Skip to main content

PRIVACY policy.

Effective Date: August 24, 2026


Ephemere Chat (“Ephemere Chat,” “we,” “us,” or “our”) operates the Ephemere Chat service (the “Service”).


This Privacy Policy explains what information we process when you use the Service, how long that information is retained, and how the Service is designed to minimise persistent data. For the rules governing your use of the Service and the legal agreement between you and Ephemere Chat, please refer to our Terms of Service.


Ephemere Chat provides access to a hardened, ephemeral Matrix server environment designed to give users greater control over the security and privacy of their communications.


The Service is intended for people who have a legitimate need for stronger communications security and reduced data persistence. This may include journalists, activists, researchers, organisations, security-conscious individuals, and others who prefer not to have their communications infrastructure retain unnecessary historical information.


We do not own or control the Matrix protocol. Matrix is an open communications protocol, and Ephemere Chat provides a hardened server service built around it.


Our approach is based on privacy by design: minimising the information created, minimising logging, limiting persistence, and automatically removing information that is no longer required.


The Service is not designed to create a permanent record of users' activity or communications.


1. Privacy by Design

The Service operates as a non-federated server. This means that communications remain within the Ephemere Chat infrastructure and are not shared with or stored on external Matrix homeservers, ensuring that our data minimisation and retention policies apply to all interactions on the Service.


Ephemere Chat provides access to a hardened, ephemeral Matrix server environment.


We do not own or control the Matrix protocol. Matrix is an open communications protocol. Ephemere Chat provides a hardened server service built around that protocol.


The Service is designed around data minimisation and ephemeral operation. Our goal is not simply to restrict access to a large persistent database of user information, but to minimise the amount of information that is created and retained in the first place.


Accordingly, the Service is designed to have:


- minimal operational logging;

- short data-retention periods;

- automated data and room cleanup;

- automatic device/session expiration;

- connectivity via the Tor network to enhance network-level anonymity;

- automated redaction of applicable client-visible data; and

- no requirement for identity verification or KYC.


The accessibility of the Service via the Tor network is intended to facilitate user anonymity. However, the use of Tor is a tool for enhancement and does not constitute a guarantee of absolute anonymity.


Because of this architecture, information may be automatically deleted or cease to exist without any action being taken by you or us.


2. Information We Collect

We intentionally collect and retain as little information as reasonably necessary to provide the Service.


Account and Registration Information

The Service is non-KYC. We do not require you to provide government identification or undergo identity verification to use the Service.


We do not maintain a persistent database of user registration details for the purpose of building user profiles or establishing your identity.


Information that is temporarily processed by the Service may nevertheless be required for the Service to function, including information inherent to operating a Matrix server and authenticating a session.


Technical Information

The Service may temporarily process limited technical information necessary to:


- operate the Service;

- maintain availability;

- protect the infrastructure;

- prevent or investigate abuse;

- diagnose technical problems; and

- maintain security.


We intentionally limit operational logging and do not seek to create detailed or persistent histories of individual user activity.


Payment Information

Ephemere Chat accepts cryptocurrency payments for the Service.


Cryptocurrency transactions are processed through the applicable blockchain network and, where applicable, third-party cryptocurrency payment infrastructure. Users should be aware that cryptocurrency transactions are generally irreversible; once a payment is submitted to the blockchain, it cannot be undone or refunded by Ephemere Chat.


We do not require payment by credit card or debit card.


We do not intentionally collect or maintain financial identity information as part of the Service. Cryptocurrency transactions may, however, be publicly recorded on the relevant blockchain and may be subject to information held by third-party payment or infrastructure providers.


The use of cryptocurrency does not by itself guarantee anonymity. Users should consider the privacy characteristics of the cryptocurrency, wallet, exchange, and other services they use when making a payment.


3. Messages and Communications

Ephemere Chat is designed to support end-to-end encrypted communications through compatible Matrix clients and rooms.


When end-to-end encryption is correctly enabled and configured, message content is encrypted in a manner that prevents us from accessing that content in readable form.


We do not intentionally collect message content for our own purposes.


However, Matrix is a distributed communications protocol and the precise information stored or transmitted can depend on the Matrix client, room configuration, encryption settings, federation, and other services involved.


Users should therefore understand that end-to-end encryption is dependent on the configuration and behavior of the clients and services involved.


4. Ephemeral Data Architecture

The Service is intentionally designed to minimise persistence.


Our current architecture includes the following controls:


Minimal Logging

We keep operational logging as limited as reasonably possible.


Logs are intended to support the operation and security of the Service rather than to create a persistent record of individual user activity.


One-Day Retention

Information that is temporarily retained as part of the normal operation of the Service is generally subject to a maximum standard retention period of one (1) day.


