Privacy Policy for Palaver
// as of: 26 September 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Lars Gossard · lasse techSchleifmühlstraße 22
91456 Diespeck
Germany
Email: lars@lasse-tech.de
2. What this policy covers
Palaver is a voice, text and screen-sharing chat. It consists of the app (for Windows, macOS, Linux
and Android, and as a web client in the browser) and a Palaver server the app connects to. This
policy applies to the app and to the Palaver server I operate at palaver.mmfds.de.
Palaver servers can also be run by others. If you connect the app to someone else's server, its operator is responsible for the data processed there, and their privacy policy applies. The app sends your data only to the server you choose, and not to me in addition.
This policy also covers Dogan, my service that keeps track of how Palaver servers are doing (section 9) — including other people's servers whose owner agreed to report to Dogan.
3. The app itself
The app contains no advertising, no tracking, no analytics or telemetry, no crash reporting to third parties and no automatic update check. Fonts are built into the app; no content is loaded from third parties.
On your device, the app stores:
- the server address, your session token and your unlocked end-to-end encryption key — protected by the operating system's key store (Windows Data Protection API, macOS Keychain, Android Keystore, the Secret Service on Linux where available; encrypted in IndexedDB in the browser)
- your settings (language, theme, notifications, link previews, stream quality)
- other members' public signing keys, to detect forgeries
The web client sets no cookies. Local storage is strictly necessary for the service to work (§ 25 (2) no. 2 TDDDG). Signing out deletes the session; you remove the remaining data by uninstalling the app or clearing the site data in your browser.
Permissions
- Microphone — only for voice channels, while you are in one.
- Screen capture — only when you start a screen share yourself and pick a screen or window. The thumbnails in the picker stay on your device.
- Notifications — for new messages; they are created on your device, without any third-party push service (no Google Firebase, no Apple Push).
The camera is never used. The app does not read your location, contacts or other files.
4. Your account
For an account on the server, the following is stored:
- user name and display name (freely chosen; no email address, real name or phone number is collected)
- an optional profile picture (re-encoded on upload, which removes embedded metadata such as GPS data)
- time of registration, roles, and approval or ban where applicable
- the channel you last opened and read markers (up to which message you have read)
- your sign-in sessions (only as a hash of the token, with an expiry date)
Your password never leaves your device. The app derives a sign-in key from it locally; the server stores only a further hash of that key (Argon2id). It also stores your public keys and your private key in encrypted form, which only you can open with your password or a recovery code.
Your online status (online, away, etc.) is kept only in the server's memory and is not stored. The legal basis for account data is Art. 6 (1) (b) GDPR (providing the service you want to use).
5. Messages and end-to-end encryption
Text messages, reactions, direct messages and channel notices are encrypted and signed on your device. The server stores only the encrypted content and cannot read it — neither can I as the operator.
The exception is the public landing channel (“Allgemein” by default): messages, reactions and link previews there are stored on the server in plain text, because new members who have not yet been approved should be able to read it too.
Metadata is unavoidably visible to the server: who wrote in which channel and when, the approximate length of a message, what it replies to, who reacted how often, and who exchanges direct messages with whom.
6. Voice and screen sharing
Voice and screen shares go through a media server (LiveKit) that I operate myself on the same server. The transmission is encrypted in transit but not end-to-end encrypted; the media server forwards the streams to the other participants. Nothing is recorded and nothing is stored. While you are connected, your IP address, user ID and display name are processed.
The helper services for setting up the connection (STUN/TURN) also run on my own server. No third-party STUN or TURN servers are used.
The legal basis is Art. 6 (1) (b) GDPR.
7. Link previews
When you send a link, your app fetches the linked page to build a title, description and a small thumbnail. The linked website receives your IP address. People who only read the message fetch nothing, and neither does the server. The preview is encrypted like the message (except in the landing channel). You can turn link previews off in the settings. The web client does not create link previews.
8. Hosting and logs
The Palaver server runs on a server of IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany, in a data centre in Germany. A data processing agreement (Art. 28 GDPR) is in place with IONOS. Hosting involves no transfer to third countries.
The web server in front of it logs each request with IP address, time, requested address and browser identifier. These logs are deleted after 14 days at the latest, unless they are needed to investigate a specific case of misuse. The Palaver server software itself does not log IP addresses, only errors and operational events with numeric user IDs; the media server logs connections including user ID and connection address. These logs are also deleted after 14 days. To protect sign-in and registration against attacks, the server counts requests per IP address; this happens only in memory and is discarded after a short time.
The legal basis is Art. 6 (1) (f) GDPR. My legitimate interest lies in operating the service securely and reliably.
