Privacy policy
This is a translation for convenience. The German version (Datenschutzerklärung) is the binding one.
This policy describes which personal data is processed when you visit the website squorli.com, use the Squorli Directory service and interact with the Squorli Server repository. It is derived from what the software actually does: there are no sections for services that are not used.
1. Controller
Daniel Klessa
c/o flexdienst – #22209
Kurt-Schumacher-Straße 74
67663 Kaiserslautern
Germany
E-mail: daniel@squorli.com
No data protection officer has been appointed; that is not required for a private project of this size.
2. Website squorli.com
2.1 Hosting and server logs
The website consists of static files served from a cloud server of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, located in Falkenstein, Germany. When you open a page, the web server necessarily processes the IP address of your device, date and time, the requested address, the status returned and your browser (user agent) in order to deliver the page. Requests are not logged; only errors of the web server are recorded with these details, to detect faults and fend off attacks. Those entries are not combined with other data and are deleted after 14 days at the latest.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, working service). A data processing agreement under Art. 28 GDPR is in place with Hetzner.
2.2 No cookies, no analytics, no external resources
The website sets no cookies, uses no local storage, no audience measurement, no tracking, and loads no fonts, scripts or content from third-party servers. A consent banner is therefore not required. The site’s two own scripts only drive the menu, the clipboard, the image lightbox and the marking of the download for your operating system; for that they read your browser locally without transmitting anything.
Links to GitHub and to the Squorli Directory transmit data to their target only when you click them.
2.3 Update checks of the desktop app
The installed Squorli desktop app asks https://squorli.com/updates/stable/ at start and every six hours afterwards whether a new version exists. The web server then receives the IP address, the update module’s identifier (user agent) and the installed version; section 2.1 applies. The app then downloads the actual installation files from GitHub (section 5). No identifier of your device or your account is transmitted.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in supplying installed apps with security and bug fixes).
3. Squorli Directory (directory.squorli.com)
Squorli Directory is the account service for Squorli chat servers: it assigns handles (@name), keeps the private key backed up under password encryption, manages the second factor, friends and end-to-end encrypted direct messages. An account is optional; chat servers can also be used without one if their operators allow it.
The service runs in containers on a virtual server of Strato GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. The database lives only on that server. A data processing agreement under Art. 28 GDPR is in place with Strato.
3.1 Account
When you create an account your browser generates a key pair. The service stores:
- the handle, the public key, the time of creation and of last use;
- the backup of your private key, encrypted by your browser with your password, plus a hash of the access key derived from it. The password itself and the private key never leave your browser in plain text; the operator cannot open the backup and cannot reset a forgotten password;
- optionally a display name (global and per chat server), a profile picture and the settings of your chat app. Recent apps encrypt the settings with a key derived from your account before they arrive; only you can read them. Settings an older app stored in plain text stay readable until a newer app encrypts them;
- optionally the secret of an authenticator (encrypted with a server key held by the operator) and hashes of the recovery codes;
- optionally your e-mail address, if you store one or the service requires it, with the time of confirmation. An address belongs to at most one account;
- the list of chat servers you signed in on with the account, with timestamps;
- the list of your signed-in devices. Every app and every browser you sign in with makes a device key of its own; the service stores its public half, a device label from the browser or the app (for example “Chrome on Windows”), the website the device was signed in through (for the desktop app only that it was the app), the times of the sign-in and of the last use and, for a device that was signed out, the time and the occasion of that. This lets you sign single devices out, and a device that was signed out gets back into your account only with password and second factor;
- a history of retrievals of your key backup (time, device label from the browser or the app, calling website or desktop app, factor used) so you can spot retrievals that were not yours.
Handle, public key and profile picture are public: anyone can look up a handle and fetch the picture so that chat servers and other members recognise you. Display names are given only to the chat server on which you use them. The e-mail address is not passed on.
Purpose: providing the account, restoring it on other devices, protection against account takeover. Legal basis: Art. 6(1)(b) GDPR (the usage relationship). The retrieval history, the device list and the server list additionally serve security, Art. 6(1)(f) GDPR.
Retention: until the account is deleted; the retrieval history 90 days. A device that was not used for 90 days is signed out (not for an account without a password); the entry of a device that was signed out is deleted one year later. A sign-in on the account page ends after 12 hours, with “remember for 30 days” after 30 days.
3.2 Friends, direct messages and presence
- Friend requests and friendships are stored as long as they exist; a declined request is kept for seven days as a block against an immediate repeat.
- Direct messages between friends are end-to-end encrypted by the chat app. The service stores only the encrypted content plus sender, recipient, time and size, in order to deliver the message. Nobody but the two participants can read it. Preview pictures of links in direct messages are likewise stored encrypted only. Messages and preview pictures are deleted after 180 days, earlier if both sides delete them.
- While your chat app is connected to the service, your friends see whether you are online or away and, if you switched the game display on, which game is running. This is only forwarded, never stored. Which games you never show is kept encrypted in your settings.
Purpose and legal basis: providing these functions, Art. 6(1)(b) GDPR.
3.3 E-mail
If you stored an e-mail address, the service sends you confirmation codes, a notice on every retrieval of your key backup and, on request, a code as a substitute for the authenticator. Mail is sent through a mail server set up by the operator; the operator of that mail server receives your address and the content of the message (handle, code or notice). Legal basis: Art. 6(1)(b) GDPR.
