StrTalk Privacy Policy
Last updated: [DATE]
StrTalk is a messaging app operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS], [COUNTRY], registered as [COMPANY REGISTRATION NUMBER] ("we", "us"). We are the data controller for everything described here. This policy explains what StrTalk collects, what it cannot see, and what you can delete.
Contact for privacy questions and requests: privacy@strtalk.sourceless.net.
The short version
- Your messages are end-to-end encrypted. We hold them only as ciphertext and cannot read them.
- Your profile name and photo are not encrypted — the server has to read them. See "What is not end-to-end encrypted".
- There is no advertising, analytics, tracking, or crash-reporting SDK in the app. We do run monitoring on our own servers; that is described below.
- We never see your wallet's private keys or seed phrase, and we never ask for them.
- We do see metadata: which accounts exchange messages, when, and in which conversations. Encryption does not hide this, and we are not going to claim otherwise.
- We watch the blockchain continuously for transfers of your STR domain, because your account depends on you still owning it.
- You can delete your account. See "Deleting your account" for what that does and does not reach, and what happens if it fails.
Who you are to us
StrTalk has no signup form. You sign in by connecting a cryptocurrency wallet and signing a message proving you control it, and by owning a STR domain — an NFT on the Polygon blockchain. Your STR domain becomes your StrTalk identity.
Two consequences worth being explicit about:
- Your wallet address and STR domain are public blockchain data. They existed before StrTalk and are visible to anyone, on a ledger we do not control and cannot alter. Deleting your StrTalk account does not and cannot remove them.
- We never receive your private keys. Signing happens inside your own wallet app. We receive only the resulting signature, which proves ownership without revealing anything that could move your assets. The signature is checked and discarded — we never store it.
We also maintain a small number of app-store review accounts that sign in with a username and password instead of a wallet, so that Google's and Apple's reviewers can test StrTalk without holding a STR domain. These are ours, not users' accounts, and they hold no personal data of yours.
What we collect
Account data
When you sign in we create a messaging account on our server, holding:
- An internal account identifier, which is a random value rather than your STR domain or wallet address
- Your STR domain, shown as the name other StrTalk users see
- A display name and profile photo, if you set them
- Your list of conversations and their memberships
- Cryptographic device and key information used to encrypt your messages
- Any message you have typed into the composer but not yet sent (see "Drafts" below)
Our sign-in service separately keeps a record linking your STR domain to your wallet address and to the account currently bound to it, so that we can tell when the domain changes owner.
Message content
Messages, photos, videos, voice notes, and files are end-to-end encrypted using the Matrix protocol's Olm and Megolm implementations. Encryption and decryption happen on the devices in the conversation. Our server stores and relays ciphertext it has no key for.
If you turn on Secure Backup, an encrypted copy of your message keys is stored on our server. It is encrypted with your recovery key, which we never receive, so we cannot open the backup. If you lose your recovery key, we cannot recover it for you. You can reset Secure Backup from Settings if you lose your recovery key; doing so permanently discards the old backup and the message history that only it could unlock.
What is not end-to-end encrypted
Some information has to be readable by our server for the service to work at all. It is held with normal server-side protection, but it is not end-to-end encrypted, and we would rather say so plainly than let you assume otherwise:
- Your display name and profile photo. The server has to serve these so that other people see who is inviting them or who is in a conversation, including before that conversation's encryption keys exist. Message content is never in this category.
- Group names and group photos, for the same reason.
- Who is in which conversation, and when they joined or left. The server enforces membership, so it must know it.
This is a property of the Matrix protocol StrTalk is built on, not a StrTalk shortcut.
Drafts
If you type a message and leave without sending it, that draft is saved to our server so it follows you between sessions. It is not end-to-end encrypted. Clearing the composer removes it, and leaving the conversation clears it too.
