Privacy policy: Shoal Messages and Shoal Push (hosted service)

Draft. This document has not completed legal review and is not yet in force.

Written by engineering from data-flow.md so that counsel starts from an accurate description of the system. Every item marked [LEGAL] needs a decision by counsel; every is a fact to confirm before publication. Company details are placeholders until the company exists.

Last updated: [date]. Version: draft 0.1 (30 September 2026).

Who we are

[Owner's name and postal address], an individual trading as Shipwright in Ireland ("we"). We are the controller for the personal data described here, except payment data, which our merchant of record processes as [controller / processor] [LEGAL]. Contact: privacy@[domain]. [Data protection officer or representative, if required [LEGAL].]

What this policy covers

The hosted Shoal Messages service (a Matrix account on our homeserver, our Signal and Telegram bridges) and Shoal Push (our push server). It does not cover the Signal or Telegram services themselves, other Matrix servers you talk to, or the apps on your phone, which keep their data on your device.

The short version

What we process, why, and for how long

DataPurposeLegal basis [LEGAL]Retention
Account: Matrix id, password (hashed), display name, avatarProvide the accountContract (Art. 6(1)(b) GDPR)Until you cancel, then erased (see "When you leave")
Licence id and subscription status (plan, expiry)Check you have a subscription; link it to your accountContractLife of the licence, plus [period] for accounting [LEGAL]
Encrypted messages and files, with sender, room and timeDeliver and sync your messages across your devicesContract30 days by default; you or room admins can choose 1 to 90 days per room. Files: 30 days after last access
Room details (names, members, avatars), including names and pictures of your Signal and Telegram contacts and groups as shown in bridged chatsShow your chatsContractWhile the room exists; deleted when you unlink the bridge or leave
Your Signal or Telegram session (linked-device keys or login session) and the contact and group identifiers those services send to any clientKeep your bridged chats connectedContractUntil you unlink, cancel, or the remote service ends the session
Bridged message content, in memory only, while relayingRelay messages between Signal/Telegram and MatrixContractNot stored in readable form
Device IP address and app versionSecurity and abuse preventionLegitimate interests (Art. 6(1)(f))3 days
Push notifications (which room and event, unread count; never message text)Wake your phoneContractDelivered immediately; if your phone is offline, kept up to 12 hours
Error logs (may contain your Matrix id or a room id)Operate and fix the serviceLegitimate interestsA few days, overwritten automatically
Backups of all the aboveRecover from failureLegitimate interests7 days, encrypted
Reports you send us about abuse, and our handling of themHandle abuseLegitimate interests; legal obligation where applicable[period] [LEGAL]

We do not use your data for advertising, profiling or training AI models, and we do not sell it.

Where your data goes

Security

Encryption in transit (TLS) everywhere; end-to-end encryption for Matrix chats; end-to-bridge encryption so our database and backups hold bridged chats encrypted; separate databases per component; no request logging; encrypted backups; access to production limited to [named roles]. The system is described in our published data-flow diagram [link].

When you leave

When your subscription ends, you get a grace period of [7] days. After that your account is suspended (you can still read and export, but not send), and if you do not renew, or if you ask us, we: log out your Signal and Telegram sessions (they disappear from your linked devices), delete your bridged chats, delete your push registration, delete files you uploaded, and deactivate and erase your account. Backups containing your data expire within 7 days after that. Messages you sent to other people remain in their copies of the conversation, as with any messaging service.

Your rights

You can ask for access to, correction, erasure, restriction or portability of your personal data, and object to processing based on legitimate interests, by writing to privacy@[domain]. You can complain to the Data Protection Commission (Ireland) or your local supervisory authority [LEGAL] wording and response times.

Self-hosting

If you prefer not to trust our server, the same software can be run on your own server before publishing that the self-hosting guide exists.

Changes

We will announce material changes in the app and by e-mail [30] days before they take effect.

Source: services/privacy/privacy-policy-DRAFT.md in the Shipwright repository; paths and ADR numbers in the text refer to it.