HarmonyHarmony
  • Download
  • Features
  • Hosting
  • Federation
  • Privacy
  • Developers
Log In
Legal

Privacy Policy

Last updated: November 30, 2025

TL;DR

We don't track you. Harmony is built with privacy as a core principle. We collect the minimum data necessary to provide the service. You can enable end-to-end encryption for private conversations. You can self-host for complete data sovereignty.

1. Introduction

This Privacy Policy explains how Harmony ("we," "our," or "the Project") collects, uses, and protects information when you use the official Harmony instance at har.mony.lol and the website at mony.lol.

If you are using a self-hosted or third-party Harmony instance, that operator's privacy policy applies instead of or in addition to this one.

2. Information We Collect

Account Information

When you create an account, we collect:

  • Email address - For authentication and account recovery
  • Username - Your chosen public identifier
  • Profile information - Display name, avatar, bio (all optional)

Content You Create

We store content you create on the platform:

  • Messages in servers and channels
  • Direct messages (unless end-to-end encrypted)
  • ActivityPub posts and interactions
  • Uploaded files and media

Automatically Collected Data

Standard web server infrastructure may log:

  • IP addresses (for security and abuse prevention)
  • Browser type and version
  • Access timestamps

These logs are used solely for security monitoring and are not used for tracking or analytics purposes.

3. What We Don't Collect

Harmony does not:

  • Use third-party analytics or tracking services
  • Sell or share your data with advertisers
  • Create advertising profiles
  • Track your activity across other websites
  • Use cookies for tracking purposes
  • Collect data from your device beyond what's needed for the service

4. Browser Storage

The Harmony web application uses your browser's local storage to improve your experience. This data stays on your device and includes:

  • Authentication tokens - To keep you logged in
  • User preferences - Theme, notification settings, etc.
  • Encryption keys - For E2EE (never sent to our servers)
  • Draft messages - Unsent message content
  • Cache data - To improve performance

You can clear this data at any time through your browser settings.

5. End-to-End Encryption

Harmony offers optional end-to-end encryption (E2EE) using Matrix-compatible Megolm encryption. When E2EE is enabled:

  • Messages are encrypted on your device before being sent
  • Only you and the intended recipients can decrypt the content
  • We cannot read encrypted messages, even with server access
  • Encryption keys are stored only on your devices

Important: If you lose your encryption keys and haven't set up key backup, encrypted message history cannot be recovered by anyone, including us.

6. Federation & Data Sharing

Harmony supports ActivityPub federation, which means some of your data may be shared with other servers in the fediverse:

  • Public posts - Distributed to your followers' instances
  • Profile information - Shared with instances where you have followers
  • Direct messages to federated users - Transmitted to their instance

We cannot control how federated instances handle your data. Check their privacy policies for information about their practices.

Non-federated content (server messages, local DMs) stays on our servers and is not shared with other instances.

7. Data Retention

We retain your data as follows:

  • Account data - Until you delete your account
  • Messages - Until deleted by you or the content owner
  • Server logs - Automatically rotated (typically 30 days)

When you delete content, we remove it from our active systems. Backups may retain deleted data temporarily as part of standard disaster recovery procedures.

8. Your Rights

You have the right to:

  • Access your personal data
  • Correct inaccurate information
  • Delete your account and associated data
  • Export your data (data portability)
  • Object to certain data processing

To exercise these rights, contact us through the official Harmony platform or GitHub repository.

9. Self-Hosting Option

For maximum privacy, you can self-host your own Harmony instance. When self-hosting:

  • You control all data storage and retention
  • You choose your own privacy policies
  • Data never touches our servers
  • You're responsible for your own compliance with applicable laws

Self-hosting documentation is available in our GitHub repository.

10. Security

We implement reasonable security measures to protect your data:

  • HTTPS encryption for all connections
  • Secure password hashing
  • Regular security updates
  • Access controls and monitoring

As an open-source project, our security practices can be audited by anyone. We encourage security researchers to responsibly disclose vulnerabilities.

11. Children's Privacy

Harmony is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of material changes by posting the updated policy on this page and updating the "Last updated" date.

13. Contact

If you have questions about this Privacy Policy or your data, please contact us through our official channels on the Harmony platform or via our GitHub repository.

HarmonyHarmony

Federated chat that's all fun & freedom. Connect with friends across the fediverse while keeping your data yours.

Harmony

Product

  • Download
  • Features
  • Hosting
  • Federation
  • Privacy

Developers

  • Bot API
  • Plugin Docs
  • Discord Bridge
  • Self-Hosting

Community

  • GitHub
  • Official Server
  • Discord Bridge
  • Blog

Legal

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • DMCA
  • Open Source

© 2026 Harmony. Open source under AGPL-3.0.

Made with ❤️ for the federated web