Skip to content

Privacy

What this website collects, what the product stores, and who can reach it.

This document requires legal review before production launch. It is an accurate description of how the application behaves today, written by the people who built it. It is not a legally authoritative privacy notice, and it has not been reviewed by counsel.

1. Scope

This describes two different things, and the difference matters. This website is the public marketing site you are reading now. The product is the Priveloq Chat application, which is reached by signing in and which is operated by whichever organisation deployed it — that organisation decides its own policy for the data inside it.

2. This website

These public pages carry no analytics, no advertising pixel, no session-recording script and no third-party tracker. Nothing on them loads from another company's servers: the stylesheets, the script, the icons and the images are all served from this installation.

No cookie is set for you by simply reading these pages. Signing in sets cookies, and those are described below.

Ordinary web server logs may record the request, including the address it came from, the page requested and the browser's own description of itself. That is how a web server is operated and how abuse is investigated; how long those logs are kept is a decision of whoever runs this installation.

3. The contact form

What you type into the contact form — your name, email address, optional company, subject and message — is emailed to the mailbox that answers enquiries for this installation, so that somebody can reply to you. It is not added to a mailing list and it is not sold or passed to a third party.

The submission is checked for the marks of an automated post, and the endpoint is rate limited by the address it came from. The message body is not written into the application log.

4. Accounts

There is no public registration. An account exists because an administrator of a deployment issued an invitation to an address and somebody redeemed it. An account record holds a display name, an email address, a password stored only in hashed form, and — if multi-factor authentication is enabled — an authenticator secret and hashed recovery codes.

5. Cookies

The cookies this application sets are functional and security cookies. There are no advertising or analytics cookies.

  • An authentication cookie, which is what keeps you signed in. It is bound to a session record that an administrator or you can revoke.
  • A refresh cookie, used to obtain short-lived access tokens for the realtime connection.
  • A guest cookie, held only by somebody who redeemed a temporary guest invitation, and valid for that one room.
  • An antiforgery cookie, which is what stops another site submitting a form as you.

All of them are marked so that a browser will not send them over an unencrypted connection and will not expose them to scripts.

6. What the product stores

Inside a deployment, Priveloq Chat stores the conversations their participants create: messages, the files and voice notes attached to them, call records, notification pointers, session records and a security audit trail of consequential administrative actions.

Message content is readable by the server. This site does not claim end-to-end encryption, and the security page says so plainly.

Photographs have their embedded metadata — including any location the camera recorded — removed before they are stored.

7. Temporary guest rooms

A temporary guest room is deleted, along with its messages, its files, the stored objects behind them, its call record and the guest's ephemeral identity, when its retention window closes. What survives is the administrative record that the room existed, who opened it and when it ended — never what was said in it. See guest access for this installation's configured windows.

8. Hidden chats

Priveloq Vault controls what is shown and to which browser session. Hidden conversations are still stored, and the vault secret is kept only in a form that cannot be read back — by anybody, including an administrator. It is an access-control feature, not encryption.

9. Who can see what

Conversation content is served only to its participants. An administrator of a deployment can manage accounts, roles, sessions and the lifecycle of guest rooms, and can read the security audit trail; the administration area has no route into the contents of a conversation.

10. Third parties

Audio and video calls are carried by a conference service that the deployment operates or contracts. Files may be stored in object storage the deployment operates or contracts. Email is delivered by whichever provider the deployment has configured. Which providers those are is a question for the organisation that deployed it.

11. Retention

Guest rooms are erased automatically on the schedule described above. Read and dismissed notifications are swept after a configurable period; an unread one is kept. Everything else is retained until it is deleted, and by whom and on what schedule is a decision of the organisation running the deployment.

12. Your rights, and who to ask

If you use Priveloq Chat because an organisation gave you an account, that organisation is the one to ask about the data in it. For anything to do with this website or a message you sent through the contact form, write to hello@priveloq.local.

The statutory rights that apply to you, the lawful bases relied upon, and the identity of the data controller are exactly the sections this draft does not attempt, because they need a lawyer rather than an engineer.

13. Changes

This document will be replaced by a reviewed privacy notice before this product launches publicly.