Information may be deleted sooner.


The one-day period does not mean that every category of information necessarily exists for one day. Different systems and data types may have shorter automated deletion periods.


Twelve-Hour Redaction

Applicable client-visible information is subject to automated redaction after approximately 12 hours.


This mechanism is intended to reduce the amount of historical information available through the Service.


Weekly Device Logout

Devices and sessions are automatically logged out on a weekly basis as part of the Service's security and ephemeral design.


This reduces the lifetime of persistent access credentials and active sessions.


Room Cleanup

Rooms and associated ephemeral data are subject to automated and periodic cleanup.


The purpose of this mechanism is to prevent unnecessary long-term persistence of information within the Service.


5. What We Do Not Do

We do not sell personal information.


We do not use the Service to build advertising profiles based on user communications.


We do not intentionally build persistent behavioral profiles of users.


We do not require KYC or government identification as a condition of using the Service.


We do not intentionally retain information merely because it may be useful in the future.


Our systems are designed to delete information when it is no longer required for the operation of the Service.


6. Information We Do Not Have

An important consequence of our architecture is that we may be unable to provide information that has already been automatically deleted or that we never collected.


The Service is not designed around maintaining a comprehensive historical database of user activity.


Accordingly, a request for historical information may have no information available to provide.


This is a consequence of the Service's ephemeral architecture and is not a guarantee that absolutely no technical information is ever processed while the Service is operating.


7. Service Providers

We may use third-party providers where necessary to operate the Service.


These providers may include infrastructure, hosting, payment, security, monitoring, or other operational providers.


A provider may process information necessary to perform the service we have engaged it to provide.


Where reasonably possible, we configure our services and providers consistently with our principles of data minimisation and limited retention.


Third-party providers may have their own privacy policies and legal obligations governing information they process independently of Ephemere Chat.


8. Security

We use reasonable technical and organisational measures designed to protect the Service and the information temporarily processed by it.


The Service's security model includes ephemeral operation, limited logging, automatic session expiration, automated cleanup, and short retention periods.


No internet service can guarantee absolute security. However, minimising the amount of information retained reduces the amount of information that could potentially be exposed if an infrastructure component were compromised.


9. Legal Requirements and Security Incidents

There may be circumstances in which we are required to process or disclose information to comply with applicable law or valid legal process.


The Service is designed with minimal logging and ephemeral data retention. We do not maintain persistent security or activity logs for the purpose of investigating users or reconstructing historical activity.


Information that exists temporarily as a necessary part of operating the Service may be processed while the Service is functioning. However, once that information has been automatically deleted or expired, we cannot recover or provide it.


If a security incident occurs, our ability to investigate historical activity is therefore inherently limited by the Service's architecture and retention model.


10. Data Retention

Our general principle is simple:


If information is not required, we do not intentionally retain it.


Information required temporarily to operate the Service is subject to automated expiration and deletion according to the relevant system and data type.


Our standard architecture is designed around:


- approximately 12-hour redaction for applicable client-visible data;

- periodic room cleanup;

- weekly device/session expiration; and

- a standard maximum retention period of one day for information that must temporarily persist.


Specific retention periods may differ where technically necessary, where information is controlled by a third party, or where a longer period is required by applicable law.


11. Your Rights

Depending on where you live and which privacy laws apply to you, you may have rights concerning personal information processed by the Service.


These may include rights to request access to, correction of, deletion of, or information about the processing of your personal information.


Because the Service intentionally minimises and automatically deletes information, we may be unable to identify, retrieve, or provide information requested by a user.


Where information no longer exists or was never collected, there is no corresponding record for us to retrieve.


12. Children's Privacy

The Service is not intended to encourage the collection of personal information from children.


We do not knowingly collect personal information from children for the purpose of creating user profiles or providing targeted advertising.


13. International Processing

The Service and its third-party providers may process information in countries other than the country in which you are located.


Where applicable, such processing will be subject to the legal requirements governing the relevant transfer or processing.


14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to the Service, our infrastructure, our data practices, or applicable legal requirements.


When we make changes, we will update the Effective Date at the beginning of this policy.


15. Contact

Questions regarding this Privacy Policy may be directed to Ephemere Chat using the contact information provided on the Ephemere Chat website. For secure, end-to-end encrypted communication regarding these matters, we recommend using our SimpleX Messenger address.


In short: Ephemere Chat is designed to collect and retain as little information as possible. The Service is intentionally ephemeral, uses minimal logging, automatically removes information, and does not require KYC. Where information has been deleted or was never collected, we cannot provide it because we do not have it.

Built for ephemeral, privacy-focused communication.

© 2026 Ephemere Chat.  All rights reserved.