Privacy Policy
Last updated: 2026-06-28
Graf is a private messenger built on the Matrix protocol. Privacy is the product. This policy explains what Graf does and does not collect.
What we collect
- Account: a username you choose. No phone number is required. Email is optional and used only for account recovery.
- Messages and media: end-to-end encrypted. They are stored on the homeserver only in encrypted form; we cannot read them. Encryption keys never leave your devices except as an encrypted key backup that only your Recovery Key can unlock.
- Operational metadata: to deliver messages, the homeserver necessarily processes data such as which accounts are in a conversation and timestamps. We minimize retention and do not sell or share this data.
What we do NOT collect
- No analytics, no tracking, no advertising identifiers, no behavioral profiling.
- No access to your contacts/address book. Finding people is by username or share link only.
- We cannot read your message content (it is end-to-end encrypted).
Federation
Graf is part of the Matrix network. If you message someone on another homeserver, the metadata required to deliver those messages is shared with that homeserver, which has its own policies.
Notifications
Push notifications carry only a reference to a message, not its content. Your device fetches and decrypts the message locally. Message content is never sent in cleartext through Apple's push service.
Data retention and deletion
You can delete your account from within the app (Settings). Deleting your account removes your profile and deactivates your identity on the homeserver.
Your data, your server
You can run Graf against your own Matrix homeserver instead of graf.chat. In that case your data lives on your server under your control.
Contact
Questions or abuse reports: privacy@graf.chat