StrTalk Privacy Policy

Last updated: [DATE]

StrTalk is a messaging app operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS], [COUNTRY], registered as [COMPANY REGISTRATION NUMBER] ("we", "us"). We are the data controller for everything described here. This policy explains what StrTalk collects, what it cannot see, and what you can delete.

Contact for privacy questions and requests: privacy@strtalk.sourceless.net.

The short version

Who you are to us

StrTalk has no signup form. You sign in by connecting a cryptocurrency wallet and signing a message proving you control it, and by owning a STR domain — an NFT on the Polygon blockchain. Your STR domain becomes your StrTalk identity.

Two consequences worth being explicit about:

We also maintain a small number of app-store review accounts that sign in with a username and password instead of a wallet, so that Google's and Apple's reviewers can test StrTalk without holding a STR domain. These are ours, not users' accounts, and they hold no personal data of yours.

What we collect

Account data

When you sign in we create a messaging account on our server, holding:

Our sign-in service separately keeps a record linking your STR domain to your wallet address and to the account currently bound to it, so that we can tell when the domain changes owner.

Message content

Messages, photos, videos, voice notes, and files are end-to-end encrypted using the Matrix protocol's Olm and Megolm implementations. Encryption and decryption happen on the devices in the conversation. Our server stores and relays ciphertext it has no key for.

If you turn on Secure Backup, an encrypted copy of your message keys is stored on our server. It is encrypted with your recovery key, which we never receive, so we cannot open the backup. If you lose your recovery key, we cannot recover it for you. You can reset Secure Backup from Settings if you lose your recovery key; doing so permanently discards the old backup and the message history that only it could unlock.

What is not end-to-end encrypted

Some information has to be readable by our server for the service to work at all. It is held with normal server-side protection, but it is not end-to-end encrypted, and we would rather say so plainly than let you assume otherwise:

This is a property of the Matrix protocol StrTalk is built on, not a StrTalk shortcut.

Drafts

If you type a message and leave without sending it, that draft is saved to our server so it follows you between sessions. It is not end-to-end encrypted. Clearing the composer removes it, and leaving the conversation clears it too.

Metadata we can see

End-to-end encryption protects content, not the fact that communication happened. Our server necessarily processes and stores:

We consider this the honest core of this policy. Anyone claiming a messenger of this kind hides who talks to whom is overstating what the technology does.

StrTalk does not have online/last-seen presence. The app does not show it, and our server is configured not to track or store it.

Server monitoring

We run monitoring on our own infrastructure to keep the service working: request rates, error rates, storage and queue health, and counts of things like active accounts and messages delivered. This runs on servers we operate and is used to run and debug the service, never to profile you. It is a different thing from the advertising and analytics SDKs that are absent from the app — those send data to third parties, and we do not use any.

Two of these go to our team's Slack workspace: a daily summary of those counts, and an alert when a STR domain signs in for the first time, which names the domain and part of the wallet address. Slack is listed in the third-parties table below.

Data stored only on your device

Your settings, notification preferences, downloaded media, and your recent-media strip stay on your phone and are not sent to us. Uninstalling the app removes them.

Two things people often assume are device-only but are not, so they are listed above instead: your drafts and your per-conversation mute choices are both stored on our server.

Your photos and videos. When you open the attachment panel, StrTalk shows a strip of your most recent photos and videos so you can send one with a single tap. Reading them to draw that strip happens entirely on your device — we do not upload, scan, index, or catalogue your gallery, and the strip is never sent anywhere. A photo or video leaves your device only when you choose to send it, and then it is end-to-end encrypted like any other message. On Android 14 and later you can grant access to only the items you select rather than your whole library; on any version you can decline, and the other attachment options (the system photo picker, camera, and files) keep working. You can change or withdraw this access at any time in your device settings.

Location data in what you send. Photos you send are re-encoded before sending, which removes embedded camera metadata including GPS coordinates. Videos and files are sent as they are, so if your camera recorded a location into a video, or a document contains author information, that travels with it — to the people you send it to, end-to-end encrypted, never to us. If that matters for a particular file, check it before sending. StrTalk also supports sending a location as a message; that is only ever sent when you choose to send it.

