Back to log inOrmbel

Privacy Policy

Last updated 2026-07-10

This page explains what data OrmbelCord collects and why. We collect the minimum needed to run a chat app — no ad tracking, no data resale.

1. What we collect

  • Account data: email, username, password (hashed with Argon2id — we never see or store your plaintext password), and avatar.
  • Content: messages, attachments, and reactions you send in servers and DMs, so they can be delivered and displayed to other participants.
  • Moderation records: reports you file, and moderation actions taken on your account within a server (kick/ban/timeout, with reason if given) are kept in that server’s audit log for accountability.
  • Technical data: IP address is used transiently for rate-limiting (anti-spam/anti-raid) and isn’t stored long-term alongside your messages.
  • Voice/video/screen-share: media streams are relayed end-to-end via LiveKit with encrypted transport (DTLS-SRTP); we don’t record calls.

2. OrmbelAI

If you DM OrmbelAI (the built-in assistant), the last ~20 messages of that conversation are sent to the configured AI provider to generate a reply. Nothing else in your account is shared with it.

3. How we use your data

Solely to operate the service: authenticating you, delivering messages in real time, showing your servers/DMs/friends, enforcing rate limits and content filters, and handling moderation/reports. We don’t sell your data or use it for third-party advertising.

4. Who can see your data

Messages in a server are visible to other members of that server; DMs are visible only to participants. Server owners/admins/mods can see reports and audit-log entries within their own server, not across other servers.

5. Data retention & deletion

Deleted messages are soft-deleted (hidden immediately, not shown to anyone) and periodically purged. You can delete your account from account settings, which removes your profile and personal data per our standard retention process.

6. Security

Passwords are hashed with Argon2id. Sessions use httpOnly, SameSite cookies with refresh-token rotation and reuse detection. All traffic is served over TLS. Every action is authorized server-side — client-reported roles are never trusted.

7. Your choices

You can update or delete your account at any time, block other users, and report content you believe violates our policies (see Trust & Safety).

8. Contact

Questions about this policy, or a data request: abuse@ormbelcord.codes.