us, or to give us a username, email address or phone number. The App asks you to choose a display name. That name never reaches us, but it is shared with the people you pair with — it travels inside the pairing code and the encrypted set-up messages, so it is stored in their vault as well as yours. A display name is a convenience, not proof of identity: it is chosen by whoever sent it, and the App does not verify it. If you connect an automated transport, you sign in to that third-party service with its own credentials — that account is with the provider, not with us.
  • No servers for your messages. We operate no relay server, no database and no storage of any kind for your messages, your contacts or your keys. None of it ever reaches us. Two narrow exceptions, stated for completeness: on Android, the final step of connecting a Google mailbox returns through a page we host on the Site, which receives a one-time authorisation code in its address and hands it straight back to the App — it never receives your password, your mail or your keys, and it stores nothing, though the request itself reaches our web host's ordinary logs like any page view; and the Site itself, including the Forum, uses a third-party hosted database, described in section 12.
  • Encryption happens on your device. Your message content is encrypted on your device before it leaves it, and is decrypted only on the recipient's device. The delivery channel you choose necessarily sees the delivery information around that content — which accounts are involved, when, how often, and how large each message is — and it can generally tell that the traffic is HushHush. HushHush cannot conceal that, and you should not rely on it to do so.
  • The Site and the Forum are different. They are ordinary websites, hosted for us by third-party providers, and what you type into the Forum or into a form on the Site is stored there. Do not treat the Forum as private.

There is no "forgot password" feature, no key escrow and no administrative backdoor. We hold no copy of your vault, your password or your keys, and we cannot reset or recover them.

6. Your password, keys and device

Because there is no recovery route, several things are entirely on you:

  • Your password. You are responsible for choosing a strong master password, remembering it, and keeping it to yourself.
  • Losing it means losing the vault. If you forget your master password, your data cannot be recovered by us, and we have no mechanism to recover it. There is no reset link, no recovery code and no support process that can restore access.
  • Your device. You are responsible for the physical and digital security of the device HushHush runs on, including keeping the operating system updated and the device locked with a passcode.
  • Losing the device is losing the vault. The key material is tied to the device you set HushHush up on, and is designed to stay out of your device's encrypted backups, so that restoring a backup onto a new phone should not unlock your vault. On a device upgraded from an older version this takes effect only once the App has run again, and in rare cases the App deliberately keeps the older, backup-included copy rather than risk destroying your only key. That is a security property, not a bug — but it means a lost, broken, wiped or replaced device means a lost vault, and we cannot move it for you.
  • Old keys linger briefly. So that a message which arrives late can still be read, the App keeps the keys for messages it has not yet received for up to 14 days. A device examined inside that window still holds usable keys for those messages.

7. Features that destroy data

HushHush includes features that permanently destroy data on your device. Some you switch on yourself; one is always active. Read this section before you rely on any of them.

  • Duress passwords and decoy vaults. You can configure a second password that opens a decoy vault containing synthetic, locally generated content instead of your real one. You choose what happens to your real vault when that password is used: it can be left intact, or it can be permanently destroyed at that moment. In both cases, what appears on screen is the decoy. Deciding whether to use these features, and whether doing so is wise or lawful where you are, is your responsibility.
  • Automatic wipe after repeated failed unlocks. After eleven consecutive failed unlock attempts — a wrong password, or a failed biometric check — the App erases its local data automatically, without further warning. This is always on and cannot be switched off, and the count is not reset by closing or restarting the App.
  • Inactivity wipe. If you set an inactivity period, the App erases its local data the first time it is opened after that period has elapsed. There is no warning and no confirmation.
  • A wipe is permanent, but the routes differ. These are not all the same operation. The eleven-attempt wipe and the inactivity wipe erase the vault and also erase, on a best-effort basis, the device-bound secret HushHush keeps in your device's secure storage — the iOS Keychain, the Android Keystore, or the operating system's keyring on desktop. The duress-password wipe works differently: it overwrites your real vault with the decoy, so the real vault is no longer on the device, but it keeps that device-bound secret, because the decoy that replaces it needs it. We hold no copy either way, so we cannot bring anything back and neither can you. The erasure is best-effort — it is what your operating system's secure storage lets an app do, not a guarantee about every trace left on the hardware. Treat a wipe as one-way.
  • What a wipe does not reach. A wipe clears what is on your device. It does not reach anything that has already left it. If you have used an automated transport, the encrypted messages already delivered to that messaging or mail account are still sitting in that account, and so are the copies in the other person's account. HushHush cannot delete them and a wipe does not touch them. Any authorisation you granted a mail provider also remains in force: withdrawing it is something you must do yourself, in that provider's own account settings.
  • No promises about what an examiner can tell. Decoy vaults are built so that a decoy is not obviously distinguishable from a real vault. We cannot promise that a determined forensic examiner, or someone who already knows how HushHush works, would not draw conclusions from your device anyway.

