Shadewire · privacy
Privacy.
We collect what running the service requires, and nothing for sale. This page says what that means concretely, including where the limits are.
1. What we collect
To run Shadewire as a working service we store:
- Account information — username, display name and email address.
- Messages and content — messages, files and media you send.
- Server and channel data — communities you create or join, channels, roles and configuration.
- Connection metadata — IP address and timestamp at login, used to spot abuse.
- Client information — app version and platform, sent by the client so we can diagnose faults.
- Access applications — the name, email and context you submit when requesting access.
2. What we don't collect
- No cross-site or cross-app tracking.
- No advertising profiles — there is no advertising.
- No third-party analytics. This website loads no third-party scripts, fonts or pixels at all.
- No payment information. Shadewire does not charge for anything.
3. How it's used
Only to operate the service: authenticating you, delivering messages and real-time features, investigating abuse reports, and diagnosing faults.
4. We do not sell data
Your personal information is not sold, rented, licensed or transferred to any third party for commercial purposes. There are no exceptions to this, and no business model that would create one.
5. Who else touches your data
Shadewire is self-hosted, so there is no hosting provider or CDN processing your content. Two narrow exceptions exist:
- Transactional email — invitations and onboarding messages are delivered through a third-party email provider, which necessarily sees the recipient address and message body.
- Legal obligation or imminent harm — if compelled by valid legal process, or to prevent serious harm to a person.
6. What the operator can see
Messages are stored on our database so they can be delivered, searched and shown on your other devices. An administrator with access to the host can therefore read them. Shadewire does not currently offer end-to-end encrypted messaging, and we would rather say so here than imply otherwise.
What self-hosting changes is who that administrator is: one identifiable operator running their own hardware, with no commercial interest in your data — rather than a company whose revenue depends on it.
7. Retention
Data is kept while your account is active. Ask for deletion and your account and message history are removed within a reasonable period, except where the law requires otherwise. Backups roll over on their own schedule, so deletion is not instantaneous everywhere.
8. Your rights
You can ask for a copy of the personal data we hold, correction of anything inaccurate, deletion of your account, or restriction of particular processing. Ask the operator directly — on the wire, or through the access gateway.
9. Security
Traffic to every public hostname is encrypted with TLS, administrative surfaces are not reachable from the public internet, and Mesh links are WireGuard. No system is perfectly secure — use a strong, unique password and enable two-factor authentication where offered.
10. Changes
If this policy changes materially, members are told in-app or by email. The date at the top of this page always reflects the current version.