Privacy policy: Shoal Messages and Shoal Push (hosted service)
Draft. This document has not completed legal review and is not yet in force.
Written by engineering from
data-flow.mdso that counsel starts from an accurate description of the system. Every item marked [LEGAL] needs a decision by counsel; every is a fact to confirm before publication. Company details are placeholders until the company exists.
Last updated: [date]. Version: draft 0.1 (30 September 2026).
Who we are
[Owner's name and postal address], an individual trading as Shipwright in Ireland ("we"). We are the controller for the personal data described here, except payment data, which our merchant of record processes as [controller / processor] [LEGAL]. Contact: privacy@[domain]. [Data protection officer or representative, if required [LEGAL].]
What this policy covers
The hosted Shoal Messages service (a Matrix account on our homeserver, our Signal and Telegram bridges) and Shoal Push (our push server). It does not cover the Signal or Telegram services themselves, other Matrix servers you talk to, or the apps on your phone, which keep their data on your device.
The short version
- Messages between Matrix users in encrypted chats are end-to-end encrypted. We cannot read them.
- Chats you bridge from Signal or Telegram are different. To connect them to Matrix, our bridge has to decrypt and re-encrypt each message, so the bridge software on our server handles those messages unencrypted while passing them on. We do not store their content in readable form and we do not look at it, but the protection is our technical and organisational measures, not end-to-end encryption. If that is not acceptable for a chat, use the official Signal or Telegram app for it.
- We keep as little as the service needs, for as short as we can: messages on our server for 30 days by default, IP addresses for 3 days, undelivered push notifications for 12 hours.
- Everything runs on servers in the EU.
What we process, why, and for how long
| Data | Purpose | Legal basis [LEGAL] | Retention |
|---|---|---|---|
| Account: Matrix id, password (hashed), display name, avatar | Provide the account | Contract (Art. 6(1)(b) GDPR) | Until you cancel, then erased (see "When you leave") |
| Licence id and subscription status (plan, expiry) | Check you have a subscription; link it to your account | Contract | Life of the licence, plus [period] for accounting [LEGAL] |
| Encrypted messages and files, with sender, room and time | Deliver and sync your messages across your devices | Contract | 30 days by default; you or room admins can choose 1 to 90 days per room. Files: 30 days after last access |
| Room details (names, members, avatars), including names and pictures of your Signal and Telegram contacts and groups as shown in bridged chats | Show your chats | Contract | While the room exists; deleted when you unlink the bridge or leave |
| Your Signal or Telegram session (linked-device keys or login session) and the contact and group identifiers those services send to any client | Keep your bridged chats connected | Contract | Until you unlink, cancel, or the remote service ends the session |
| Bridged message content, in memory only, while relaying | Relay messages between Signal/Telegram and Matrix | Contract | Not stored in readable form |
| Device IP address and app version | Security and abuse prevention | Legitimate interests (Art. 6(1)(f)) | 3 days |
| Push notifications (which room and event, unread count; never message text) | Wake your phone | Contract | Delivered immediately; if your phone is offline, kept up to 12 hours |
| Error logs (may contain your Matrix id or a room id) | Operate and fix the service | Legitimate interests | A few days, overwritten automatically |
| Backups of all the above | Recover from failure | Legitimate interests | 7 days, encrypted |
| Reports you send us about abuse, and our handling of them | Handle abuse | Legitimate interests; legal obligation where applicable | [period] [LEGAL] |
We do not use your data for advertising, profiling or training AI models, and we do not sell it.
Where your data goes
- Signal and Telegram. When you link an account, our bridge connects to Signal or Telegram as your client, as their own apps do. Their privacy policies govern what they process. Signal Messenger LLC and Telegram are outside the EU entities and transfer mechanisms [LEGAL].
- Other Matrix servers. If you chat with users on other Matrix servers, those rooms are copied to their servers, which set their own retention. Bridged Signal and Telegram chats are never shared with other servers.
- Hosting. [Hetzner Online GmbH, Germany], data centres in Germany and Finland, as our processor under a data processing agreement.
- Payments. [Merchant of record], which handles payment and VAT. We receive only a licence id, plan and paid-until date, not your card details.
- Authorities. Only where the law requires it, after review by counsel. We cannot hand over content of end-to-end encrypted chats because we do not have it.
Security
Encryption in transit (TLS) everywhere; end-to-end encryption for Matrix chats; end-to-bridge encryption so our database and backups hold bridged chats encrypted; separate databases per component; no request logging; encrypted backups; access to production limited to [named roles]. The system is described in our published data-flow diagram [link].
When you leave
When your subscription ends, you get a grace period of [7] days. After that your account is suspended (you can still read and export, but not send), and if you do not renew, or if you ask us, we: log out your Signal and Telegram sessions (they disappear from your linked devices), delete your bridged chats, delete your push registration, delete files you uploaded, and deactivate and erase your account. Backups containing your data expire within 7 days after that. Messages you sent to other people remain in their copies of the conversation, as with any messaging service.
Your rights
You can ask for access to, correction, erasure, restriction or portability of your personal data, and object to processing based on legitimate interests, by writing to privacy@[domain]. You can complain to the Data Protection Commission (Ireland) or your local supervisory authority [LEGAL] wording and response times.
Self-hosting
If you prefer not to trust our server, the same software can be run on your own server before publishing that the self-hosting guide exists.
Changes
We will announce material changes in the app and by e-mail [30] days before they take effect.
Source: services/privacy/privacy-policy-DRAFT.md in the Shipwright repository; paths and ADR numbers in the text refer to it.