You acknowledge that these actions are permanent, cannot be undone, and may run without any further prompt.

8. Transports and delivery

HushHush lets you move encrypted text by hand — copy and paste, or your device's share sheet — or automatically, through a messaging or mail account you already control. The transports available to you are the ones shown in the App; we may add, change or remove supported services over time, and this section applies to all of them, including any we add later.

  • Your account, your credentials. When you link a third-party service you sign in with your own credentials, and we never receive them. Where they are kept on your device depends on the service: most are held inside your encrypted vault, while a Telegram sign-in instead creates a session in Telegram's own local database, which HushHush keeps encrypted alongside the vault rather than inside it. Both are erased when the App wipes. On Android, the final step of a Google sign-in returns through a page we host on the Site, which receives a one-time authorisation code and never a password, a token or a message.
  • Permissions can be broader than the use. If you connect a mail account, the permissions you grant are the ones that provider's consent screen describes, and they are broader than the messages HushHush actually reads. The App only ever looks for its own messages, but we cannot narrow the permission itself. You can withdraw the authorisation at any time in your provider account. Uninstalling the App, or erasing your vault, does not withdraw it.
  • Ciphertext only. Automated transports carry your message content only as ciphertext — the provider cannot read the content, and neither can we. We operate no proxy relay and we do not intercept transport traffic. Everything around the content is ordinary and visible to the provider: who sent it, to whom, when, and how large it was. Over email, HushHush also writes a fixed subject line and a marker header in the clear so the other device can find its own messages, which makes HushHush mail plainly identifiable as HushHush mail.
  • We do not promise delivery. HushHush encrypts your message and hands it to a channel you chose. It is not a messaging service and does not carry your messages itself. We cannot and do not promise that any message will be sent, delivered, delivered in order, delivered on time, or delivered at all. Messages may be delayed, duplicated, dropped or rejected by the transport, the network, the other person's settings or their device. Text queued while you are offline is sent when your device reconnects, and will not be sent if you delete the App or wipe the vault first. If a message matters, confirm it arrived.
  • Third-party terms. You must comply with the terms of service and privacy policies of any service you connect, and you are responsible for making sure your use of HushHush with that service is permitted by it — including, for example, your mobile data agreement. We are not a party to your relationship with those providers, and what they do with the ciphertext they carry is governed by their policies, not ours.

9. Acceptable use and security research

Use the Services lawfully. You agree not to:

  • use the Services for any unlawful, fraudulent or malicious purpose;
  • modify or interfere with the App's security or cryptographic functions in a way that puts the people you communicate with at risk, or misrepresent to them the protection a message has received;
  • break any export control or encryption regulation that applies where you are;
  • break, overload, scrape or automate the Site or the Forum, or try to reach parts of them you were not given access to.

Security research

We want people to find problems in HushHush and tell us about them. Nothing in these Terms is meant to stop good-faith security research.

If you are testing in good faith, you may probe your own installation and your own data. Please do not access anyone else's data or device, do not disrupt the Site or the Forum for other people, do not run destructive or high-volume tests against the Site, and do not publish a flaw before we have had a reasonable chance to fix it. Tell us what you found at support@thehushhush.com. We will not pursue you for research that stays inside those lines. We do not run a paid bug bounty.

