Consort mobile app privacy policy

Draft: not yet in effect. This policy is still being written. Placeholders are shown in [BRACKETS].

Some statements describe the app as it will be once work in progress is finished, so they may not match the current version yet.

Effective date: [DATE]

This policy explains what the Consort app for Android does with your information. It covers the app only. Consort is a client: it connects to a chat server that you choose, and whoever runs that server decides what happens to the data stored there. Read your server’s own privacy policy for that.

The short version

  • We, the publishers of the app, receive none of your data. The app has no analytics, advertising, crash reporting or tracking of any kind, and it doesn’t send anything to us.
  • The app sends your messages, files and account details only to the server you log in to.
  • The only other services the app uses are push notifications and video calls. Both are described below.
  • We don’t sell or share personal information, because we don’t have any.

Information sent to your server

To work, the app exchanges information with the server you log in to:

  • Your login. Your email address or username, your password (or a sign-in through a service your server offers, such as Google or GitHub), and the API key the server issues when you log in.
  • What you do in the app. Messages you send, reactions, files and photos you upload, profile changes, and which messages you’ve read.
  • Activity status. Whether the app is open, so others can see you’re online, and when you’re typing. The app doesn’t send these when you’ve turned them off in your settings. Whether others can see that you’ve read their messages is also controlled by your settings on the server.
  • App and system version. Each request includes the app version and your Android version, so the server can stay compatible with the app. No device model, identifiers or other device information are sent.

Push notifications

To notify you of new messages, the app registers your device with a push notification service and gives your server the address it needs to reach you. Which service is used depends on how you installed the app.

Google Play version. The app uses Google’s Firebase Cloud Messaging (FCM). When the app starts, it registers with FCM, and Google issues a token that identifies this installation of the app. The app sends the token to your server, which may pass it on to the push service it uses. On servers that support it, the token and notification contents are end-to-end encrypted: Google and any push service in between can’t read your messages. Older servers may send notification contents unencrypted through these services. Google processes this information under its own terms: firebase.google.com/support/privacy.

F-Droid version. This version contains no Google or Firebase code.

UnifiedPush (both versions). If you’ve installed a UnifiedPush distributor app, such as ntfy, and your server supports it, notifications are delivered through that distributor’s push service. The contents are encrypted, so the service sees only when a notification arrives and how large it is.

Notifications show the sender, the conversation and the message text. Whether they appear on your lock screen is controlled by your device’s notification settings.

Calls

When you join a call, the app connects to the Jitsi video server your chat server uses, never to a default public one. Your server gives the call your display name and avatar. Audio and video go through the call servers your server’s operator has set up. The app doesn’t record calls.

Permissions

The app asks only for permissions it needs, and it asks for each one when it’s first needed:

Permission Why
Notifications To show new messages. Asked when you first open the app.
Camera To take a photo to send, and for video in calls.
Microphone For audio in calls.
Run in the background during calls To keep a call going while you use other apps.
Internet access and network status To reach your server, and to reconnect when your connection changes.

The app never asks for your contacts, location, calendar, phone state or general access to your storage. When you attach a photo or file, you pick it in Android’s own picker, and the app can see only what you pick. Files are uploaded only when you send them.

Content from other websites

Messages can include images, link previews and videos hosted on other websites. When you view them, the app loads them straight from those sites, which can see your IP address, as they would in a web browser. The app doesn’t send those sites your login or any other identifying information. Links you tap open in your browser.

Information stored on your device

The app stores the following on your device:

  • the address of each server you’re logged in to, your user ID and email address there, and the API key used to access your account
  • the keys used to decrypt your push notifications
  • your app settings, such as theme and browser preference.

Messages aren’t stored on your device; they’re loaded from your server each time. This data is excluded from Android backups and device transfers. Logging out of an account deletes that account’s information from the device, and uninstalling the app deletes all of it.

Your choices and rights

Because we don’t hold any of your data, there’s nothing for us to give you, correct or delete. For data on your chat server, including your account, messages and files, contact the person or organization that runs the server. You can:

  • log out to remove an account from your device
  • turn off notifications, or revoke any permission, in Android settings
  • use the F-Droid version to avoid Google services entirely.

Children

The app doesn’t knowingly collect any information from anyone, including children. Whether children may use a particular server is up to that server’s operator.

Changes to this policy

If the app’s handling of your information changes, we’ll update this page and its effective date before releasing the change.

Contact

[PUBLISHER NAME]
[CONTACT EMAIL]