Privacy Policy
What Yeetline holds about you, for how long, and who can see it — and what it cannot read, which is everything you send.
1. Who Is Responsible
Yeetline operates Yeetline at https://yeetline.com and is responsible for the personal data this server holds. This policy says what that is, why it is held, for how long, and who can see it.
2. What the Server Cannot Read
Messages, files, call audio and video are encrypted on the device that sends them and decrypted only on the devices that receive them. The server stores and forwards ciphertext and holds no key that can open any of it, even with complete access to its database and its disks. That is not a policy we could change by editing this page; it is how the software is built, and it is described in full in the application's documentation.
3. What the Server Holds
What any messaging server must hold to work, and no more:
- Your account — your username, the public half of your identity key and the one-time keys other devices use to start a conversation with you, an email address if you chose to add one, and — if you set them up — the secrets that verify a second factor, your passkeys, and your recovery codes (stored hashed).
- Your devices — a label for each device you have signed in on, its keys, and when it was last seen.
- Sign-ins — the network address and browser or app each sign-in came from, kept for 30 days. It exists so a suspension can cover the addresses behind it and so you can recognise your own devices.
- Messages — the encrypted form of each message, with what any relay must see to deliver it: who sent it, which conversation it belongs to, when, and how large it is. Not its content, and not the names of anyone mentioned in it.
- Files — the encrypted form of each file you send, its size, who uploaded it and which conversation it belongs to. Not its name, its type or its content — those travel inside the encryption.
- Rooms — which rooms you are a member of, and any room role you hold.
- Presence — whether you are online right now, shown to the people you share a room or a conversation with, and not stored.
- Profile — a display name and a profile picture, if you set them. The picture is published to everyone signed in to this server and cannot be recalled from anyone who has kept a copy.
- Push subscriptions — if you turn notifications on, the address your browser's push service gave us for this device. What we send through it is a wake-up with no content in it.
- Staff records — an audit trail of what administrators and moderators do (kept for 365 days), and a server log that records connections, errors and rate-limit events by address.
4. How Long
These are the windows this server is actually configured with; the operator can change them, and this page changes with them.
| Messages | until you or the room's moderators delete them |
|---|---|
| Files | 30 days |
| Sign-in addresses | 30 days |
| Staff audit trail | 365 days |
| Account, keys, devices, rooms | until you delete the account, or a staff member does |
Deleting your account removes your account record, keys, devices, room memberships and the encrypted files you uploaded. Encrypted messages you sent stay in the conversations you sent them to until their own retention window ends, as a letter stays with the person you sent it to.
5. Who Can See It
We do not sell, rent or share what the server holds with anyone, and no analytics or advertising service is loaded by the app. The parties that can see something are these:
- The people you talk to see your username, display name, picture, presence and — of course — what you send them.
- Staff (administrators and moderators) see your account details, your devices, the addresses you signed in from, how much storage you use and the audit trail; they cannot see message or file content.
- Your browser's or phone's push service (Apple, Google or Mozilla, depending on the device) receives the content-free wake-ups described above.
- A call relay, if this server runs one, forwards call audio and video between devices that cannot reach each other directly. The media is encrypted end to end; the relay sees the addresses and the volume of traffic.
- Google, if you sign in with a Google account, learns that you signed in to this service and when; we receive your Google account's identifier and email address and nothing else.
- A mail provider, if you have an email address on your account, delivers the notices we send you — welcome, new-device and role-change notices, and second-factor codes. The provider sees the address and the message.
- Any network or CDN in front of this server sees your address and the encrypted connection, as any network does.
6. Why We Hold It
Everything above is held to run the Service you asked for — to deliver your messages, keep your account yours and let you sign in from more than one device — and to keep the Service safe: rate limits, suspensions and the staff audit trail exist so abuse can be stopped and so what staff do is on record. We do not profile you and make no automated decisions about you.
7. Your Rights and Choices
You can see and change your profile, your devices and your second factors from your settings, sign out any device, and delete the account outright. Where the law where you live gives you rights to access, correct, export or erase personal data, or to object to its use, you can exercise them by contacting us; we will answer within the time the law allows. You may also complain to the data-protection authority where you live.
8. Security
Beyond the encryption itself: connections are TLS-only, passphrases never leave the device, second factors and passkeys are available and can be required, sign-in is rate-limited by address, and staff actions are audited. No system is perfect; if you find a problem, the application's documentation says how to report it.
9. Children
The Service is not directed at children under 13, and we do not knowingly hold data about them. If you believe a child has created an account, contact us and it will be removed.
10. Changes to This Policy
The current version is always the one at https://yeetline.com/privacy. A material change will be announced through the Service before it takes effect.
This page is generated by the software from this deployment's settings, so what it promises is what the server does. It is a starting point, not legal advice: the operator should have it reviewed by counsel before relying on it.