Privacy Policy
Last updated: 14 August 2026
Introduction
This describes what Cordice does with your data. It is written to be accurate rather than reassuring: where something is imperfect, it says so.
Who runs this
Cordice is operated by an individual, not a company. That person is the data controller and can be reached at [email protected].
For data questions specifically: [email protected].
What is held, item by item
This list is written from the data model itself rather than from memory. If something is stored, it is named here.
Your account
- Email address, and a normalised form of it used to stop one address being registered twice under different spellings.
- Password, stored as an Argon2 hash. It cannot be read back, by us or by anyone holding the database.
- Verification state — whether the address has been confirmed.
- Password reset and account deletion state, while either is in progress.
- Lockout state, if repeated failed sign-ins have temporarily closed the account.
Who you are on the service
- Username and the four-digit discriminator after it.
- Display name, pronouns and profile text, if you fill them in.
- Avatar, profile background and banner, if you upload them.
- Status, and a badge field we set — not you.
- Relationships: your friends, your outgoing and incoming requests, and anyone you have blocked.
Signing in from somewhere
Each session records a name — what the browser or app said about itself, such as “Firefox on Linux” — the time it was last used, and the token that keeps it signed in. No IP address is stored with a session. You can see and end every one of them in Settings.
If you turn on two-step verification we also hold your authenticator secret and your recovery codes, because verifying a code requires having them.
What you send and where you send it
- Messages, with their attachments, edits, reactions and replies.
- Which channels you have read up to, so unread marks work across devices.
- The servers you are in, your nickname and roles in each, and when you joined.
- Servers you run: their settings, channels, roles, custom emoji, invites and bans.
- Audit log entries for moderation actions in a server, which delete themselves after a set period.
Messages are not end-to-end encrypted. They travel over an encrypted connection and sit on encrypted disks, and the server can read them. Anything that depends on us being unable to should not be sent through Cordice.
Files you upload
Stored with the original filename, a hash of the contents, who uploaded it, when, and what it was attached to.
Photographs are stripped of their EXIF metadata on upload — the camera, the settings, and above all the GPS coordinates. Orientation is applied to the image and the rest is discarded before the file is ever stored. This is done for JPEG, PNG, AVIF and TIFF.
The hash exists so that the same file uploaded twice is stored once. It also means an identical file can be recognised as identical.
Reports
If somebody reports a message or a user, we keep the report and a snapshot of what was reported. Without the snapshot a report becomes unreviewable the moment the content is deleted, which is the first thing that happens.
Support
Your email address and everything in your message, kept as a ticket so that a conversation continued months later still has its history.
Your IP address
Your address is visible to our servers, as it is to any server you connect to, and it is used to apply rate limits — the mechanism that stops one machine hammering the service. It is not stored against your account, it is not stored with your sessions, and we run no web-server access log. Service logs may contain it incidentally while they are being written; nothing builds a profile from it, and none of it is shared for advertising.
During sign-up, Cloudflare Turnstile checks you are not a script, and Cloudflare sees your address and browser characteristics for that check.
What is not held
Stated because the absence is as much a fact as the presence, and because each of these can be checked in the source rather than believed.
- No advertising or tracking of any kind. No advertising identifiers, no pixels, no third-party analytics on the site or in the clients.
- No crash or error reporting to anybody else. The client contains a hook for Sentry; it has no address configured, so it does not start and nothing is sent.
- No IP address kept against your account.
- No location data. We do not ask for it, and where a photograph carried it, it is removed before storage.
- No reading of your messages by machine for advertising, profiling or training. Nothing is sold, rented or shared for advertising.
- No contact list, no address book, no phone number. Cordice never asks for a phone number.
Why we are allowed to hold it
Your account, your messages, and your files are held because they are what the service is: without them there is nothing to deliver. Logs and the sign-up check are held because a service open to the internet cannot be run without some defence against abuse.
We do not hold anything for advertising, because there is no advertising on Cordice.
