Privacy Policy
Matrix chat service · derfel.dev · Last updated 17 September 2026
derfel.dev's
Matrix service actually handles data — written by the person who runs it, not by a
lawyer. It is not a substitute for legal advice. If you need a legally binding privacy
notice for compliance purposes, have it reviewed by a qualified lawyer before relying
on it.
1. Who runs this service
The Matrix homeserver at derfel.dev (server name matrix.derfel.dev)
is operated by Pavel Dimov as an individual — this is a personal project, not a
registered company. Contact for anything in this policy: @pavel:derfel.dev
on Matrix, or [email protected] by email.
2. What this covers
This policy covers the derfel.dev / matrix.derfel.dev
homeserver and the chat.dimov.xyz web client (a branded deployment of
Element Web) used to access it. It does not cover third-party Matrix clients you may
choose to use instead, or the platforms reached through bridges (see section 6) —
those are covered by their own privacy policies.
3. Who can use it, and how you sign in
Public self-registration is closed — there is no sign-up form. Access is granted
through Google Workspace single sign-on for the dimov.xyz Workspace
organization. If you have an account, it's because it was set up for you as part of
that organization.
4. What data we process
Running a Matrix homeserver necessarily involves processing:
- Account identifiers — your Matrix ID, display name, avatar, and the Workspace identity your login is linked to
- The content and metadata of messages in rooms you're a member of, for as long as you're a member of them
- Device and session information, including end-to-end encryption key material needed for encrypted rooms to work
- Media you upload or that's sent to rooms you're in
- Standard server logs (connection metadata, error logs) kept for operational troubleshooting
5. Federation — talking to people on other servers
Federation is enabled on this homeserver. Matrix is a decentralized protocol: if you're in a room with someone on a different homeserver, or you message them directly, your messages, profile information, and any shared media are sent to and stored by their homeserver as well as ours — not just to make delivery possible, but for as long as that server chooses to keep them.
We have no control over how another homeserver stores, retains, or otherwise handles data once it's been federated to it. If privacy from a specific counterpart matters to you, keep in mind that federated conversations are, in a real sense, held on infrastructure we don't operate and can't erase data from on your behalf.
6. Bridges — talking to people on other platforms
This server runs bridges connecting Matrix rooms to a number of third-party chat platforms. If you use a bridged room or DM, your messages and media are relayed through — and processed by — that platform's own infrastructure, under its own terms and privacy policy. We only control what happens on the Matrix side; the moment a message crosses a bridge, the other platform's rules apply to that copy of it.
| Platform | Bridge | Their privacy policy |
|---|---|---|
| Telegram | mautrix-telegram | telegram.org/privacy |
mautrix-whatsapp | whatsapp.com/legal/privacy-policy | |
| Signal | mautrix-signal | signal.org/legal |
| Discord | mautrix-discord | discord.com/privacy |
| Slack | mautrix-slack | slack.com/trust/privacy-policy |
| Twitter / X | mautrix-twitter | x.com/en/privacy |
mautrix-linkedin | linkedin.com/legal/privacy-policy | |
| Google Chat | mautrix-googlechat | policies.google.com/privacy |
| Google Voice | mautrix-gvoice | policies.google.com/privacy |
| Bluesky | mautrix-bluesky | bsky.social/support/privacy-policy |
| Messenger (Meta) | mautrix-meta-messenger | facebook.com/privacy/policy |
| Instagram (Meta) | mautrix-meta-instagram | privacycenter.instagram.com/policy |
7. How long we keep data
These are the actual retention settings configured on this server:
| Data | Retention |
|---|---|
| Room messages, in general | Not automatically deleted — chat history is kept intentionally, indefinitely, unless you or an admin removes it |
| Redacted (deleted) message content | Purged permanently 7 days after redaction |
| Rooms you've left and forgotten | Removed from the database after 28 days |
| Local media, including files sent through bridges | 120 days |
| Remote / federated media cache | 30 days — this is only our local cached copy; the original file remains on the sending server, outside our control |
8. Security
End-to-end encryption is available and supported for rooms that use it, in line with standard Matrix/Element functionality. Traffic to and from the server is encrypted in transit (TLS). As with any single-operator service, treat this as a reasonably but not exhaustively secured personal infrastructure project rather than an audited enterprise platform.
9. Your rights, and how to exercise them
You can ask to have your account deactivated and your data erased at any time — this
is a real, working procedure on this server, not a formality. Contact
@pavel:derfel.dev or [email protected]
to request it. Because this is a one-person operation, requests for access,
correction, or erasure are handled directly and personally rather than through a
formal privacy team — expect a direct reply, not a ticketing system.
Erasure of your account and local data does not retroactively remove copies that federation or bridges have already sent to other servers or platforms (see sections 5 and 6) — those need to be requested from the party that holds them.
10. Changes to this policy
If the server's configuration changes in a way that affects this policy — different retention periods, new or removed bridges, federation being disabled — this page will be updated to reflect the actual, current setup. Check the "last updated" date above.
11. Contact
@pavel:derfel.dev (Matrix) · [email protected] (email)