3.4 Chat servers as recipients
Chat servers registered with the Directory look up your handle, display name and profile picture when you sign in; this tells the service which server you signed in on (section 3.1). The service passes your public key to a chat server only when you ask it to delete your account there, or when your name, your picture or your signed-in devices change. To a chat server you are signed in on with the account, or are signing in on at that moment, the service also names the public keys of your signed-in devices, so that the server can refuse a device that was signed out; it does not get the devices’ labels and times. The operator of a chat server is responsible for the processing on that server (section 4).
3.5 Technical data, logs and abuse protection
The service logs every request with IP address, time, method and address, and failed sign-in attempts with IP address. The logs serve operation, troubleshooting and the defence against attacks and are deleted after 14 days at the latest. To protect against abuse the service limits the number of registrations, password attempts and actions per IP address; these counters exist only in memory and are discarded after one minute. For the operator’s statistics the service counts every five minutes how many accounts are online, away and known in total, without reference to individual accounts.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure operation).
The service’s TLS certificate is issued by Let’s Encrypt (Internet Security Research Group, USA); only the domain name and the server address are transmitted for that, no user data.
3.6 Looking up links and games
- When you send a link in a direct message from a browser, the service fetches the linked page on your behalf to produce title, description and preview picture; the linked site sees the service’s address, not yours. For YouTube links the service asks YouTube’s (Google’s) oEmbed interface for the title. The service stores and logs nothing about the link. The desktop app fetches linked pages itself.
- For the game display the service knows names and icons of games; unknown ids are looked up in the catalogues of Steam (Valve), Microsoft Store and GOG. Only the game id is transmitted, nothing about you; the service does not remember who asked. When your app fetches a game icon, the service sees your IP address and the game id.
Legal basis: Art. 6(1)(b) GDPR.
3.7 Storage in your browser
The account page sets no cookies. If you choose “remember for 30 days” at sign-in, the page stores your key in your browser’s local storage and the device’s key in the browser’s database (IndexedDB), where it cannot be read out; “sign out” removes both and signs the device out at the service. The page also remembers the chosen language. Both are technically necessary for the chosen function and need no consent.
3.8 Deleting the account
You can delete your account yourself at any time on the account page under “Delete account”. This removes handle, key backup, authenticator, e-mail address, profile picture, display names, settings, friendships, direct messages with preview pictures, the server list, the device list and the retrieval history; the handle becomes free again. Chat servers you signed in on with the account are asked to delete your account there; a server that is unreachable at that moment catches up at its next reconciliation. Only a chat server whose first owner you are keeps your account. The request to a chat server is kept until that server confirms it; the server logs remain until their retention expires (section 3.5).
4. Chat servers and the Squorli Server software
Squorli Server is open-source software that anyone can run. A chat server processes messages, attachments, memberships and voice and video connections of its members; the person running the server is responsible for that, not the controller of this policy. Channel messages and attachments on a chat server are not end-to-end encrypted and are readable by its operator; voice and video pass through the media server of that chat server. Ask the server you join.
The chat app (in the browser or as the desktop app) connects to the chosen chat server, to the Squorli Directory (section 3) if you use an account, and to squorli.com for updates (section 2.3). Further connections arise only from functions you or the server switch on: web radio streams, YouTube videos (through the privacy-enhanced address youtube-nocookie.com and only after you press play) and Twitch streams are delivered directly from the respective provider to your browser, which sees your IP address and, in Twitch’s case, may set its own cookies. The camera’s background blur loads its model from the chat server or from the desktop app; older versions (before Squorli Server 0.5.2 and desktop app 0.8.1) download it from jsDelivr and Google Cloud Storage on first use. The desktop app sends no usage statistics and no crash reports.
5. GitHub: repository, releases and container image
The source code of Squorli Server, the installation files of the desktop app and the container image are published on GitHub, Inc., 88 Colin P Kelly Jr St, San Francisco, CA 94107, USA. When you visit the repository, open issues or pull requests, download releases or pull the container image, GitHub processes your data under its own responsibility; GitHub’s privacy statement applies. GitHub is certified under the EU-US Data Privacy Framework. The desktop app also downloads updates from GitHub (section 2.3).
6. Donations
Donations to support the project are planned. Once a donation service is integrated, this section will name the provider, the payment data processed there and link to its privacy policy. Until then no payment data is processed through the website or the service.
7. Recipients and transfers to third countries
Recipients of personal data are Hetzner Online GmbH as the hoster of the website and Strato GmbH as the hoster of the Directory (each under a data processing agreement), the mail provider named in section 3.3 for sending e-mail, the chat servers you sign in on (section 3.4) and your friends to the extent of sections 3.1 and 3.2. Transfers to third countries take place only where you yourself use services of GitHub, YouTube, Twitch or other providers (sections 4 and 5) or the service looks up links or game catalogues on your behalf (section 3.6); those providers then receive at most the service’s address.
8. Your rights
Towards the controller you have the right of access to your personal data (Art. 15 GDPR), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20) and the right to object, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR (Art. 21). You can delete your account and the data connected to it yourself (section 3.8). For anything else an e-mail to the address above is enough.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for the controller is:
Die Landesbeauftragte für den Datenschutz Niedersachsen (State Commissioner for Data Protection of Lower Saxony)
Prinzenstraße 5
30159 Hannover, Germany
lfd.niedersachsen.de
You may also contact the supervisory authority of your place of residence.
9. Changes
This policy is updated when the software or the services used change. The current version is always at squorli.com/en/datenschutz/.
Last updated: 30 September 2026