Privacy Policy

Privacy is a good part of why this server exists in the first place. This page describes what data trustserv.de processes, why, how long it is kept, and what rights you have.

If anything here is unclear, please get in touch.

Who is responsible Link to heading

trustserv.de is operated by me, Oli, as a private individual. I am the controller for the personal data described below. You can reach me at the address on the Disclaimer page.

Website log files Link to heading

The web server keeps standard access logs containing IP address, browser type, and a timestamp. They are used solely to detect and respond to abuse, attacks, and security incidents โ€” a legitimate interest under Art. 6(1)(f) GDPR โ€” and are rotated and deleted weekly.

Mail accounts Link to heading

If you have a mail account here, the mail server logs connection and delivery metadata: envelope sender and recipient, timestamps, and delivery status. Message content is not logged. This is necessary to operate the service and to handle abuse, and follows the same weekly rotation as the web logs.

The contents of your mailbox are stored on disk for as long as your account exists. Nothing is deleted automatically โ€” managing and deleting your own mail is up to you as the account holder.

Incoming mail passes through a spam filter (Amavis and SpamAssassin) before delivery. This runs automatically on the server; results are not reviewed by hand.

Matrix homeserver Link to heading

If you use the Matrix homeserver, the following is stored: your account and display name, your avatar, the rooms you belong to, and the messages and files you send.

Most message content is stored encrypted. Matrix uses end-to-end encryption, which Element enables by default for direct messages and private rooms: your client encrypts the content before sending it, and what this server stores is ciphertext. The keys live on the participants’ devices only, never here โ€” so I cannot read those messages, and neither could anyone who obtained the database or a backup.

Two limits are worth knowing about. First, encryption is not universal: public rooms are typically unencrypted, and there the message content is stored in plain text and is readable by me. Element shows a shield icon in encrypted rooms, so you can tell the difference at a glance. Second, encryption covers content, not metadata. Who talked to whom, when and how often, which rooms you are in, and room names and topics are all stored unencrypted โ€” the server needs them to deliver messages at all.

Attachments follow the same rule: encrypted in encrypted rooms, plain in unencrypted ones.

There is also a limit that no homeserver can engineer away: I hold the account database and could in principle reset a password or attach a device. That would not decrypt past messages, and your contacts’ clients would flag the new device as unverified โ€” but it is the reason verifying devices in Element is worth the thirty seconds it takes.

Unlike mail, your Matrix data is not stored only here. Once a message reaches a federated room, copies exist on the homeservers of everyone in that room. I can delete your data on this server; I have no way to delete the copies held elsewhere. Please keep that in mind for anything sensitive.

Registration runs through a process I wrote myself and requires my approval.

Cookies Link to heading

trustserv.de sets a cookie only when you log in to PostfixAdmin or Roundcube, and that cookie is used exclusively on trustserv.de. If you disable cookies in your browser, a session ID is used instead.

There are no third-party advertising partners, tracking pixels, or analytics services involved with this site, and there never will be.

Backups Link to heading

Full backups are made roughly every three to six months and deleted after twelve months. This means that if you ask for data to be erased, it may still exist in an offline backup until that backup expires.

Hosting Link to heading

The server is rented from netcup GmbH and is located in Germany. netcup acts as a processor under Art. 28 GDPR, on the basis of a data processing agreement; they operate the hardware and network, and have no access to the services running on the machine beyond what physical and infrastructure operation requires.

No personal data is transferred to any country outside the EEA that does not benefit from an adequacy decision of the European Commission.

How long data is kept Link to heading

  • Web and mail logs: one week
  • Mailbox contents: until you delete them, or until the account is closed
  • Matrix data: until you delete it, or until the account is closed โ€” note that deletion on this server does not remove federated copies
  • Backups: up to twelve months

Your rights Link to heading

If you are in the EEA, the UK, or Switzerland, you have the right to access, rectify, erase, restrict, and port your personal data, and to object to processing based on legitimate interest. To exercise any of these, simply write to me โ€” there is no form and no ticket system, it lands in my inbox.

You also have the right to lodge a complaint with a data protection supervisory authority.

Changes to this policy Link to heading

This page is updated whenever the setup changes. The date shown above is the last revision.