Saving media to your device. "Save to device" copies a photo, video, voice note, or file out of StrTalk into your device's normal albums and folders. Once saved there it is an ordinary file on your phone: it is outside StrTalk, it is not covered by our retention or deletion, and it stays after you delete the message, the conversation, or your account.

Conversation shortcuts. When a message notification shows a preview, Android is given a shortcut for that conversation so the notification can display the sender's name and photo the way your phone shows other conversations. The shortcut carries that name and photo and is held by the operating system. If you turn message previews off, no shortcut is created. They are removed when you sign out, and uninstalling the app removes them.

Sharing into StrTalk from other apps. When you share a photo, video, file, or text into StrTalk from another app, it is copied into StrTalk's private storage while you choose a recipient. Nothing is sent anywhere until you send it. The copy is deleted once you send or discard it, and any copy left behind is cleared automatically within a day.

Device permissions

StrTalk asks for a permission only when you first use the feature that needs it, never at startup, and declining is always a supported state:

PermissionUsed for
MicrophoneVoice notes, and voice and video calls
CameraTaking a photo or video inside a conversation, and video calls
Photos and videosDrawing the recent-media strip in the attachment panel
NotificationsMessage and call notifications
Biometrics / device lockOptional app lock

Finding other people

There is no browsable directory and no contact-list upload. StrTalk never asks for access to your phone's address book, and we do not build a social graph from one.

You find someone by typing their exact STR handle, the way you would type a phone number. A lookup returns a result only on an exact match, so the user base cannot be enumerated or browsed, and someone who does not know your handle cannot find you. Lookups are rate-limited and available only to signed-in users.

The reverse also happens automatically: to show you a verified STR handle instead of an internal identifier, the app asks our sign-in service which handle belongs to an account whenever it displays someone. This happens as a normal part of drawing the screen, without you doing anything.

Our sign-in service records these lookups — which account looked up which handle or account — in its operational logs, for rate limiting and abuse investigation. We do not use these records to build a profile of who you know, they are not shared, and they are kept in a rolling per-service buffer of about 30 MB and overwritten automatically as new lines arrive — in practice days to a few weeks, depending on traffic.

Your wallet and the blockchain

Because your account exists only while you own your STR domain, we monitor the Polygon blockchain continuously for transfers of STR domains. This runs roughly every 90 seconds, plus an hourly reconciliation, and it looks at the STR domain contract rather than at your wallet's other activity. We do not track your balances, your other tokens, or your unrelated transactions.

To check ownership at sign-in and to run that monitoring, we query blockchain data providers. This means those providers receive wallet addresses. They are listed in the third-parties table below.

Self-destructing conversations

StrTalk offers a self-destructing 1:1 conversation that both people knowingly enter. Everything in it — every message and all media — is destroyed on both devices and on our server once both people have left it.

To make that work, our sign-in service keeps a small registry entry for the conversation: its internal room identifier, the identifiers of the media uploaded into it so they can be deleted, and timestamps. The registry never holds message content, which stays end-to-end encrypted like any other conversation. When both participants have left, a job running every few minutes deletes the media, then the conversation itself, then the registry entry.

Two honest limits. If one participant's device is offline, its local copy is wiped the next time that device runs the app, not before. And routine server records created while the conversation existed — access logs, and any backup taken during its life — age out on their normal schedules rather than being destroyed instantly.

Blocking and reporting

Blocking someone stops their messages and calls reaching you. The list of accounts you have blocked is stored on our server against your account, because the server is what enforces it.

Reporting sends us the reason you picked and anything you typed, plus who reported and who or what was reported. Reporting a message identifies that message and the conversation it is in; reporting a person identifies only the account. Because the content is end-to-end encrypted, we cannot read the messages themselves; we act on what is visible to us and on patterns of abuse at the infrastructure level. Reports are retained for 12 months so that repeat abuse can be recognised, then deleted automatically.

One phone at a time

An account can be signed in on one phone at a time. When you sign in on a new phone, we sign out the previous one. If your wallet holds more than one STR domain, you choose which one to sign in as, and we record that choice so the app knows which account to open.

Calls

Voice and video calls are end-to-end encrypted. Each participant encrypts their own audio and video before it leaves their device, and the keys are shared only with the other people in the call, over the same encrypted Matrix channel your messages use. Our media server forwards streams it cannot decrypt.