Metadata we can see
End-to-end encryption protects content, not the fact that communication happened. Our server necessarily processes and stores:
- Which accounts are in which conversations, and when they joined or left
- The time each message was sent, its size, and which conversation it belongs to
- Your device list and when devices connect
- Your IP address and app version, recorded in server logs
- Read receipts and typing notifications, unless you turn those off in Settings -> Privacy
- Which conversations you have muted, and which accounts you have blocked
We consider this the honest core of this policy. Anyone claiming a messenger of this kind hides who talks to whom is overstating what the technology does.
StrTalk does not have online/last-seen presence. The app does not show it, and our server is configured not to track or store it.
Server monitoring
We run monitoring on our own infrastructure to keep the service working: request rates, error rates, storage and queue health, and counts of things like active accounts and messages delivered. This runs on servers we operate and is used to run and debug the service, never to profile you. It is a different thing from the advertising and analytics SDKs that are absent from the app — those send data to third parties, and we do not use any.
Two of these go to our team's Slack workspace: a daily summary of those counts, and an alert when a STR domain signs in for the first time, which names the domain and part of the wallet address. Slack is listed in the third-parties table below.
Data stored only on your device
Your settings, notification preferences, downloaded media, and your recent-media strip stay on your phone and are not sent to us. Uninstalling the app removes them.
Two things people often assume are device-only but are not, so they are listed above instead: your drafts and your per-conversation mute choices are both stored on our server.
Your photos and videos. When you open the attachment panel, StrTalk shows a strip of your most recent photos and videos so you can send one with a single tap. Reading them to draw that strip happens entirely on your device — we do not upload, scan, index, or catalogue your gallery, and the strip is never sent anywhere. A photo or video leaves your device only when you choose to send it, and then it is end-to-end encrypted like any other message. On Android 14 and later you can grant access to only the items you select rather than your whole library; on any version you can decline, and the other attachment options (the system photo picker, camera, and files) keep working. You can change or withdraw this access at any time in your device settings.
Location data in what you send. Photos you send are re-encoded before sending, which removes embedded camera metadata including GPS coordinates. Videos and files are sent as they are, so if your camera recorded a location into a video, or a document contains author information, that travels with it — to the people you send it to, end-to-end encrypted, never to us. If that matters for a particular file, check it before sending. StrTalk also supports sending a location as a message; that is only ever sent when you choose to send it.
Saving media to your device. "Save to device" copies a photo, video, voice note, or file out of StrTalk into your device's normal albums and folders. Once saved there it is an ordinary file on your phone: it is outside StrTalk, it is not covered by our retention or deletion, and it stays after you delete the message, the conversation, or your account.
Conversation shortcuts. When a message notification shows a preview, Android is given a shortcut for that conversation so the notification can display the sender's name and photo the way your phone shows other conversations. The shortcut carries that name and photo and is held by the operating system. If you turn message previews off, no shortcut is created. They are removed when you sign out, and uninstalling the app removes them.
Sharing into StrTalk from other apps. When you share a photo, video, file, or text into StrTalk from another app, it is copied into StrTalk's private storage while you choose a recipient. Nothing is sent anywhere until you send it. The copy is deleted once you send or discard it, and any copy left behind is cleared automatically within a day.
Device permissions
StrTalk asks for a permission only when you first use the feature that needs it, never at startup, and declining is always a supported state:
| Permission | Used for |
|---|---|
| Microphone | Voice notes, and voice and video calls |
| Camera | Taking a photo or video inside a conversation, and video calls |
| Photos and videos | Drawing the recent-media strip in the attachment panel |
| Notifications | Message and call notifications |
| Biometrics / device lock | Optional app lock |
Finding other people
There is no browsable directory and no contact-list upload. StrTalk never asks for access to your phone's address book, and we do not build a social graph from one.
You find someone by typing their exact STR handle, the way you would type a phone number. A lookup returns a result only on an exact match, so the user base cannot be enumerated or browsed, and someone who does not know your handle cannot find you. Lookups are rate-limited and available only to signed-in users.
The reverse also happens automatically: to show you a verified STR handle instead of an internal identifier, the app asks our sign-in service which handle belongs to an account whenever it displays someone. This happens as a normal part of drawing the screen, without you doing anything.