9. Contributing: server figures for Dogan
Dogan (https://www.lasse-tech.de/dogan/) is my service that keeps track of how Palaver servers are doing:
whether they run, which version they have and how much they are used. A Palaver server reports there
only if the server's owner agrees — Palaver asks them once when they sign in to
their server in the app — or if the operator sets the server up with Dogan themselves using a
one-time code. The app on your device sends nothing to Dogan; it is the server that reports. Only the
owner is asked; other members are not, because nothing about them is sent.
Once agreed, the server sends every minute:
- the server's name, public address, version and icon (the icon only when it changed), its start time, whether open registration is on, the media server's address, and details of the server software (Go version, operating system, architecture)
- numbers: accounts (and accounts waiting for approval), members online, in voice and sharing their screen (these four only as far as the owner releases them), voice channels, messages in the last 24 hours, storage used by attachments
- technical values: database response time and size, schema version, whether the media server answers, requests and server errors in the last five minutes, open connections
Never sent are names of members or channels, messages, files, members' IP addresses or anything else about an individual person. Dogan also checks the server from outside: whether its interface and media server answer, and how long their TLS certificates are valid. In doing so, Dogan learns the server's IP address.
The purpose is statistics about Palaver servers and improving Palaver's infrastructure, including detecting outages. This information can be personal data if a private individual runs the server (for example the server's name or address, its IP address). The legal basis is the owner's consent under Art. 6 (1) (a) GDPR; if the operator sets the server up with Dogan using a one-time code, that is their consent. Stored with it are when consent was given and which version of the consent text it was given to.
Withdrawal: The owner can stop contributing at any time in the app under settings → Server → Contribute (Art. 7 (3) GDPR). Dogan then deletes immediately and irrevocably all data the server has sent, including history and events; it cannot be restored. This does not affect the lawfulness of the processing up to that point. If Dogan cannot be reached at that moment, the server stops sending anyway and keeps asking for the deletion until Dogan confirms it. Withdrawal by email to lars@lasse-tech.de is possible as well.
While consent stands, Dogan keeps the per-minute values for 30 days, hourly summaries and events (such as outages, restarts, version changes) for one year, and daily summaries until the server stops contributing.
Public list of outposts
With a second, separate consent, the owner can also have their server shown on the public list at palaver.social/outposts.html. This requires sending figures to Dogan. Publicly visible are then the server's name, icon and address, whether it is running, its Palaver version, whether you can register without an invite, and the numbers of accounts, of members online, in voice and of streams. The owner releases these four one by one; what they do not release never leaves their server, not even towards Dogan, and the list shows a symbol in its place. The legal basis is Art. 6 (1) (a) GDPR. The owner can take the server off again at any time in the app under settings → Server → Contribute; it then disappears from the list within seconds. Stopping contributing altogether removes the entry as well. The list page loads the details from Dogan on the same domain; it sets no cookies and embeds nothing from third parties.
Dogan runs on a server of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, in a data centre in
Germany; a data processing agreement (Art. 28 GDPR) is in place with Hetzner. The data is not passed
on to third parties. Anyone running a Palaver server can also turn Dogan off entirely on their server
(PALAVER_DOGAN_URL=off); the owner is then not asked.
10. Retention and deletion
- Sessions expire after 30 days and are then deleted; when you sign out, immediately.
- Deleted messages lose their content and reactions immediately; only an empty placeholder with author and time remains, so the conversation stays coherent.
- Editing a message overwrites the previous version; no history is kept.
- Otherwise, messages remain stored until they or their channel are deleted.
-
You delete your account yourself in the app under Profile → Security → “Delete account” (also in
the web client at
https://palaver.mmfds.de); your password is required to confirm. This immediately deletes your account, sessions, profile picture, keys, roles, reactions and read markers. If you choose “Also delete all my messages”, your messages lose their content as well; otherwise they remain in the history without a name, as “Deleted account”. Alternatively, an email to lars@lasse-tech.de or a message to an admin of the server is sufficient.
11. Disclosure
Your data is not sold and not passed on for advertising. What Dogan receives is described in section 9. Other members of the server see what you post in channels they have access to, as well as your name, profile picture and online status.
12. Children
Palaver is not directed at children under 16. No proof of age is required.
13. Your rights as a data subject
Under the GDPR you have the following rights:
- access to the data stored about you (Art. 15 GDPR)
- rectification of inaccurate data (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- objection to the processing (Art. 21 GDPR)
To exercise your rights, an email to lars@lasse-tech.de is sufficient. Please note: I cannot read encrypted content and therefore cannot hand it out in plain text.
14. Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement.
15. Changes
If Palaver changes in a way that processes different data, I will update this policy. The version published here applies.
This English version is a convenience translation. In case of any discrepancy, the German version is authoritative.