Who else can see it
Only these, and only for the purpose named:
| Who | What they see | Why |
|---|---|---|
| Contabo | the servers themselves | they host them |
| Cloudflare | DNS lookups; your IP during sign-up | domain names, anti-automation |
| Let’s Encrypt | our domain names, publicly logged | certificates |
| Cloudflare Pages | visits to the website and documentation | they serve those pages |
| GitHub | visits to the status page | it serves that page |
| if you turn on push notifications in the Android app: the notification itself, including the sender’s name and the text shown in it | Android delivers notifications to a sleeping app only through Google’s service | |
| Your browser’s push service | if you turn on push notifications on the web: that a notification is waiting and which browser it is for — not what it says | web push payloads are encrypted to your browser before they leave us |
Push notifications are the exception to everything else on this page, and they are worth reading twice.
On Android, a notification about a message carries the sender’s name and the text of the message, and Android has no way of waking a sleeping app except through Google’s own service. So Google sees that text. This is true of every Android chat app that notifies you, ours included, and it is not something we can encrypt our way out of while still showing you what was said.
Web push is different: the payload is encrypted before it leaves us and only your browser can read it, so the push service sees that something arrived and nothing about what.
If this matters to you, turn push notifications off. Cordice works without them — messages arrive while the app is open either way.
Things that look like they leave and do not
Link previews. When you post a link, our own service fetches the page to build the preview. The site at the other end sees a request from our server, not from you — it does not learn your address, and it does not learn that it was you who posted the link.
Voice and video. Calls run through our own media server on our own machines. The other people in a call do not learn your IP address, and neither does anyone outside.
Email. Everything to and from Cordice passes through our own mail server. No third party handles it.
Custom emoji and the standard emoji sets are served from our own domain, so opening a message does not tell anyone else which messages you are reading.
Nothing is sold, rented, or shared for advertising.
We will disclose data if we are legally required to. Where we are permitted to tell you that it happened, we will.
Where it is stored
On servers rented from Contabo, physically located in France. Nothing is stored outside the European Union.
Push notifications are again the exception, and only while they are switched on: they are handed to the platform’s push service for delivery, and those services operate outside the European Union. Nothing is stored there — a push is delivered and discarded — but it does pass through.
How long it is kept
Messages and files stay until they are deleted — by you, by whoever can moderate the channel they are in, or with the account.
Your account stays until you end it. Two ways to do that, and they differ: disabling takes it out of use and keeps the data; deleting queues it for removal. A deleted account is held for seven days first, so that a change of mind is possible, and is then removed.
Audit log entries in a server carry their own expiry and delete themselves when it passes.
Backups deserve a straight answer. Everything is copied nightly, and those copies are kept on a fixed ladder: seven daily, four weekly, six monthly. So the longest anything survives in a backup is about six months. When you delete your account it disappears from the running service at once, and copies remain in backups until they age off that ladder. This is true of nearly every service that backs anything up; few of them say so.
Support tickets are kept so that history is not lost between messages.
Rate-limit counters live for the length of the window they count — minutes — and are not written to the database.
Your rights
If you are in the European Union, the GDPR gives you the right to:
- know what we hold about you and get a copy
- correct anything wrong
- erase your data
- restrict what we do with it while a dispute is resolved
- take it elsewhere in a portable form
- object to particular processing
Write to [email protected] from the address on your account. We answer within one month.
Two honest limits. Erasure removes your account and your content, but cannot reach the copy already written into a backup — that expires on its own within six months. And messages you sent to other people stay in their conversations, as a letter you posted stays with whoever received it.
Children
Cordice is not intended for anyone under 16. If we learn that an account belongs to a child below that age, we close it and delete the data.
Changes
If this changes in a way that affects you, it will be announced before it takes effect, not applied quietly. The date at the top always reflects the current version.
Complaints
Write to us first — most things are a misunderstanding and can be fixed. If that gets you nowhere, you may complain to the data protection authority in the country where you live.