Last updated: August 23, 2026 Provider: Toskr L.L.C., a Wyoming limited liability company
This Privacy Policy explains what information Toskr L.L.C. ("Toskr," "we," "us") processes, why, how long we keep it, and the choices you have. It covers toskr.io, the Toskr account portal, and the hosted Matrix service we operate for our customers.
Toskr is offered to customers in the United States who are at least 18 years old. This Policy is written for U.S. law.
Toskr hosts a Matrix server for each customer. That means data falls into two buckets:
Account & billing
The hosted Matrix service
Technical & security
Analytics
toskr.io home and public pages) we use Google Analytics, and only after you accept the cookie banner. It never loads in your dashboard or on your chat server.Support, abuse & legal
To provide, operate, secure, and improve the Service; to authenticate accounts; to bill and prevent fraud; to provide support; to investigate and act on abuse; to comply with law and respond to lawful requests; and to keep minimal records the law requires. We process only what is reasonably needed for these purposes.
We do not sell your information. We do not use community content to build advertising profiles, serve targeted ads against it, or train general-purpose machine-learning models on it. Toskr personnel do not intentionally access plaintext community content except as described in our Terms §6 and §15 (e.g., you ask us to for support, it is necessary to operate or secure the Service, we investigate reported abuse, or the law requires it).
| Data | Retention |
|---|---|
| Client IP / last-seen | 90 days, then pruned |
| Redactions / forgotten-room state | 7 days |
| Remotely-cached (federated) media | 30 days |
| A customer's separate backup set (after cancellation) | 14 days, then deleted |
| Platform disaster-recovery snapshots | rolling, not exceeding 35 days; encrypted, and commingled across customers so an individual customer's data cannot be extracted from them |
| Account, billing, tax, security, abuse, and legal records | as long as reasonably necessary for the purpose or as required by law |
A legal-preservation duty (for example a valid government preservation request) can require us to keep specific data beyond these periods; see Terms §12.5 and §15.
We use a small set of service providers ("subprocessors") to run Toskr, each only for its function:
We also disclose information when required by valid legal process, to protect rights and safety, or in connection with a merger or sale of the business (subject to this Policy). See Terms §15 for how we handle legal and emergency requests, and our Transparency page.
Community messages can be end-to-end encrypted by member devices (keys we do not hold). Traffic to Toskr is encrypted in transit (TLS). Each customer's server runs in its own isolated environment. Off-site backups are encrypted with a key the backup system cannot itself decrypt. Access to production systems is restricted. No system is perfectly secure, and we cannot guarantee absolute security.
privacy@toskr.io and we will respond as required by applicable law. We will not discriminate against you for exercising a right.Toskr is intended for people 18 and older and is not directed to children. We do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact privacy@toskr.io.
Toskr is a U.S. business and currently serves U.S. customers, with infrastructure in the United States. We do not target the Service to people outside the United States. If that changes, we will update this Policy and add the notices those regions require.
We may update this Policy; each version carries an effective date. For material changes we will provide reasonable notice through the Service or by email.
Privacy questions: privacy@toskr.io
Mailing address: Toskr L.L.C., 30 N Gould St Ste N, Sheridan, WY 82801, United States