If you go outside those lines — attacking other people, using a flaw rather than reporting it, or dumping data — this section does not protect you.

10. Your content on the Forum

What you post on the Forum stays yours. You keep the copyright in it.

By posting, you give us a non-exclusive, worldwide, royalty-free licence to store, host, copy, publish, display and distribute your post, and to edit, format, translate or shorten it, for the purpose of running the Forum and HushHush. That licence lasts as long as your post is on the Forum, and afterwards only for backups and archived copies until they are overwritten in the ordinary course. You promise that what you post is yours to post, that it does not infringe anyone else's rights, and that publishing it will not break the law. We do not pay for posts and we are not obliged to publish or keep any post.

Posts are public, and you cannot delete them yourself

Anything you post on the Forum can be read by anyone, including people who do not use HushHush. Posts can be copied, quoted, indexed by search engines and archived by third parties within minutes of going up, and once that has happened it is outside our control. The Forum has no accounts, so there is no button to edit or delete your own post — if you want something taken down, email support@thehushhush.com and we will normally remove it from the Forum where we reasonably can, subject to section 11. We cannot remove copies other people have already made. Write every post as though it will be public forever.

Names are not verified, and posts are not us

The Forum has no accounts. The display name on a post is free text typed by whoever wrote it, and we do not check it. Anyone can type any name, including ours. Treat every name on the Forum as unverified.

Posts are the views of the people who wrote them. We do not endorse, verify, adopt or take responsibility for anything a user posts, including any security or technical advice, which may simply be wrong. Do not act on it as though it came from us. Any official statement from us is published on the Site, not delivered as a forum reply.

We will never ask you for a password, a recovery detail, a pairing code or anything from your vault. If a post or a reply asks you for one, it is not from us, whatever name is on it — please tell us at support@thehushhush.com.

Ideas and feedback

If you send us feedback, bug reports or suggestions — by email, on the Forum, or anywhere else — you are giving us permission to use them freely, without payment, credit, confidentiality or any obligation to you. That includes building them into HushHush. This is about the suggestion itself and nothing else you own. If you would rather keep an idea to yourself, please do not send it to us.

11. Forum rules, moderation and reporting

The Forum is for asking questions, reporting bugs, requesting features and sharing tips. When you post, do not:

  • post anything illegal, or anything that encourages or helps someone break the law;
  • post anything that harasses, threatens or bullies anyone, or that incites hatred or violence;
  • post other people's personal information — names, addresses, phone numbers, email addresses, photos, screenshots of private conversations — without their consent;
  • impersonate anyone, including us, or claim to speak for HushHush;
  • post sexual content, or anything at all involving children;
  • post malware, exploit code, phishing links or anything designed to cause harm;
  • post spam, advertising, or the same thing over and over;
  • post anything that infringes someone else's copyright, trade mark or other rights.

One more, for your own sake: do not post your own security details. Never post a password, a recovery detail, a pairing QR code, a safety number or the contents of your vault.

What we may do, and what we do not promise

We may, but we are not obliged to, review, edit, refuse, move or remove anything posted on the Forum, and we may block someone from posting. We can do that at our discretion, with or without notice. We do not monitor the Forum and we do not pre-screen posts: nothing here creates a duty to review anything, and the fact that we have removed one post does not mean we have looked at any other. If we remove a post, we may keep a copy where we need it to deal with a complaint or a legal obligation.

Reporting a post

If you see something on the Forum that is illegal, breaks these rules, or infringes your rights, tell us at support@thehushhush.com. Put "Forum report" in the subject line and include a link to the post or enough detail for us to find it, what is wrong with it, and how to reach you if you would like a reply.

We look at every report we receive and decide in good faith. We may remove the content, leave it up, or ask you for more information. We aim to acknowledge reports within a few working days, though we are a small project and cannot promise a fixed time. Where we remove something after a report, we will normally tell the person who posted it what we removed and why, if we have a way to reach them. If you think we got it wrong — either by removing your post or by leaving something up — reply to us and we will look again.

If you are reporting something you believe is a crime in progress or a risk to someone's safety, please contact your local police as well as us. We are not an emergency service.