Our sign-in service records these lookups — which account looked up which handle or account — in its operational logs, for rate limiting and abuse investigation. We do not use these records to build a profile of who you know, they are not shared, and they are kept in a rolling per-service buffer of about 30 MB and overwritten automatically as new lines arrive — in practice days to a few weeks, depending on traffic.
Your wallet and the blockchain
Because your account exists only while you own your STR domain, we monitor the Polygon blockchain continuously for transfers of STR domains. This runs roughly every 90 seconds, plus an hourly reconciliation, and it looks at the STR domain contract rather than at your wallet's other activity. We do not track your balances, your other tokens, or your unrelated transactions.
To check ownership at sign-in and to run that monitoring, we query blockchain data providers. This means those providers receive wallet addresses. They are listed in the third-parties table below.
Self-destructing conversations
StrTalk offers a self-destructing 1:1 conversation that both people knowingly enter. Everything in it — every message and all media — is destroyed on both devices and on our server once both people have left it.
To make that work, our sign-in service keeps a small registry entry for the conversation: its internal room identifier, the identifiers of the media uploaded into it so they can be deleted, and timestamps. The registry never holds message content, which stays end-to-end encrypted like any other conversation. When both participants have left, a job running every few minutes deletes the media, then the conversation itself, then the registry entry.
Two honest limits. If one participant's device is offline, its local copy is wiped the next time that device runs the app, not before. And routine server records created while the conversation existed — access logs, and any backup taken during its life — age out on their normal schedules rather than being destroyed instantly.
Blocking and reporting
Blocking someone stops their messages and calls reaching you. The list of accounts you have blocked is stored on our server against your account, because the server is what enforces it.
Reporting sends us the reason you picked and anything you typed, plus who reported and who or what was reported. Reporting a message identifies that message and the conversation it is in; reporting a person identifies only the account. Because the content is end-to-end encrypted, we cannot read the messages themselves; we act on what is visible to us and on patterns of abuse at the infrastructure level. Reports are retained for 12 months so that repeat abuse can be recognised, then deleted automatically.
One phone at a time
An account can be signed in on one phone at a time. When you sign in on a new phone, we sign out the previous one. If your wallet holds more than one STR domain, you choose which one to sign in as, and we record that choice so the app knows which account to open.
Calls
Voice and video calls are end-to-end encrypted. Each participant encrypts their own audio and video before it leaves their device, and the keys are shared only with the other people in the call, over the same encrypted Matrix channel your messages use. Our media server forwards streams it cannot decrypt.
Calls run entirely on our own self-hosted infrastructure — no third-party calling provider is involved. The media server still sees your IP address and the timing and duration of calls, because it has to route the traffic. All call audio and video is relayed through our server rather than sent directly between participants, which means the other people on a call do not see your IP address.
StrTalk cannot be used to call emergency services. It has no access to 112, 911, or any other emergency number, and it cannot pass your location to emergency services. Always use your phone's normal dialler in an emergency.
Notifications
Notification wake-ups deliberately contain no message content and no sender name — only an identifier the app uses to fetch and decrypt the message locally. Google and Apple therefore never receive anything you wrote. They do see that your device received a notification, and when. If that timing signal matters to you, turn off message notifications in Settings.
Incoming calls ring your phone through the same mechanism, including when StrTalk is closed.
Links
StrTalk does not generate link previews. Neither the app nor our server fetches a page because a link was typed or received, so sending or reading a link does not reveal your IP address to that website. Opening a link yourself is an ordinary visit to that site, which sees you as any website would.
