Toskr Privacy Policy

Last updated: August 23, 2026 Provider: Toskr L.L.C., a Wyoming limited liability company

This Privacy Policy explains what information Toskr L.L.C. ("Toskr," "we," "us") processes, why, how long we keep it, and the choices you have. It covers toskr.io, the Toskr account portal, and the hosted Matrix service we operate for our customers.

Toskr is offered to customers in the United States who are at least 18 years old. This Policy is written for U.S. law.

1. Our two roles

Toskr hosts a Matrix server for each customer. That means data falls into two buckets:

2. What we process

Account & billing

The hosted Matrix service

Technical & security

Analytics

Support, abuse & legal

3. Why we process it

To provide, operate, secure, and improve the Service; to authenticate accounts; to bill and prevent fraud; to provide support; to investigate and act on abuse; to comply with law and respond to lawful requests; and to keep minimal records the law requires. We process only what is reasonably needed for these purposes.

4. What we do NOT do

We do not sell your information. We do not use community content to build advertising profiles, serve targeted ads against it, or train general-purpose machine-learning models on it. Toskr personnel do not intentionally access plaintext community content except as described in our Terms §6 and §15 (e.g., you ask us to for support, it is necessary to operate or secure the Service, we investigate reported abuse, or the law requires it).

5. How long we keep it

DataRetention
Client IP / last-seen90 days, then pruned
Redactions / forgotten-room state7 days
Remotely-cached (federated) media30 days
A customer's separate backup set (after cancellation)14 days, then deleted
Platform disaster-recovery snapshotsrolling, not exceeding 35 days; encrypted, and commingled across customers so an individual customer's data cannot be extracted from them
Account, billing, tax, security, abuse, and legal recordsas long as reasonably necessary for the purpose or as required by law

A legal-preservation duty (for example a valid government preservation request) can require us to keep specific data beyond these periods; see Terms §12.5 and §15.

6. Who we share it with

We use a small set of service providers ("subprocessors") to run Toskr, each only for its function:

We also disclose information when required by valid legal process, to protect rights and safety, or in connection with a merger or sale of the business (subject to this Policy). See Terms §15 for how we handle legal and emergency requests, and our Transparency page.

7. Security

Community messages can be end-to-end encrypted by member devices (keys we do not hold). Traffic to Toskr is encrypted in transit (TLS). Each customer's server runs in its own isolated environment. Off-site backups are encrypted with a key the backup system cannot itself decrypt. Access to production systems is restricted. No system is perfectly secure, and we cannot guarantee absolute security.

8. Your choices and rights

9. Children

Toskr is intended for people 18 and older and is not directed to children. We do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact privacy@toskr.io.

10. Where we operate

Toskr is a U.S. business and currently serves U.S. customers, with infrastructure in the United States. We do not target the Service to people outside the United States. If that changes, we will update this Policy and add the notices those regions require.

11. Changes

We may update this Policy; each version carries an effective date. For material changes we will provide reasonable notice through the Service or by email.

12. Contact

Privacy questions: privacy@toskr.io Mailing address: Toskr L.L.C., 30 N Gould St Ste N, Sheridan, WY 82801, United States

Privacy Policy — Toskr — Toskr