Introduction
SLACKSPACE, LLC (“we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Application, Sites, or Services. We have improved our descriptions to make it easier for you to understand what information we collect and why. By using the Application, Sites, or Services, you agree to the collection and use of information in accordance with this policy.
Data we collect and how long we keep it
Application
All application data remains local to your device. We do not collect, store, or have access to the messages, contacts, notes, bookmarks, or settings you generate or input while using meshage.
The Application contains no analytics, advertising, or crash-reporting software, or any other third-party software that collects data about you. The Application does not count, time, or report your use of any feature.
Website (meshage.me)
We keep no access logs. We do not record your IP address, the pages you request, your browser or your referrer. The site loads no analytics, no trackers, and no third-party scripts, fonts or assets — every request stays on our server.
Our web server records an error log, which includes your IP address, only when a request fails. These entries are kept for at most 7 days.
If you submit a form such as the tester registration form we store what you enter, which may include your contact method and address (email or LXMF address). We retain a copy of these submissions in order to facilitate the purpose described when collected, and they are deleted when no longer needed for those purposes.
Reticulum Transport Hub (rns.meshage.me)
Meshage is a mesh networking application, and reaching a mesh over the internet means connecting to an internet-connected mesh transport hub.
We provide an Internet transport hub you can enable if you choose to.
The meshage Internet transport hub (“Internet Interface” in the Application) relays mesh traffic. We do not log the IP addresses of nodes that connect to us, or record who connected when. Routing tables exist in memory while the service runs and are not written to disk.
Reticulum Propagation Node (lxmf.propagation)
The meshage propagation node (when enabled) holds messages for you when you, or a recipient you send to, are offline, and delivers them when they return.
We cannot read your messages. That content is end-to-end encrypted by the underlying Reticulum and LXMF protocols before it ever leaves your device.
When we accept a message on behalf of a recipient who is offline, we store it until they collect it. For each stored message we hold, unencrypted:
- the sender’s LXMF address,
- the recipient’s LXMF address,
- the time it arrived, and
- its size.
The message body itself is encrypted end-to-end and we cannot read it.
Stored messages are deleted 30 days after they arrive, whether or not they were collected, or sooner once the recipient collects and acknowledges them.
This node peers automatically with other public propagation nodes. Messages we hold may be replicated to nodes operated by other people, under their retention rules, not ours.
Reticulum Relay Chat Hub (rrc.hub)
The meshage RRC Chat hub allows mesh users to participate in live group chats (a.k.a. Rooms, or Channels). The chat hub relays messages live, in memory. Message content is never written to disk.
For the group chat to function the RRC hub decrypts your message in memory only, and immediately re-encrypts it for delivery to each chat member. This is never written to disk, or logged.
We do not log nicknames, identity hashes, or which rooms you join or leave.
We do retain, indefinitely, the identity hashes recorded in channel registers (founders, operators, voiced and invited users, and banned users). A ban is a permanent record of an identity hash, by design.
While you are connected, your nickname, identity hash and room membership are held in memory and are visible to other users in the same room.
Security logs
Failed SSH login attempts and automated bans record the source IP address. These are kept for 7 days.
General
All service logs are kept for a maximum of 7 days, in one place, and are not copied to any secondary log store.
Location
On Android, meshage requests location permission because the operating system requires that permission for Bluetooth scanning — which is how the Application finds nearby mesh radios. Your location is not read, recorded, or sent anywhere as a result of granting it.
Some mesh networks further support broadcasting your position so that other users can see you on a map. Where meshage offers such a feature, it will be off unless you turn it on, it will be clear about what is being shared and with whom, and anything shared goes to the mesh (not to us) at your direction alone. Any position information the Application keeps is stored locally on your device, like the rest of your data.
Other connections you choose
The Application can connect to nodes, hubs, and mesh services operated by other people; those nodes are not governed by this policy.
How we use your information
Your data is stored locally on your device. That data, and anything you send us, is used only for the purposes described elsewhere in this document and to:
- Notify you about changes to our Application or services.
- Allow you to participate in interactive features of our Application when you choose to do so.
- Provide customer support and respond to your inquiries.
Data sharing
- We do not sell your personal data.
- We do not share or transfer your personal data to third parties; except as required for the (optional) message propagation features within Reticulum LXMF.
- Messages stored as part of this service are end-to-end encrypted and stored at most 30 days.
- We do not use any third-party analytics, advertising, or attribution service, and there is none embedded in the Application.
- We may disclose information we have if required to do so by law. What we have is set out above, and does not include the content of your direct messages, which we cannot decrypt.
Security
No method of transmission over the internet or method of electronic storage is 100% secure.
The security of your data is important to us. We implement industry-standard security measures to protect your information both in transit and at rest. The Web Site uses TLS encryption, and all Mesh Sites provided are end-to-end encrypted via the underlying Reticulum protocol.
We do not store your data, but provide tools such as Identity Lock to encrypt and secure your device-local Identity file, as well as meshvault backups to encrypt and safeguard any backups you make and manage.
User rights
You have specific rights regarding your personal data. We provide tools that allow you to update, manage, export, and delete your data directly within the Application. Specifically, you have the right to:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request that we correct any inaccurate or incomplete information.
- Deletion: Request that we delete your personal information, subject to certain legal obligations and to the security and integrity of our Services. The one thing we will not delete on request is a ban record: an identity hash recorded as banned from a chat room is kept permanently, because a ban that could be lifted by asking would not be a ban.
This document does not limit your rights with regard to your personal data should it be collected or provided in using the Application or Services. Where we hold nothing about you, a request under these rights will be answered by telling you so.
Because your messages, contacts, and settings live on your device rather than on our servers, most of these rights are exercised directly in the Application: you can export your data with a meshvault backup, correct it by editing it, and delete it by deleting it from your device.
Children’s privacy
Our Application is not intended for use by children under the age of 13. We do not knowingly collect personally identifiable information from children under 13. If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact us so that we can take the necessary actions to remove it.
Changes to this Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the “Effective Date” at the top. You are advised to review this Privacy Policy periodically for any changes.
Contact information
If you have any questions or suggestions about our Privacy Policy, do not hesitate to contact us at:
Slackspace, LLC
Indianapolis, IN
privacy@slackspace.net