Privacy notice
Draft published for review. Last updated 25 September 2026.
This page is a draft. It has not been reviewed by a lawyer and it is not final.
1. Who we are
KithMoot is run by ForgeSworn. For UK data protection law we are the controller of the personal data described here, to the extent described below: most of what happens in a room is not something we hold at all (section 2). Contact us about anything in this notice at abuse@safety.forgesworn.dev.
2. The short version
- KithMoot's rooms are end-to-end encrypted. We do not hold, and cannot read, your messages, your files, or your calls.
- Joining a room needs only its link. We do not run accounts, and most people never give us anything we would call personal data.
- Our default infrastructure (a TURN server, a file store, a drop tier, and, for rooms whose links name it, a relay we also run) sees connection-level information while helping your room connect or store a sealed file, and is designed to keep as little of it as possible.
- We keep no server-side account, session or membership record for a room. There is nothing to delete on request because there is nothing held.
- We do not sell your data, we do not show adverts, and we do not run analytics or tracking.
3. Things we never collect
- Your private key. Never sent to us in any KithMoot flow.
- Room content. Messages, files and call media are end-to-end encrypted; the traffic key lives in the room's own link, not on our servers.
- A membership list. There is no server-side record of who is in a room.
- Card or bank details. KithMoot has no payments functionality.
4. What our default infrastructure sees, and why
4.1 The default TURN server
When your call cannot connect device to device, your browser asks for a short-lived credential, then relays media through our TURN server if needed. Minting a credential needs no account or sign-in. The credential-minting service keeps an in-memory, per-IP rate-limit counter only, reset on every restart and never written to disk. During a relayed call, the TURN server necessarily sees both sides' IP addresses, because that is what a TURN relay does.
4.2 The default file store
A file you choose to drop into a room's chat, after you explicitly opt in to shared storage, is sealed in your browser first, then uploaded as an opaque encrypted blob. The store holds the encrypted bytes, their size, and the device key that signed the upload, never the file's name, type or contents. It is kept for up to 90 days from the blob's last fetch, sooner if storage is full.
4.3 The default drop tier
A bounded relay for one Nostr message kind, accepted from any connection with no authentication, used for quiet delivery. It deliberately keeps no index of who sent or who a delivery was for, so nobody, including us, can look up what belongs to whom. It is bounded by size (1 GiB by default) and a 30-day maximum age.
4.4 A relay we also run
The relays KithMoot suggests by default are independent public relays we do not operate. Until September 2026 one of the defaults was a relay we run, and a room whose link was written then still names it. On that relay we can see, for events that pass through it: event kinds, device public keys, opaque room selectors, timing and message size, never plaintext content, which is encrypted before it reaches any relay. A room's link shows which relays it uses, and a room's creator can remove that relay from them.
4.5 Access and error logs on our web server
Our web server is configured to discard access logs for the KithMoot site. Known gap, stated honestly: the automatic redirect from plain HTTP to HTTPS may still be recorded by the operating system's own connection logging even though the site's own access log is discarded. We have not independently verified this is fully suppressed, and we say so rather than claim a guarantee we have not checked.
5. How long we keep information
We hold almost nothing described in section 4 for long, by design: TURN rate-limit counters live in memory only; the default file store keeps a file up to 90 days from last fetch; the default drop tier keeps a delivery up to 30 days; and system logs on the box that runs our default services are bounded to two weeks, or 500 MB, whichever comes first.
We keep no server-side account record to delete, because we do not run accounts. If you have contacted us by email, that correspondence is kept for as long as we reasonably need it, and you can ask us to delete it (section 6).
6. Your rights
Because we hold so little that identifies anyone, most requests will come back "we do not hold that", which is itself the answer to a request, not a failure to respond to one. Where we do hold something identifiable to you, you can ask us to give you a copy, correct it, delete it, or restrict or stop using it. Write to abuse@safety.forgesworn.dev. We will answer within one month.
Content in a room. We cannot delete a message, a file, or a call from a room, because we never held it. If you want something removed from a room you are in, leave the room, ask a keeper who runs it to remove you or close it, or, for your own signed public events, use the in-app tool that asks relays to delete them.
You can complain to the Information Commissioner's Office (ico.org.uk). We would like the chance to put things right first.
7. Who else receives data
- Public Nostr relays, including the two independent defaults and any a room's creator adds, receive the ciphertext, device keys and timing any room necessarily produces to function.
- Our hosting provider, which hosts the box our default TURN server, file store, drop tier and relay run on.
We do not use an email marketing service, an analytics company or an error-tracking company for this site.
8. Children
KithMoot has not yet set a minimum age. We do not knowingly collect personal information from children, and in practice we hold almost no personal information from anyone (section 2). If you think a child has given us personal information through a report or an email, contact us at abuse@safety.forgesworn.dev and we will delete it.
9. Automated decisions
We make no decisions about you by automated means that have legal or similarly significant effects. Rate limits on default infrastructure slow or refuse requests automatically, for short periods, based on connection volume, not on anything about you personally.
10. Changes
If we change this notice, we will say so on the site.