Privacy Policy
Last updated: 11 June 2026
This policy describes how MatrixMedia, published by Steegler, handles your data. It is written in plain English. If anything below is unclear, email support@steegler.com and we will explain.
The short version
- We do not sell your data.
- We do not run advertising or analytics tracking.
- Messages, voice and video calls, and live broadcasts are end-to-end encrypted by default. Our servers cannot read their contents.
- You can delete your account at any time.
Who we are
Steegler operates the hosted homeserver at matrix.steegler.com and publishes the MatrixMedia iOS and Android apps. MatrixMedia is open source (Apache-2.0) and built on the Matrix protocol — a federated, open standard for real-time communication.
You can also use MatrixMedia against any other Matrix homeserver (your own self-hosted server, or any public one). When you do, that homeserver's operator becomes your data controller for the data they hold; this policy then only covers what the app itself does on your device.
What we collect when you use matrix.steegler.com
Account information
When you sign up, you choose a username. That username, plus a password hash, is stored so you can log in again. We do not require an email address or phone number.
Messages and media
Direct messages and group rooms are encrypted end-to-end between participating devices. The homeserver stores the encrypted blobs and routes them to the right devices; it cannot read the plaintext. The same applies to media you upload (images, files) — they are encrypted before they leave your device.
Calls and live broadcasts
Voice, video, and broadcast media are streamed through a media server (LiveKit) hosted by Steegler. Audio and video frames are encrypted between participating devices; the media server forwards encrypted frames without decrypting them.
Server-side metadata
Like every messaging service, the homeserver has to know who is in which room in order to deliver events to the right people. So it stores: room membership lists, room state events (such as a room name or topic that you have explicitly published), timestamps of events, and the IP address that contacted the server. This kind of metadata is inherent to a federated chat system and is what allows it to work; we minimise it where we can.
Abuse-defense data at sign-up
When you create an account, we record a one-way hashed form of your IP address together with the timestamp and the username chosen. This lets us defend against bulk-signup abuse without storing the raw IP. The hash uses a server-side secret and cannot be reversed.
Push notification tokens
If you allow notifications, your device gives us an opaque token from Apple (APNs) or Google (Firebase Cloud Messaging). We send it, with the event identifier of new messages, to Apple/Google so they can wake your device. The notification body that the app finally shows is decrypted on your device, not on our server.
What we do NOT do
- We do not embed third-party analytics SDKs (no Google Analytics, no Mixpanel, no AppsFlyer, or equivalent).
- We do not embed advertising SDKs.
- We do not link your account to advertising identifiers (IDFA, GAID) or any cross-app tracking system.
- We do not sell, rent, or share your data with data brokers.
- We do not read your messages, listen to your calls, or watch your broadcasts. The encryption keys never leave your devices.
Third parties involved when you use the apps
- Apple — for iOS app distribution and APNs push notifications. Apple's privacy policy: apple.com/legal/privacy/.
- Google — for Android app distribution (Play Store) and Firebase Cloud Messaging (FCM) push delivery. Google's privacy policy: policies.google.com/privacy.
- LiveKit — software we run on our own servers to forward encrypted call and broadcast media. The instance runs under our control at
livekit.steegler.comand sees encrypted media frames only. - Other Matrix homeservers — when you communicate with someone on a different homeserver, that homeserver and yours exchange encrypted events to deliver the conversation. Each homeserver only sees the metadata it needs to route events.
How long we keep your data
- Demo server resets: data on the demo server may be cleared during routine resets, independently of the periods below.
- Account data and rooms: retained while your account is active.
- Sign-up audit records: up to 12 months, then deleted.
- Server access logs: up to 30 days, then deleted.
- Push notification tokens: deleted when you sign out, or after a period of inactivity.
- Account deletion: when you delete your account, your profile is removed and your encrypted message blobs are dereferenced. Note that messages already delivered to other people's devices remain on their devices — that is how end-to-end encryption works.
Your rights
Under GDPR and similar laws elsewhere, you have the right to access, correct, export, and delete your personal data. You can also object to processing and lodge a complaint with a data protection authority.
To exercise any of these rights, email support@steegler.com from the account associated with your username, or open an in-app request via Settings → Help → Contact Support. We aim to respond within 30 days.
Children
MatrixMedia is not directed at children under 13 (or under 16 in the EU, where local law sets a higher digital-consent threshold). We do not knowingly collect personal data from such users. If you believe a child has signed up without parental consent, email support@steegler.com and we will remove the account.
Changes to this policy
If we change this policy in a way that affects how we handle your data, we will update the "Last updated" date at the top and post a notice in the app for at least 30 days before the change takes effect. Material changes will be highlighted, not buried.
Contact
Questions, privacy requests, or anything else: support@steegler.com