XMPP Privacy Policy

How the Telepath XMPP service collects, uses, and protects your data.

Last updated: 28 June 2026

This policy explains what data we process when you use Telepath XMPP (the telepath.im messaging service and its related domains), why we process it, and the rights you have over it. We have tried to write it plainly. Where it uses formal terms, those terms come from the GDPR.

Telepath is built around a simple idea: we should not be able to read your conversations, and we should not keep anything we do not need. This policy describes the data that the service does process so that it can function at all — and how little of it we hold on to.

The short version

This summary is for convenience only; the sections below are what actually govern.

Contents

1. Who is responsible for your data

The Telepath XMPP service is operated by FSKY, a non-profit tech collective established in Sweden ("we", "us", "our"). FSKY is the data controller for the personal data described in this policy.

The servers that run the service are located in the Netherlands. Both Sweden and the Netherlands are within the European Economic Area (EEA).

For any privacy question, or to exercise your rights, contact us at contact@telepath.im or over XMPP at admin@telepath.im.

2. What data we process

Account information

When you accept an invitation and register, we store:

Registration is invite-only. We do not ask for or store an email address, phone number, or real name.

Messages

So that your conversations stay in sync across your devices, the server keeps a recent archive of your one-to-one messages (XEP-0313 "Message Archive Management"). You can change what is archived — or turn archiving off entirely — from your XMPP client.

If you use OMEMO end-to-end encryption, anything stored in this archive is ciphertext that we cannot read. We strongly recommend it.

Group chats

Messages sent in group chats (MUC rooms hosted at room.telepath.im) are, by default, archived on the server so that participants can see recent history when they join. Presence information (who is online) is not logged. Anyone in a room can see the messages sent to it; if the room is public, that may include people you do not know.

Files and media

When you share a file or image, it is uploaded to our file-sharing service at hypertext.telepath.im (XEP-0363). Files can be up to 300 MiB. Anyone who has the file's link can download it for as long as it is stored, so treat a shared link as semi-public — unless you are sending the file inside an OMEMO-encrypted chat, in which case the file is encrypted on your device before upload and we only ever store ciphertext.

Profile, contacts, and settings

If you choose to set them, we store your profile and avatar (vCard / PEP), your contact list (roster), your bookmarks (the rooms you have joined), and your block list. This data exists to make the service work across your devices.

Connection and technical data

To run the service, keep it secure, and prevent abuse, our server and web-server software record technical logs. These can include IP addresses, timestamps, and connection or authentication events. We use these only for operating the service, diagnosing faults, and detecting abuse such as brute-force login attempts (which we also rate-limit automatically).

3. Why we process it, and our lawful basis

We do not profile you, run advertising, or sell data. We have no commercial interest in your information.

4. How long we keep it

When you delete your account, your messages, files, profile, and settings are removed according to the schedule above. The only thing retained is the tombstone described.

5. Who your data is shared with

We do not sell your data and we do not share it for advertising. Data leaves our servers only where the service itself requires it:

We may also disclose data if we are legally required to by a valid order under applicable law. We hold very little data and much of it can be end-to-end encrypted, so there is often little for us to give.

6. International transfers

Our servers and our hosting provider are within the EEA, so the data we store stays in the EEA. However, some of the optional flows described above can involve parties outside the EEA — for example a push-notification gateway, a federated server, or a bridged network may be located in another country. Where that happens it is an inherent part of how that feature or the federated network operates, and you can avoid it by not enabling the feature or not joining the bridged/remote room.

7. How we protect your data

8. Your rights

Under the GDPR you have the right to:

To exercise any of these, contact us at contact@telepath.im or admin@telepath.im. We will respond within the time limits set by the GDPR and we will not charge you for it.

If you believe we have mishandled your data, you have the right to lodge a complaint with the Swedish supervisory authority, the Integritetsskyddsmyndigheten (IMY)imy.se — or with the data protection authority in your own country.

9. Children

The service is not directed at children. You must be at least 13 years old to register an account. If you believe a child has given us personal data, contact us and we will remove it.

10. Changes to this policy

We may update this policy as the service evolves. When we make a material change we will update the date at the top of this page and, where appropriate, announce it through our usual channels. Continuing to use the service after a change means you accept the updated policy.

11. How to contact us

For anything in this policy, reach us at:

See also our XMPP Terms of Service.