NOSTR MAGAZINE

Nostr's Data Sovereignty Crisis: ''We'll Spaff Your Notes Everywhere''

The Catalyst: A Protocol Promise Broken

Nostr’s original pitch was simple and seductive. You choose which relays publish your notes. You control your data. If a relay censors you, you move to another one. The protocol’s architecture made this possible because relays were interchangeable and clients respected your relay preferences.

The outbox model changed that. Under this architecture, clients automatically broadcast your notes to multiple relays based on where your followers are, not where you want to publish. The goal is better reach and censorship resistance. The effect, critics argue, is that users lose meaningful control over where their data lives.

The Stacker News post laid out the consequences in stark terms. For users who specified only one or two relays, there’s now no reliable way to delete published content. Data protection regulations may not apply. Direct messages may have been propagated across the network, making them vulnerable to harvest-now-decrypt-later attacks. The author asked the question that’s now echoing across Nostr’s developer channels: “Is there any way to leave Nostr???”


The Trade-Off Nobody Wants to Name

Pamplona has defended the outbox model on technical grounds. In my experience covering protocol development, this is the classic decentralization dilemma dressed in new clothes. You can have user sovereignty or you can have network efficiency. You can’t have both at scale.

The outbox model solves real problems. Nostr’s relay fragmentation was making the network feel broken. Notes weren’t loading. Conversations were missing replies. Users were blaming clients when the architecture was the culprit. Automatic propagation fixes that.

But it fixes it by making a choice on the user’s behalf. And that’s what’s ignited this controversy. Nostr’s entire value proposition rests on the idea that users, not developers, make these decisions. When a prominent developer says he doesn’t care what users think, even if that’s a paraphrase of a more nuanced position, it strikes at the heart of the protocol’s social contract.


The Privacy Win That’s Being Buried

Here’s what’s getting lost in the outrage. On September 3, 2026, NIP-78 was updated to require AUTH for kind 30078 events, which store personal app settings. This means relays must authenticate users before accepting or returning their data. Alex Gleason called it a “big privacy win for Nostr”.

The NIP-78 change shows that Nostr’s development process can still deliver meaningful privacy improvements. The question is whether these wins matter when the broader architectural direction feels like it’s moving in the opposite direction.


What the Community Is Saying

The responses to the Stacker News post reveal a community deeply split. Some defend the outbox model as necessary pragmatism. Others see it as a betrayal of Nostr’s founding principles.

One commenter cut to the heart of the matter: “I understood the nature of nostr to be public forever. I was surprised when people claimed to roll out an option to delete a nostr note. It is not possible. Nostr is public and permanent as far as I can tell”.

That’s the uncomfortable truth. Nostr was never designed to let you take things back. The protocol’s censorship resistance comes from replication, and replication means your notes live everywhere. The outbox model just makes that replication automatic and invisible.


The Real Question

The data propagation fight isn’t really about the outbox model. It’s about whether Nostr’s developers can be trusted to make architectural decisions that prioritize user agency over network performance. The protocol has no governance mechanism to force that trust. It relies entirely on social pressure and the threat of client forks.

I think this moment matters because it forces Nostr to confront something it’s avoided since fiatjaf wrote the first spec. Decentralization isn’t a binary. It’s a spectrum of trade-offs. The outbox model moves Nostr toward efficiency and away from sovereignty. Whether that’s the right call depends on what you think Nostr is for.

If it’s for building a usable social network, the outbox model is probably necessary. If it’s for giving users genuine control over their digital presence, it’s probably a mistake. The community needs to decide. And it needs to decide publicly, before another developer declares that user opinions don’t matter.


Summary

A September 12 Stacker News post accused Vitor Pamplona, Nostr’s “Chief Android Officer,” of declaring that client developers will propagate user notes everywhere without permission. The controversy centers on the outbox model, which improves network reliability by automatically broadcasting notes to multiple relays. Critics say it violates Nostr’s core promise of user-controlled data sovereignty. The debate reflects a broader tension between protocol pragmatism and decentralization ideals. Meanwhile, a recent NIP-78 privacy upgrade shows the development process can still deliver wins. The outcome will shape whether Nostr remains a user-sovereign protocol or evolves into something more efficient, and less controllable.

Comments