Calls run entirely on our own self-hosted infrastructure — no third-party calling provider is involved. The media server still sees your IP address and the timing and duration of calls, because it has to route the traffic. All call audio and video is relayed through our server rather than sent directly between participants, which means the other people on a call do not see your IP address.

StrTalk cannot be used to call emergency services. It has no access to 112, 911, or any other emergency number, and it cannot pass your location to emergency services. Always use your phone's normal dialler in an emergency.

Notifications

Notification wake-ups deliberately contain no message content and no sender name — only an identifier the app uses to fetch and decrypt the message locally. Google and Apple therefore never receive anything you wrote. They do see that your device received a notification, and when. If that timing signal matters to you, turn off message notifications in Settings.

Incoming calls ring your phone through the same mechanism, including when StrTalk is closed.

StrTalk does not generate link previews. Neither the app nor our server fetches a page because a link was typed or received, so sending or reading a link does not reveal your IP address to that website. Opening a link yourself is an ordinary visit to that site, which sees you as any website would.

Third parties

We keep these to a minimum. There is no advertising or analytics network anywhere in StrTalk.

WhoWhat they receiveWhy
[VPS PROVIDER]Hosts our servers, so technically holds everything described hereOur messaging, sign-in, and media infrastructure
Your wallet app and the WalletConnect/Reown relayConnection metadata, the sign-in message, and your signatureTo connect your wallet and receive your signed proof of ownership
AlchemyWallet addresses, when we verify STR domain ownership and monitor for transfersReading the Polygon blockchain
BlockscoutWallet addresses, as a fallback when the above is unavailableReading the Polygon blockchain
Google Firebase Cloud MessagingA device push token, and the identifier of a conversation with a new messageTo wake the app for notifications on Android
Google Firebase InstallationsAn identifier for your app installation, generated by Google's push libraryRequired by the push library; not used by us for anything else
Apple Push Notification serviceThe same as Firebase, on iOSTo wake the app for notifications on iOS
Google FontsYour IP address, when the app downloads the typeface it usesLoading the app's font through Google Play Services
SlackAn operational alert when a STR domain signs in for the first time, containing the domain and part of the wallet addressAlerting our own team to new sign-ups and service events

We have data processing agreements in place with the providers above where the law requires it, and we keep an up-to-date list of them at [SUBPROCESSOR PAGE URL].

A closed network

StrTalk is built on the Matrix protocol, which normally lets servers exchange messages with each other across the internet. We have turned that off. Our server does not federate: it will not send to or accept messages from any other Matrix server.

That means your conversations stay entirely on SourceLess infrastructure. They are never replicated to a server we do not operate, so there is no copy of your data sitting somewhere we cannot reach or delete.

Registration is closed as well — an account exists only for someone who owns a STR domain and signs in with it. You cannot be contacted on StrTalk by someone outside StrTalk.

Where your data is processed

Our messaging server is hosted in [SERVER LOCATION / PROVIDER]. Sign-in verification runs on that same SourceLess-operated server, not on a separate third-party cloud. Push notifications are operated by Google and Apple and may be processed outside the EEA under their own safeguards; the blockchain data providers above are outside the EEA and receive wallet addresses only. Where we transfer personal data outside the EEA we rely on [TRANSFER MECHANISM — e.g. the EU Standard Contractual Clauses], and you can ask us for details.

What we doLegal basis
Running your account and delivering your messagesPerformance of a contract
Verifying STR domain ownership and monitoring for transfersPerformance of a contract
Server logs, rate limiting, abuse investigation, blocking and reportingLegitimate interests — keeping the service secure and usable
Keeping the ownership record after an account is deletedLegitimate interests, and the establishment and defence of legal claims
Operational monitoring of our own infrastructureLegitimate interests — running a reliable service
Device permissions: camera, microphone, photos and videos, notificationsConsent, withdrawable at any time in your device settings

Where we rely on legitimate interests we have weighed them against your rights, and you can ask us for that assessment or object to the processing.

