Last updated: 5 August 2026
This policy applies to the Reckfell deployment that links to this page. The data controller is the Operator identified in the Imprint. Self-hosted deployments have independent operators and privacy practices.
Data we process
- Account data: user ID, username, display name, email address when enabled, password hash, authentication factors, recovery and session metadata.
- Content and social data: messages, reactions, communities, channels, roles, contacts, moderation reports, bot interactions, and settings.
- Media: files, images, audio, video, thumbnails, metadata, and temporary conversion artefacts. Media may be compressed, converted, scanned, encrypted, cached, or deduplicated as configured by the Operator.
- Voice and video: room membership, call signalling, quality statistics, and network metadata. Audio, video, and screen-share streams are relayed for the call and are not recorded unless a clearly disclosed recording feature is enabled.
- Technical and security data: IP address, user agent, timestamps, request and audit logs, device and push tokens, rate-limit events, and abuse indicators.
- Support data: tickets, feedback, attachments, and correspondence you submit.
Why we process it
Data is processed to provide the service, authenticate users, deliver messages and calls, process media, synchronise clients, operate discovery and bots, prevent abuse, respond to support requests, maintain backups, and comply with law. The legal basis depends on the Operator’s jurisdiction and may include performance of a contract, legitimate interests, consent, and legal obligations.
Storage and recipients
The default self-hosted stack stores application data in MongoDB, transient state and queues in Redis-compatible and message-broker services, and media in S3-compatible object storage. LiveKit relays real-time media. Support, email, push, identity, monitoring, and backup providers are optional and must be listed by the Operator before production use.
Data is disclosed only to authorised operators and processors, to other users as required by the feature you choose, or where legally required. Public discovery entries and public profile fields are intentionally visible to visitors.
Retention
Account content remains until deleted by a user, moderator, retention policy, or the Operator. Security and audit logs are kept only as long as needed for security and legal obligations. Deleted data may remain in encrypted backups until the backup retention window expires. Temporary upload and conversion artefacts are removed by background jobs.
Your choices and rights
You can edit profile data and delete eligible content in the app. Depending on applicable law, you may request access, correction, export, restriction, objection, or deletion through Support. The Operator may need to verify your identity and may retain data where law or legitimate security needs require it.
Security
Reckfell supports encrypted transport, hashed passwords, scoped permissions, rate limits, audit logging, isolated workers, and encrypted object storage where configured. No system can guarantee absolute security; report suspected issues at the security contact.
Changes and contact
Material changes will be announced through the service. Privacy questions and rights requests can be submitted at Support.