Third parties
We keep these to a minimum. There is no advertising or analytics network anywhere in StrTalk.
| Who | What they receive | Why |
|---|---|---|
| [VPS PROVIDER] | Hosts our servers, so technically holds everything described here | Our messaging, sign-in, and media infrastructure |
| Your wallet app and the WalletConnect/Reown relay | Connection metadata, the sign-in message, and your signature | To connect your wallet and receive your signed proof of ownership |
| Alchemy | Wallet addresses, when we verify STR domain ownership and monitor for transfers | Reading the Polygon blockchain |
| Blockscout | Wallet addresses, as a fallback when the above is unavailable | Reading the Polygon blockchain |
| Google Firebase Cloud Messaging | A device push token, and the identifier of a conversation with a new message | To wake the app for notifications on Android |
| Google Firebase Installations | An identifier for your app installation, generated by Google's push library | Required by the push library; not used by us for anything else |
| Apple Push Notification service | The same as Firebase, on iOS | To wake the app for notifications on iOS |
| Google Fonts | Your IP address, when the app downloads the typeface it uses | Loading the app's font through Google Play Services |
| Slack | An operational alert when a STR domain signs in for the first time, containing the domain and part of the wallet address | Alerting our own team to new sign-ups and service events |
We have data processing agreements in place with the providers above where the law requires it, and we keep an up-to-date list of them at [SUBPROCESSOR PAGE URL].
A closed network
StrTalk is built on the Matrix protocol, which normally lets servers exchange messages with each other across the internet. We have turned that off. Our server does not federate: it will not send to or accept messages from any other Matrix server.
That means your conversations stay entirely on SourceLess infrastructure. They are never replicated to a server we do not operate, so there is no copy of your data sitting somewhere we cannot reach or delete.
Registration is closed as well — an account exists only for someone who owns a STR domain and signs in with it. You cannot be contacted on StrTalk by someone outside StrTalk.
Where your data is processed
Our messaging server is hosted in [SERVER LOCATION / PROVIDER]. Sign-in verification runs on that same SourceLess-operated server, not on a separate third-party cloud. Push notifications are operated by Google and Apple and may be processed outside the EEA under their own safeguards; the blockchain data providers above are outside the EEA and receive wallet addresses only. Where we transfer personal data outside the EEA we rely on [TRANSFER MECHANISM — e.g. the EU Standard Contractual Clauses], and you can ask us for details.
Legal bases (EEA/UK users)
| What we do | Legal basis |
|---|---|
| Running your account and delivering your messages | Performance of a contract |
| Verifying STR domain ownership and monitoring for transfers | Performance of a contract |
| Server logs, rate limiting, abuse investigation, blocking and reporting | Legitimate interests — keeping the service secure and usable |
| Keeping the ownership record after an account is deleted | Legitimate interests, and the establishment and defence of legal claims |
| Operational monitoring of our own infrastructure | Legitimate interests — running a reliable service |
| Device permissions: camera, microphone, photos and videos, notifications | Consent, withdrawable at any time in your device settings |
Where we rely on legitimate interests we have weighed them against your rights, and you can ask us for that assessment or object to the processing.
How long we keep things
| Data | Kept for |
|---|---|
| Photos, videos, voice notes, and files on our server | 30 days from when they were sent, whether or not anyone opened them |
| Text messages | Until deleted by you, or until the conversation is deleted |
| A conversation nobody is in any more | Deleted automatically about a day after the last participant leaves |
| Content of a message you deleted for everyone | A few minutes at most, after which only the marker that a message existed remains |
| Media attached to a message you deleted | Until the 30-day media cycle removes it |
| Display name, profile photo, group photos | While the account or group exists; replaced photos are removed |
| Account data, conversation memberships, device and key information | Until you delete your account |
| Encrypted key backup | Until you disable Secure Backup or delete your account |
| Records of the IP addresses and devices you connect from | 28 days |
| Web server, call server, and application logs | Kept in a rolling per-service buffer of about 30 MB and overwritten automatically as new lines arrive — in practice days to a few weeks, depending on traffic |
| Handle lookup records | Held only in application logs — kept in a rolling per-service buffer of about 30 MB and overwritten automatically as new lines arrive — in practice days to a few weeks, depending on traffic |
| Reports of abuse | 12 months, then deleted automatically |
| Backups of our databases | 7 days — see "Deleting your account" |
| The ownership record | Permanently — see below |
Media is deleted 30 days after it is sent. This is deliberate. After that, anyone whose device never downloaded the file will see it as unavailable. If you want to keep something, use "Save to device" before the 30 days are up.
