Legal
Privacy Policy
How Gryt handles your data on the services we run, and what stays on a server we have nothing to do with.
This Privacy Policy describes how Gryt Chat ("we", "us", "our") handles data when you use the services we operate:
- app.gryt.chat, the Gryt web client
- auth.gryt.chat, our authentication service
- id.gryt.chat, our identity certificate service
- community.gryt.chat, the Gryt server we run
Gryt servers: Gryt is designed for self-hosted and third-party servers. When you connect to one, that server is run by its own operator, who controls how your data is processed and stored. Contact that operator for their privacy practices. This policy does not cover them.
community.gryt.chat is the exception: we run it, so this policy covers it. What that server stores is what any Gryt server stores — your membership and role, your nickname and avatar, the messages you send, and any files you upload. Messages and uploads are kept until you or a moderator delete them; we do not expire them on a schedule.
What we can and cannot read there. Messages in channels are not encrypted, and we can read them. Direct messages sent by a client that supports encryption are end-to-end encrypted and we cannot read their contents — but we can still see who is talking to whom and when, that a file was sent, and how large it is. An older client that does not support encryption sends a direct message we can read. If that matters to you, check that your client is up to date.
Server logs on community.gryt.chat do not record IP addresses. A log line that has to tell two callers apart — a rate-limit ban, a client connecting, a client dropping — carries a short label worked out from the address instead. The key that produces it is random, generated when the server starts and never written down. The same address gets the same label for as long as that process runs, and a different one after a restart. The address itself is never written, and none is stored in the database.
Those logs have a ceiling. Each service on that machine keeps at most three log files of 20 MB, and the oldest is deleted when a new one starts. That is a limit on size, not on time, so we cannot promise a number of days: a quiet week stays on disk longer than a busy one. What we can say is that the logs roll over on their own, rather than building up for as long as the server has been running.
What we collect
Account data
When you create an account or sign in through auth.gryt.chat, we process:
- Email address
- Password (hashed, never stored in plain text)
- Account metadata needed for authentication (internal identifiers, email verification status)
Identity certificates
When you sign in, the Gryt client generates a cryptographic keypair on your device and sends the public key to id.gryt.chat along with your authentication token. The identity service verifies your token, issues a short-lived certificate binding your identity to that key, and returns it. No user data is stored by this service. It processes your public key and identity claims only for the duration of the request.
Bug reports and feedback
When you send a bug report or feedback from inside a Gryt app, it goes to reports.gryt.chat, which we run. The report holds what you wrote and any contact details you chose to give. We also record the app version and build, an install id, your platform, operating system version and device model, and your user-agent. The install id is a number the app made up about itself the first time it ran. Nothing outside our database can turn it into a name or an address, but it does link your reports to each other, which is how we tell that this one and last week's came from the same copy of the app.
Your IP address and, if you signed the report, your identity key are recorded too, and both are deleted after two days. They are there to stop one person filling the inbox with junk, which happens within a day if it happens at all. The report stays; the part that says where it came from does not.
Two other places hold an address for a little longer. A rate counter keeps one for a day, and if somebody is blocked from sending reports, the block holds the address it applies to for as long as it lasts, which is a week by default. Neither is attached to anything you wrote.
If you would rather send none of this, email sivert@gryt.chat instead of using the form.
Operational logs
Like most web services, our web servers may record minimal operational data for security and reliability, for example IP addresses, user-agent strings, and request timestamps. The chat server on community.gryt.chat is the exception described above, since it writes a label rather than an address.
Our login service at auth.gryt.chat also records failed sign-in attempts, along with the IP address each one came from. We keep these so we can tell an account locking itself out from someone working through a list of passwords. Successful sign-ins are not recorded this way, and failed ones are deleted after 30 days.
Cloudflare
Everything we run on gryt.chat sits behind Cloudflare: the websites, the web client, and the login, bug report and chat servers. Every request goes through Cloudflare first, which is how those services are kept fast and protected from attacks. To do that, Cloudflare handles your IP address and the other details a browser or app sends with a request. What Cloudflare does with them is covered by its privacy policy.
We also use Cloudflare Web Analytics to see how the sites are doing. It runs on most of our web pages, including gryt.chat, docs.gryt.chat and the web client at app.gryt.chat. It counts page views and records which page was viewed, the site that linked to it, the browser, operating system and type of device, the country, and how quickly the page loaded. We see totals, not individual visitors. Cloudflare says it uses no cookies or local storage for this, and doesn't fingerprint visitors by IP address or user agent. It keeps the full data for a week and a sample of about a tenth after that, and we can look back six months.
We don't use any other analytics, and nothing on our pages tracks you across other sites. The Gryt apps for desktop, Android and iOS don't include Web Analytics.
What we do not collect
The web client at app.gryt.chat does not send your messages, files, voice data, or server profiles to us. All chat content flows directly between your device and the Gryt server you connect to.
Data on your device
The Gryt client stores data locally in your browser to keep you signed in and remember your preferences, for example authentication tokens, a cryptographic identity keypair used for server verification, identity certificates, and UI settings. Your private key never leaves your device. This data stays on your device and is not sent to us.
Data on servers you connect to
When you use a Gryt server, the server operator, not Gryt Chat, stores and controls the data you send, which typically includes:
- Profile information (nickname, avatar)
- Messages, reactions, and file uploads
- Server membership and roles
Voice and video streams may be routed through a media relay operated by the server operator. The server operator's own policies govern how this data is retained and used.
Data retention
- Account data is retained for as long as your account exists.
- Operational logs are kept for security and reliability. On community.gryt.chat they are capped by size and roll over, as described above. On other servers, the operator decides.
- Failed sign-in records on auth.gryt.chat are deleted after 30 days.
- Bug reports are kept until we delete them. The IP address and identity key on one are deleted after two days; the rest of the report has no schedule.
- Server data is retained according to the policies of each server operator.
Deleting your account
This applies to the Gryt account you sign in with, on the Gryt Chat apps for Android, iOS, desktop and the web.
To delete it, email sivert@gryt.chat from the address the account uses, and ask for the account to be deleted. There is no self-service button for this yet. We will confirm by reply once it is done.
What deleting the account removes. The account itself and everything held with it on auth.gryt.chat — your email address, your display name, and your sign-in credentials — along with any identity certificates issued to it by id.gryt.chat. These are removed within 30 days of the request.
What it does not remove. Messages, files, and profile information you sent to a Gryt server are held by that server, and those servers are run by other people rather than by us. Deleting your Gryt account does not reach them. You can delete your own messages in the app, and for the rest you have to ask that server's operator. Operational logs, which hold request timestamps and the labels described above rather than anything you wrote, are kept until they roll over as described under Data retention. A bug report you sent is separate. The address on it is gone after two days either way, and we will delete the rest of it on request.
You do not need an account to use Gryt. If you never made one, there is nothing here to delete: the identity you join servers with is a key held on your own device, and uninstalling the app — or clearing its data from your system settings — removes it.
Your rights and choices
- Local data: clear your browser storage, or the app's data from your device settings, at any time to remove tokens, keys and preferences.
- Server data: contact the server operator to request access to or deletion of data stored on their server.
- Account data: contact us to request information about your authentication account, or see Deleting your account above to have it removed.
Contact
If you have questions or requests, reach out at sivert@gryt.chat.