12. The Site, the waitlist and privacy

The App is built to collect nothing about you: your messages, contacts and keys stay on your device and never reach us, with the narrow exception described in section 5. Our Privacy Policy explains how the App handles your data.

The Site is a different matter, and this section says so plainly rather than leaving you to find it out.

  • The Forum. When you post, the display name you type, along with the category, title and body of a post or the text of a reply, is stored for us in a third-party hosted database (Supabase) and published publicly on the Site. There is no account, so there is nothing to sign in to and nothing to delete yourself — email us if you want a post removed.
  • The enterprise waitlist. The enterprise version of HushHush is not available yet. If you join the waitlist on our enterprise page, the work email address, organisation name and description you submit are stored in the same third-party database. Joining the list tells us you would like to hear about it and nothing more: it is not an order, a booking or an agreement, it creates no obligation on either of us, and it gives you no entitlement to access, to a price, or to a place in a queue. We use what you send us to get in touch about HushHush for organisations, and for nothing else. Ask us at support@thehushhush.com to remove you at any time and we will.
  • Ordinary web hosting. The Site is served by a third-party host, and the pages load fonts and icons from third-party content delivery networks. Those providers see your IP address and browser details in the ordinary course of serving a web page, as they would for any website. The App is built differently and makes no such requests.

None of this touches your vault. Apart from the Android sign-in return page described in section 5, nothing you give the Site is connected to anything in the App, and we have no way to link the two.

13. Ownership and open source

HushHush is licensed to you, not sold. We and our licensors keep all rights in the App, the Site, the Forum and everything in them — the code, the design, the text, the graphics, and the HushHush name and logo. Nothing in these Terms transfers any of those rights to you. HushHush is not open-source software; publishing the source is something we may choose to do in future, and nothing here is a promise to do it.

What you may not do with the software

Except to the extent that the law expressly allows it despite this restriction, you agree not to copy, modify, adapt, translate or create derivative works from the App, and not to reverse-engineer, decompile or disassemble it or try to derive its source code.

Nothing in this section limits rights you have under mandatory law — including, for users in the EEA and the UK, the right to make a back-up copy, to observe and study how the program works, and to decompile it where that is necessary to achieve interoperability with other software. Good-faith security research is covered by section 9.

Open-source components

HushHush is built on top of open-source software written by other people, including cryptographic libraries, the app runtimes it is packaged with, and the client libraries for the transports it supports. The Android app also includes Google's ML Kit to read pairing QR codes on-device, as explained in our Privacy Policy.

Each of those components is licensed to you under its own terms, and where those terms conflict with these Terms, the component's own licence governs that component. Those licences generally come with their own warranty disclaimers, which apply in addition to ours. We will provide a current list of components and their licences on request at support@thehushhush.com.

14. Cryptography and export rules

HushHush uses strong cryptography. Message content is protected by a four-cipher cascade — AES-256-GCM, XChaCha20-Poly1305, XSalsa20-Poly1305, and AES-256-CBC with HMAC-SHA-256 — with Argon2id for password-based key derivation and HKDF-SHA-512 for key derivation and separation. Contacts you pair in person with the optional "Ultra Secure" setting additionally use a hybrid post-quantum key exchange: ML-KEM-1024 (NIST FIPS 203) combined with P-384 elliptic-curve Diffie-Hellman, so that it is at least as strong as the classical exchange on its own. That option is chosen per contact when you pair in person and is fixed for that contact. It is not a global setting and it is not on by default.

Software of this kind is controlled under export and import rules in many countries, including the US Export Administration Regulations (ECCN 5D002) and the Wassenaar Arrangement's dual-use controls. Some countries also restrict importing or using encryption software at all.

By using HushHush you confirm that you are allowed to receive and use cryptographic software where you are, that you are not in a country subject to a relevant embargo, and that you are not on a prohibited-party list; and you agree not to export or re-export it in breach of those rules. Checking the rules where you live is your responsibility, not ours.

