-
Notifications
You must be signed in to change notification settings - Fork 390
Update Privacy Policy #2860
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update Privacy Policy #2860
Conversation
Supersedes #2775 Signed-off-by: Thib <[email protected]>
Deploying matrix-website with
|
| Latest commit: |
e2fdf99
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://1dcc33a6.matrix-website.pages.dev |
| Branch Preview URL: | https://update-privacy-policy.matrix-website.pages.dev |
| We collect: | ||
|
|
||
| * Name | ||
| * Pronouns | ||
| * Name | ||
| * Pronouns | ||
| * MatrixID |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
we probably need to reference this in the handbook and consider it when setting up these services
| **Pretalx** – specifically with regards to event speakers, we collect: | ||
|
|
||
| * Profile picture | ||
| * Name | ||
| * Biography | ||
| * Availability | ||
| * MatrixID | ||
| * Fediverse handle | ||
| * LinkedIn profile | ||
| * Twitter handle | ||
| [**Pretalx**](https://pretalx.com/) – specifically with regards to event speakers, we collect: | ||
|
|
||
| * Profile picture | ||
| * Name | ||
| * Biography | ||
| * Availability | ||
| * MatrixID | ||
| * Fediverse handle | ||
| * LinkedIn profile | ||
| * Twitter handle |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
same here
Co-authored-by: Hugh Nimmo-Smith <[email protected]>
| ### 2.4 Transfers of your data | ||
|
|
||
| If you use our Service your data will be transferred outside of the EU to other homeservers and services connected with matrix.org as this is necessary to provide the Service to you. By the very nature of our Service, such transfers will occur regularly and we have no control over the safeguards adopted by third party recipients. | ||
| If you use our Service your data will be transferred outside of the EU to other homeservers and services connected with Matrix.org as this is necessary to provide the Service to you. By the very nature of our Service, such transfers will occur regularly and we have no control over the safeguards adopted by third party recipients. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
matrix.org or Matrix.org?
Signed-off-by: Thib <[email protected]>
Signed-off-by: Thib <[email protected]>
Signed-off-by: Thib <[email protected]>
| If you share information in a room set to world\_readable this might be available to people outside the Matrix ecosystem and indexed by search engines, via projects such as [archive.matrix.org](https://archive.matrix.org). Please ensure that you double check the settings of each room before you participate and always avoid sharing personal and sensitive data in unencrypted rooms. | ||
|
|
||
| In encrypted rooms, the data is stored in our databases but the encryption keys are stored only on your devices or by yourself. Users can optionally backup an encrypted copy of their keys on the Service to aid recovery if they lose all their keys and devices. This key backup is encrypted by a recovery key that only the user has access to. Element (the company, employees, and contractors) are unable to read your message content in our database. If you lose access to your encryption keys, you lose access to your messages forever. | ||
| In encrypted rooms, the data is stored in our databases but the encryption keys are stored only on your devices or by yourself. Users can optionally backup an encrypted copy of their keys on the Service to aid recovery if they lose all their keys and devices. This key backup is encrypted by a recovery key that only the user has access to. [Element](https://element.io) (the company, including its employees and contractors) are unable to read your message content in our database. If you lose access to your encryption keys, you lose access to your messages forever. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
For the next iteration, I suggest to keep the wording more general instead of specific to Element. It's the team running the HS, not Element for the sake of being Element. For comparison: everywhere else it is written "guidelines the Foundation follows when accessing my data" and similar.
| ### 2.10 What are the guidelines the Foundation follows when accessing my data? | ||
|
|
||
| As per 2.11, the Foundation contracts Element to manage the hosting and data management of the homeserver. We restrict who at Element (employees and contractors) can access user data to roles which require access in order to maintain the health of the Service; | ||
| As per 2.11, the Foundation contracts [Element](https://element.io) to manage the hosting and data management of the homeserver. We restrict who at [Element](https://element.io) (employees and contractors) can access user data to roles which require access in order to maintain the health of the Service; |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
per 2.11
it would be feasible to link to headings as appropriate.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
For the next iteration: This sentence implies that Foundation staff does not restrict itself in the same way.
| ### 2.11 Who else has access to my data? | ||
|
|
||
| Element is a Processor of your data, managing the homeserver on behalf of the Matrix.org Foundation. We host the majority of the Service in Mythic Beasts data centres. Here’s Mythic Beast’s [privacy policy](https://www.mythic-beasts.com/terms/privacy). | ||
| [Element](https://element.io) is a Processor of your data, managing the homeserver on behalf of the Foundation. We host the majority of the Service in Mythic Beasts data centres. Here’s Mythic Beast’s [privacy policy](https://www.mythic-beasts.com/terms/privacy). |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
For the next iteration: The implication from the following sentence is: Does Mythic Beasts not control physical access to their data centres?
Signed-off-by: Thib <[email protected]>
46f3953 to
105393a
Compare
Signed-off-by: Thib <[email protected]>
Signed-off-by: Thib <[email protected]>
Signed-off-by: Thib <[email protected]>
Signed-off-by: Thib <[email protected]>
|
imo: |


Supersedes #2775
🎩 Website WG on behalf of the legal team
✔️ Checklist
<>to linkify them (learn more).[label](@/target.md)syntax./blogpage, especially for multiple posts on the same day. Prefer UTC format, e.g.2025-12-01T14:00:00Zfor Dec 1st, 2025, 2pm UTC.This PR should be merged today