Spectrlink Privacy Policy
Last updated: 4 October 2026
Developer: the developer shown as the seller on Spectrlink's App Store / Google Play page
("Spectrlink", "we", "us")
Contact: [email protected]
Spectrlink is a client app for the open Matrix protocol, not a messaging service. This policy explains what the app does with data, what we ourselves receive, and what we do not.
1. The short version
- Spectrlink is an app, not a service with accounts. You connect it to a Matrix server that you choose (for example your own). That server holds your account and messages; we do not have access to it.
- Messages, calls and files in encrypted chats are end-to-end encrypted.
- We do not sell your data, show ads, or use analytics or tracking SDKs in the app.
- What reaches us is limited to what is needed to deliver push notifications (section 4).
2. Who is responsible for what
| Responsible | What they handle | |
|---|---|---|
| Your homeserver (the operator you chose) | The server operator, under their own policy | Your account, profile, messages and files, room membership, devices, logs, backups, retention, moderation, account deletion |
| Spectrlink (the app developer) | Us | The app on your device; the push notification gateway; this website |
| Apple / Google | Them, under their own policies | Push delivery (APNs / Firebase Cloud Messaging); App Store / Google Play |
We are not responsible for how server operators, Apple, Google or other third parties handle your data. Read the privacy policy of the server you use: it decides how long it keeps your data and who can see unencrypted content. A server operator can see account metadata (who you talk to, when, from which IP address) and the content of unencrypted rooms.
3. What the app does on your device
- It stores your session and a local database of your chats on the device, encrypted, with keys held in the system keychain.
- It sends your data to your homeserver (and, for calls, to the call servers that server announces). Our servers are not in that path.
- It asks for these permissions, which you can revoke in system settings: Camera (video calls, video messages, scanning verification QR codes), Microphone (calls, voice and video messages), Photos (attach or save images), Location (only when you choose to share it in a chat; it is sent to the people in that chat via your server), Notifications.
- It has no analytics, no advertising identifier and no tracking. It does not read your contacts.
4. What reaches us: push notifications
To show notifications while the app is closed, the app registers with your homeserver a push endpoint that points to our push gateway. When something happens for you, your homeserver sends a small notification request to our gateway, which forwards it to Apple's or Google's push service.
- We process: your device's push token, the app ID, the identifiers of the room and event to be notified about, and unread counts. The app registers for pushes in the "event ID only" format, so no message text, sender name or room name passes through our gateway, Apple or Google, in any room; the app fetches the message from your server and, if it is encrypted, decrypts it on your device to show it.
- The gateway may see the network address of the server that sends the request, but not your Matrix user ID or your messages, and cannot link a push token to a person.
- We do not keep access logs of the gateway and do not store message content. The gateway service writes a small technical log (service events and errors, without message content and without your network address); it is overwritten automatically as it fills up.
- Apple and Google process your push token under their own policies.
- Your server operator can see that you use push.
5. Website and contact
Our website and support mailboxes process what you send us (email address and message content) only to answer you, for as long as needed to resolve the matter.
6. Sharing
We do not sell personal data and do not share it for advertising. We share the data described in section 4 with Apple/Google as needed to deliver notifications, with the provider that hosts the gateway, and when the law requires it. We have no access to your messages, and for encrypted content we have no keys.
7. Deleting your data
- Account and messages: are on your homeserver. Use Settings → Delete account in the app (it deactivates your account on your server), or ask your server's operator. We cannot delete data on a server we do not operate.
- Push registration: signing out removes the push registration; deleting the account removes it too on standard Matrix servers. To remove anything we hold, write to [email protected].
- Local data: signing out erases the app's data for that account on the device. Uninstalling removes the app's files; on iPhone, small items in the system keychain can remain until you reset the device, and are not readable by other apps.
8. Your rights
Depending on where you live (for example under the GDPR / UK GDPR or the CCPA/CPRA) you may have the right to access, correct, delete or export your data, to object or restrict processing, and to complain to a data protection authority. For data on your homeserver contact its operator; for push data and the website contact [email protected]. We reply within the time the applicable law requires. We do not make automated decisions about you. Legal bases (GDPR): contract (delivering notifications you ask for), legitimate interests (security, abuse prevention), consent for the optional device permissions.
9. Children
Spectrlink is not directed to children under 13, or under the higher minimum age that applies where you live (up to 16 in some EU countries). The app connects to servers run by others, which set their own age rules.
10. Security
The app uses encrypted connections (TLS), end-to-end encryption in encrypted rooms, and encrypted local storage. No software is free of flaws, and we cannot guarantee security; the security of your account also depends on your server and your device. Report vulnerabilities to [email protected].
11. Changes
We may change this policy by posting a new version on this page; the date at the top shows the latest version.