15. Support, updates and availability

We try to answer support email and to keep HushHush working, but we do not promise a response time, and we are not obliged to provide support, maintenance, updates or new versions.

We may change, suspend or withdraw any part of the Services — including features, transports, the Site and the Forum — at any time, with or without notice. We may stop the project altogether. Where we can reasonably give notice of something significant, we will post it on the Site.

Some features depend on services we do not control. If one of those changes its rules or its interfaces, the matching feature may stop working and we may have to remove it.

You are responsible for your own backups of anything you care about. Because there is no server and no recovery route, we cannot restore anything for you.

16. No warranties

The Services are provided on an "AS IS" and "AS AVAILABLE" basis, without warranties of any kind, whether express, implied, statutory or otherwise. To the maximum extent permitted by applicable law we disclaim all warranties, including the implied warranties of merchantability, fitness for a particular purpose, title and non-infringement. If you are a consumer, this does not affect rights the law gives you that cannot be excluded.

HushHush is built from standard, published cryptographic building blocks. Those building blocks are widely studied. The way HushHush layers them together is our own design, and it has not been independently audited: there has been no third-party security audit, no penetration test and no formal verification of HushHush. We say so plainly rather than implying a review that has not happened. The optional post-quantum protection relies on a third-party library that is itself pre-1.0 and unaudited.

We do not warrant that the Site or the Forum will be available, uninterrupted, timely, secure or error-free, that defects will be corrected, or that anything posted on the Forum is accurate, complete, current or fit for any purpose. You rely on forum content at your own risk.

No software and no encryption can protect you from everything. A compromised or unlocked device, a weak password, a flaw in your operating system, someone reading your screen, or a capable attacker with physical access can all defeat good cryptography. HushHush reduces risk; it does not remove it. Do not rely on it as your only protection where the consequences of failure would be severe.

17. Limits on our liability

First, what we never exclude. Nothing in these Terms limits or excludes our liability for death or personal injury caused by our negligence, for fraud or fraudulent misrepresentation, or for anything else that the law does not allow us to limit or exclude. Nothing in these Terms limits our liability to you beyond what applicable law permits. If you are a consumer, you have legal rights these Terms cannot take away, and nothing here affects them.

Subject to that, the Services are provided free and as-is, and to the fullest extent the law allows we are not liable for:

  • loss of, or inability to reach, your messages, contacts, keys or vault — including after a wipe, a forgotten password, a lost device, or any of the destructive features described in section 7;
  • messages that are delayed, not delivered, or delivered to the wrong person by a transport you chose;
  • anything a third-party service does or fails to do;
  • anything posted by another user on the Forum;
  • loss of profits, loss of business, business interruption, or loss of an expected saving;
  • damage to, or malfunction of, any device the Services are used on;
  • indirect or consequential loss of any kind, and — to the extent the law allows — any other loss of any kind, whether direct or indirect.

We are also not liable for loss or damage that was not foreseeable — meaning it was neither obvious that it would happen, nor something you told us about before you started using HushHush.

Where we are liable to you despite all of the above, our total liability for all claims connected with the Services is limited to £100, or to the amount you have paid us in the twelve months before the claim if that is greater. HushHush is currently free, so that amount is normally nil.

Where these Terms limit our liability, that limit also covers the people who maintain HushHush, acting in that capacity.

18. Ending these Terms

You can stop at any time. Delete the App and stop using the Site and the Forum. That ends these Terms for you. Your vault stays on your device until you remove it; we hold no copy, and there is nothing for us to delete.

What we can do. If you break these Terms — particularly the Forum rules — we may remove your content, refuse to publish further posts from you, and take technical measures to stop you posting. The Forum has no accounts, so there is no personal login for us to close.

What we cannot do. Because HushHush has no accounts and no servers holding your messages, we cannot remotely disable the App, reach your vault, or delete anything on your device. We say so because nothing here should read as a power we do not have.

The sections on your content licence, ownership, warranties, liability and the general provisions carry on applying after these Terms end.

19. Changes to these Terms

We may update these Terms — for example when we add a feature, change how the Forum works, or reflect a change in the law.