How long we keep things

DataKept for
Photos, videos, voice notes, and files on our server30 days from when they were sent, whether or not anyone opened them
Text messagesUntil deleted by you, or until the conversation is deleted
A conversation nobody is in any moreDeleted automatically about a day after the last participant leaves
Content of a message you deleted for everyoneA few minutes at most, after which only the marker that a message existed remains
Media attached to a message you deletedUntil the 30-day media cycle removes it
Display name, profile photo, group photosWhile the account or group exists; replaced photos are removed
Account data, conversation memberships, device and key informationUntil you delete your account
Encrypted key backupUntil you disable Secure Backup or delete your account
Records of the IP addresses and devices you connect from28 days
Web server, call server, and application logsKept in a rolling per-service buffer of about 30 MB and overwritten automatically as new lines arrive — in practice days to a few weeks, depending on traffic
Handle lookup recordsHeld only in application logs — kept in a rolling per-service buffer of about 30 MB and overwritten automatically as new lines arrive — in practice days to a few weeks, depending on traffic
Reports of abuse12 months, then deleted automatically
Backups of our databases7 days — see "Deleting your account"
The ownership recordPermanently — see below

Media is deleted 30 days after it is sent. This is deliberate. After that, anyone whose device never downloaded the file will see it as unavailable. If you want to keep something, use "Save to device" before the 30 days are up.

The ownership record is permanent. Our sign-in service keeps one row per period of ownership of a STR domain — the domain, the wallet that held it, the internal account identifier, and the dates. These rows are marked revoked rather than deleted, because they are what lets us prove which account legitimately holds a domain at any moment and stop a previous owner regaining access. They survive account deletion. They contain no messages and no profile information.

Deleting your account

You can delete your StrTalk account from Settings -> Account -> Delete your account in the app (both platforms), or at [DELETION PAGE URL].

Deleting your account removes your profile, display name, photo, conversation memberships, drafts, encrypted key backup, blocked list, and push registration from our server, and invalidates your sessions on every device.

Timing, including backups. Deletion from our live systems happens immediately. We also keep backups of our databases so that we can recover from a failure; a backup taken before your deletion still contains your data. Those backups are never used to restore individual accounts, are deleted on their normal cycle within 7 days, and if we ever have to restore from one we re-apply every deletion afterwards so your data does not come back.

If deletion fails. Deletion runs across several systems and, like any software, it can fail. We check afterwards that each part actually completed. If something did not, we finish it, and if your data was retained for longer than it should have been we will tell you what happened and what we did about it. We would rather tell you than let you assume a promise was kept.

Three things deletion does not reach, all for reasons outside our control:

Anything you saved to your device with "Save to device" also stays, because it is an ordinary file on your phone. Uninstalling the app removes StrTalk's own on-device data.

If your STR domain changes hands

Your account is bound to your ownership of the STR domain. If the domain is transferred or sold, we detect the change on-chain and the account bound to the previous owner is deactivated and erased, including its media. The new owner starts a completely fresh, empty account.

The new owner never gains access to the previous owner's messages, contacts, or profile. This is why an ownership change is a clean break rather than a handover.

This is an automated decision, and it can be wrong — for example if a transfer was not what it appeared to be, or if blockchain data was misread. If your account is deactivated and you believe it should not have been, write to privacy@strtalk.sourceless.net and a person will review it. We describe that process in our Terms of Service.

Your rights

If you are in the EEA or UK you have the right to access, correct, export, or delete your data, to object to or restrict processing, and to complain to your national data protection authority ([SUPERVISORY AUTHORITY]). Write to privacy@strtalk.sourceless.net and we will respond within one month. The law lets us extend that by two further months for a complex or repeated request; if we need to, we will tell you inside the first month and say why.

Two practical notes specific to StrTalk:

Children

StrTalk is for adults. You must be 18 or older to use it. We do not knowingly collect data from anyone under 18, and if we learn that we have, we delete the account and its data.

Security

Your messages are stored on our server only as ciphertext we cannot decrypt. Connections between your device and our servers use TLS. The data we can read — profile names and photos, memberships, logs — is held on [encrypted-at-rest infrastructure provided by our host / ordinary server storage], but is not separately encrypted by us. Session data on your device can be protected with your device's screen lock or biometrics if you enable that in Settings.

No system is perfectly secure. If we discover a breach affecting your data we will notify you and the relevant authority as required by law. If you believe you have found a security problem in StrTalk, please tell us at security@strtalk.sourceless.net; our disclosure policy is on our support page.

Changes

If we change this policy materially we will say so in the app before the change takes effect. The "last updated" date above always reflects the current version, and previous versions are available at [POLICY ARCHIVE URL].