The ownership record is permanent. Our sign-in service keeps one row per period of ownership of a STR domain — the domain, the wallet that held it, the internal account identifier, and the dates. These rows are marked revoked rather than deleted, because they are what lets us prove which account legitimately holds a domain at any moment and stop a previous owner regaining access. They survive account deletion. They contain no messages and no profile information.
Deleting your account
You can delete your StrTalk account from Settings -> Account -> Delete your account in the app (both platforms), or at [DELETION PAGE URL].
Deleting your account removes your profile, display name, photo, conversation memberships, drafts, encrypted key backup, blocked list, and push registration from our server, and invalidates your sessions on every device.
Timing, including backups. Deletion from our live systems happens immediately. We also keep backups of our databases so that we can recover from a failure; a backup taken before your deletion still contains your data. Those backups are never used to restore individual accounts, are deleted on their normal cycle within 7 days, and if we ever have to restore from one we re-apply every deletion afterwards so your data does not come back.
If deletion fails. Deletion runs across several systems and, like any software, it can fail. We check afterwards that each part actually completed. If something did not, we finish it, and if your data was retained for longer than it should have been we will tell you what happened and what we did about it. We would rather tell you than let you assume a promise was kept.
Three things deletion does not reach, all for reasons outside our control:
- Messages you already sent to other people. They were delivered to their devices and their copies of the conversation. We cannot reach into other people's devices to withdraw them, the same way a sent email cannot be recalled. You can delete individual messages for everyone before deleting your account, which removes their content but leaves a marker showing a message was deleted.
- Your wallet and STR domain. They are yours, on a public blockchain. Nothing we do affects them, and you can use them elsewhere afterwards.
- The ownership record, as described above.
Anything you saved to your device with "Save to device" also stays, because it is an ordinary file on your phone. Uninstalling the app removes StrTalk's own on-device data.
If your STR domain changes hands
Your account is bound to your ownership of the STR domain. If the domain is transferred or sold, we detect the change on-chain and the account bound to the previous owner is deactivated and erased, including its media. The new owner starts a completely fresh, empty account.
The new owner never gains access to the previous owner's messages, contacts, or profile. This is why an ownership change is a clean break rather than a handover.
This is an automated decision, and it can be wrong — for example if a transfer was not what it appeared to be, or if blockchain data was misread. If your account is deactivated and you believe it should not have been, write to privacy@strtalk.sourceless.net and a person will review it. We describe that process in our Terms of Service.
Your rights
If you are in the EEA or UK you have the right to access, correct, export, or delete your data, to object to or restrict processing, and to complain to your national data protection authority ([SUPERVISORY AUTHORITY]). Write to privacy@strtalk.sourceless.net and we will respond within one month. The law lets us extend that by two further months for a complex or repeated request; if we need to, we will tell you inside the first month and say why.
Two practical notes specific to StrTalk:
- We cannot give you your message content, because we cannot read it. It is on your devices. We can give you everything we do hold: your account data, memberships, metadata, and the ownership record.
- We verify who you are by asking you to sign a message with your wallet, the same way you sign in. If you have lost access to your wallet, contact us and we will find another way to verify you that does not require you to send us identity documents unless there is no alternative.
Children
StrTalk is for adults. You must be 18 or older to use it. We do not knowingly collect data from anyone under 18, and if we learn that we have, we delete the account and its data.
Security
Your messages are stored on our server only as ciphertext we cannot decrypt. Connections between your device and our servers use TLS. The data we can read — profile names and photos, memberships, logs — is held on [encrypted-at-rest infrastructure provided by our host / ordinary server storage], but is not separately encrypted by us. Session data on your device can be protected with your device's screen lock or biometrics if you enable that in Settings.
No system is perfectly secure. If we discover a breach affecting your data we will notify you and the relevant authority as required by law. If you believe you have found a security problem in StrTalk, please tell us at security@strtalk.sourceless.net; our disclosure policy is on our support page.
Changes
If we change this policy materially we will say so in the app before the change takes effect. The "last updated" date above always reflects the current version, and previous versions are available at [POLICY ARCHIVE URL].