When we do, we will change the "last updated" date at the top and publish the new version here. If a change is significant, we will also put a notice on the Site's home page for at least 30 days, and in the App where we reasonably can.

Changes apply from the day they are published. If you keep using the Services after that, you are accepting them. If you do not accept a change, stop using the Services — your vault stays yours either way, and there is nothing you need from us to walk away. We will not apply a change retrospectively to something that has already happened.

20. If you got the App from Apple's App Store

This section applies only to the iOS app downloaded from the App Store, and it overrides anything else in these Terms that conflicts with it.

  • Not with Apple. These Terms are concluded between you and us only, and not with Apple. We, and not Apple, are solely responsible for the App and its content. These Terms do not set usage rules for the App that conflict with the Apple Media Services Terms and Conditions in force when you accept these Terms, and we confirm we have had the opportunity to review those terms.
  • Scope. Your licence under section 4 is further limited, for the App obtained through the App Store, to a non-transferable licence to use it on any Apple-branded products that you own or control, as permitted by the Usage Rules in the Apple Media Services Terms and Conditions — except that it may also be accessed and used by other accounts associated with you through Family Sharing or volume purchasing.
  • Maintenance and support. We are solely responsible for providing any maintenance and support for the App. Apple has no obligation whatsoever to furnish any maintenance or support services for it. Support requests go to support@thehushhush.com.
  • Warranty. We are solely responsible for any product warranties, express or implied, to the extent not effectively disclaimed in section 16. If the App fails to conform to any applicable warranty, you may notify Apple, and Apple will refund the purchase price (if any) you paid for it. To the maximum extent permitted by applicable law, Apple has no other warranty obligation of any kind for the App, and any other claims, losses, liabilities, damages, costs or expenses attributable to a failure to conform to any warranty are our responsibility rather than Apple's.
  • Product claims. We, and not Apple, are responsible for addressing any claim by you or a third party relating to the App or your possession or use of it — including product liability claims, claims that the App fails to meet a legal or regulatory requirement, and claims arising under consumer protection, privacy or similar legislation.
  • Intellectual property. If a third party claims that the App, or your possession and use of it, infringes their intellectual property rights, we, and not Apple, are solely responsible for the investigation, defence, settlement and discharge of that claim.
  • Legal compliance. You represent and warrant that you are not located in a country subject to a US Government embargo, or designated by the US Government as a "terrorist supporting" country, and that you are not listed on any US Government list of prohibited or restricted parties. This is in addition to the confirmation you give in section 14.
  • Third-party terms. You must comply with applicable third-party terms when using the App — for example, connecting an automated transport must not put you in breach of your mobile data agreement or of the terms of the service whose account you connect.
  • Third-party beneficiary. You and we acknowledge and agree that Apple and Apple's subsidiaries are third-party beneficiaries of these Terms as they relate to your licence of the App, and that on your acceptance of these Terms Apple has the right — and is deemed to have accepted the right — to enforce these Terms against you as a third-party beneficiary. It is our express intention and yours that Apple and its subsidiaries should have the benefit of, and be able to enforce directly against you, the provisions of this section 20.

21. General

  • If part of this does not hold. If a court finds any part of these Terms unenforceable, that part is cut back to the smallest extent needed, or removed, and the rest stays in force.
  • The whole agreement. These Terms are the whole agreement between us about the Services, and they replace anything said earlier. Marketing copy on the Site is not a promise or a warranty unless these Terms say it is.
  • Not enforcing something is not giving it up. If we do not enforce part of these Terms straight away, we can still enforce it later.
  • Transfers. You may not transfer your rights under these Terms to anyone else. We may transfer ours — for example if the project is later run through a company, or handed on to other maintainers — as long as it does not reduce your rights.
  • Other people. Apart from Apple and its subsidiaries, who may enforce section 20, nobody other than you and us has any right to enforce these Terms.
  • Language. These Terms are written in English. Any translation is for convenience, and the English version governs.

22. Contact

For questions about these Terms, to report something on the Forum, to ask us to remove a post, or to reach a person about anything else, write to us:

HushHush Support: support@thehushhush.com