1. What may be collected
Normal operation may create account records, login/session records, device identifiers, IP addresses, user-agent strings, request timestamps, room membership metadata, and content stored by the Matrix server.
If an email address is provided, it may be stored for account management. Email is not required unless a specific access flow says otherwise.
2. How data is used
Data is used for authentication, session management, abuse prevention, moderation, system stability, troubleshooting, security monitoring, and investigation of Terms violations.
3. Encryption and visibility
End-to-end encrypted rooms encrypt message content client-side. The server stores encrypted payloads but cannot read properly encrypted message contents.
Encryption does not hide all metadata. Room membership, timestamps, devices, IP/login records, and other operational metadata may still be visible. Unencrypted rooms and uploaded media may be visible to administrators.
4. Retention and backups
Retention varies by data type and configuration. Account records may remain while an account is active and may be retained for a limited period after deactivation for operational, administrative, abuse-prevention, or legal reasons.
Messages, media, operational metadata, logs, and backups may use different retention periods based on their purpose and configuration. Where retention is discretionary rather than required for security, technical operation, or law, community-wide retention defaults and data-lifecycle policies are established through RG Herd's community governance process rather than solely by infrastructure administrators. That process consists of a published proposal, a defined discussion period, a time-bounded community vote, a documented result, and publication or archival of the adopted policy. Individual rooms or independently operated deployments may use shorter retention periods or more restrictive data practices where technically supported. Backups may exist for disaster recovery, are not intended to function as permanent archives, and should use bounded and documented retention.
5. Security practices
RG Herd uses layered security practices including HTTPS/TLS, delegated authentication, access controls, infrastructure logging, rate limiting, abuse detection, and operational monitoring.
No system is immune to compromise. Users are responsible for protecting credentials, devices, encryption keys, and recovery material.
6. Disclosure
Data may be disclosed when required by valid legal process, necessary to prevent imminent harm, or necessary to protect system integrity. Requests for user data must comply with applicable law.
7. Contact, governance, and updates
Routine editorial, legal-reference, and technical corrections may be made administratively when they do not materially alter user rights or community data practices. Material changes to discretionary community-wide privacy, retention, or data-governance policy should follow the community governance process described above. Urgent security or legal changes may be implemented immediately when delay would materially increase risk. Administrators may rotate credentials or keys, invalidate sessions, block abusive traffic, patch systems, isolate services, or take other measures necessary to protect infrastructure or users without first holding a vote. Emergency action does not itself establish permanent community policy and should be documented and reviewed afterward when it materially changes ongoing policy. No community vote may require RG Herd to violate applicable law, disclose another person's private information, intentionally weaken necessary security controls, or prevent administrators from responding to an active security incident.