Privacy Policy
Last updated: November 30, 2025
TL;DR
We don't track you. Harmony is built with privacy as a core principle. We collect the minimum data necessary to provide the service. You can enable end-to-end encryption for private conversations. You can self-host for complete data sovereignty.
1. Introduction
This Privacy Policy explains how Harmony ("we," "our," or "the Project") collects, uses, and protects information when you use the official Harmony instance at har.mony.lol and the website at mony.lol.
If you are using a self-hosted or third-party Harmony instance, that operator's privacy policy applies instead of or in addition to this one.
2. Information We Collect
Account Information
When you create an account, we collect:
- Email address - For authentication and account recovery
- Username - Your chosen public identifier
- Profile information - Display name, avatar, bio (all optional)
Content You Create
We store content you create on the platform:
- Messages in servers and channels
- Direct messages (unless end-to-end encrypted)
- ActivityPub posts and interactions
- Uploaded files and media
Automatically Collected Data
Standard web server infrastructure may log:
- IP addresses (for security and abuse prevention)
- Browser type and version
- Access timestamps
These logs are used solely for security monitoring and are not used for tracking or analytics purposes.
3. What We Don't Collect
Harmony does not:
- Use third-party analytics or tracking services
- Sell or share your data with advertisers
- Create advertising profiles
- Track your activity across other websites
- Use cookies for tracking purposes
- Collect data from your device beyond what's needed for the service
4. Browser Storage
The Harmony web application uses your browser's local storage to improve your experience. This data stays on your device and includes:
- Authentication tokens - To keep you logged in
- User preferences - Theme, notification settings, etc.
- Encryption keys - For E2EE (never sent to our servers)
- Draft messages - Unsent message content
- Cache data - To improve performance
You can clear this data at any time through your browser settings.
5. End-to-End Encryption
Harmony offers optional end-to-end encryption (E2EE) using Matrix-compatible Megolm encryption. When E2EE is enabled:
- Messages are encrypted on your device before being sent
- Only you and the intended recipients can decrypt the content
- We cannot read encrypted messages, even with server access
- Encryption keys are stored only on your devices
Important: If you lose your encryption keys and haven't set up key backup, encrypted message history cannot be recovered by anyone, including us.
6. Federation & Data Sharing
Harmony supports ActivityPub federation, which means some of your data may be shared with other servers in the fediverse:
- Public posts - Distributed to your followers' instances
- Profile information - Shared with instances where you have followers
- Direct messages to federated users - Transmitted to their instance
We cannot control how federated instances handle your data. Check their privacy policies for information about their practices.
Non-federated content (server messages, local DMs) stays on our servers and is not shared with other instances.
7. Data Retention
We retain your data as follows:
- Account data - Until you delete your account
- Messages - Until deleted by you or the content owner
- Server logs - Automatically rotated (typically 30 days)
When you delete content, we remove it from our active systems. Backups may retain deleted data temporarily as part of standard disaster recovery procedures.
8. Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate information
- Delete your account and associated data
- Export your data (data portability)
- Object to certain data processing
To exercise these rights, contact us through the official Harmony platform or GitHub repository.
9. Self-Hosting Option
For maximum privacy, you can self-host your own Harmony instance. When self-hosting:
- You control all data storage and retention
- You choose your own privacy policies
- Data never touches our servers
- You're responsible for your own compliance with applicable laws
Self-hosting documentation is available in our GitHub repository.
10. Security
We implement reasonable security measures to protect your data:
- HTTPS encryption for all connections
- Secure password hashing
- Regular security updates
- Access controls and monitoring
As an open-source project, our security practices can be audited by anyone. We encourage security researchers to responsibly disclose vulnerabilities.
11. Children's Privacy
Harmony is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of material changes by posting the updated policy on this page and updating the "Last updated" date.
13. Contact
If you have questions about this Privacy Policy or your data, please contact us through our official channels on the Harmony platform or via our GitHub repository.