DERFEL

Privacy Policy

Matrix chat service · derfel.dev · Last updated 17 September 2026

This page is a plain-language, factual description of how derfel.dev's Matrix service actually handles data — written by the person who runs it, not by a lawyer. It is not a substitute for legal advice. If you need a legally binding privacy notice for compliance purposes, have it reviewed by a qualified lawyer before relying on it.

1. Who runs this service

The Matrix homeserver at derfel.dev (server name matrix.derfel.dev) is operated by Pavel Dimov as an individual — this is a personal project, not a registered company. Contact for anything in this policy: @pavel:derfel.dev on Matrix, or [email protected] by email.

2. What this covers

This policy covers the derfel.dev / matrix.derfel.dev homeserver and the chat.dimov.xyz web client (a branded deployment of Element Web) used to access it. It does not cover third-party Matrix clients you may choose to use instead, or the platforms reached through bridges (see section 6) — those are covered by their own privacy policies.

3. Who can use it, and how you sign in

Public self-registration is closed — there is no sign-up form. Access is granted through Google Workspace single sign-on for the dimov.xyz Workspace organization. If you have an account, it's because it was set up for you as part of that organization.

4. What data we process

Running a Matrix homeserver necessarily involves processing:

5. Federation — talking to people on other servers

Federation is enabled on this homeserver. Matrix is a decentralized protocol: if you're in a room with someone on a different homeserver, or you message them directly, your messages, profile information, and any shared media are sent to and stored by their homeserver as well as ours — not just to make delivery possible, but for as long as that server chooses to keep them.

We have no control over how another homeserver stores, retains, or otherwise handles data once it's been federated to it. If privacy from a specific counterpart matters to you, keep in mind that federated conversations are, in a real sense, held on infrastructure we don't operate and can't erase data from on your behalf.

6. Bridges — talking to people on other platforms

This server runs bridges connecting Matrix rooms to a number of third-party chat platforms. If you use a bridged room or DM, your messages and media are relayed through — and processed by — that platform's own infrastructure, under its own terms and privacy policy. We only control what happens on the Matrix side; the moment a message crosses a bridge, the other platform's rules apply to that copy of it.

PlatformBridgeTheir privacy policy
Telegrammautrix-telegramtelegram.org/privacy
WhatsAppmautrix-whatsappwhatsapp.com/legal/privacy-policy
Signalmautrix-signalsignal.org/legal
Discordmautrix-discorddiscord.com/privacy
Slackmautrix-slackslack.com/trust/privacy-policy
Twitter / Xmautrix-twitterx.com/en/privacy
LinkedInmautrix-linkedinlinkedin.com/legal/privacy-policy
Google Chatmautrix-googlechatpolicies.google.com/privacy
Google Voicemautrix-gvoicepolicies.google.com/privacy
Blueskymautrix-blueskybsky.social/support/privacy-policy
Messenger (Meta)mautrix-meta-messengerfacebook.com/privacy/policy
Instagram (Meta)mautrix-meta-instagramprivacycenter.instagram.com/policy

7. How long we keep data

These are the actual retention settings configured on this server:

DataRetention
Room messages, in generalNot automatically deleted — chat history is kept intentionally, indefinitely, unless you or an admin removes it
Redacted (deleted) message contentPurged permanently 7 days after redaction
Rooms you've left and forgottenRemoved from the database after 28 days
Local media, including files sent through bridges120 days
Remote / federated media cache30 days — this is only our local cached copy; the original file remains on the sending server, outside our control

8. Security

End-to-end encryption is available and supported for rooms that use it, in line with standard Matrix/Element functionality. Traffic to and from the server is encrypted in transit (TLS). As with any single-operator service, treat this as a reasonably but not exhaustively secured personal infrastructure project rather than an audited enterprise platform.

9. Your rights, and how to exercise them

You can ask to have your account deactivated and your data erased at any time — this is a real, working procedure on this server, not a formality. Contact @pavel:derfel.dev or [email protected] to request it. Because this is a one-person operation, requests for access, correction, or erasure are handled directly and personally rather than through a formal privacy team — expect a direct reply, not a ticketing system.

Erasure of your account and local data does not retroactively remove copies that federation or bridges have already sent to other servers or platforms (see sections 5 and 6) — those need to be requested from the party that holds them.

10. Changes to this policy

If the server's configuration changes in a way that affects this policy — different retention periods, new or removed bridges, federation being disabled — this page will be updated to reflect the actual, current setup. Check the "last updated" date above.

11. Contact

@pavel:derfel.dev (Matrix) · [email protected] (email)

See also: Terms of Service