Skip to content
xmpp.lt
Home Statistics Account Help LT

xmpp.lt

Privacy policy

Effective date: 2026-08-28

This policy explains how xmpp.lt (“we”) processes personal data when providing the xmpp.lt website and XMPP communication service.

Data controllerxmpp.lt
Contactadmin@xmpp.lt

1. Scope

This policy covers the xmpp.lt account website, connections to the xmpp.lt XMPP server, and features delivered through it. When you communicate with users on other XMPP servers, their operators process data under their own policies.

2. Data we process

  • Account data: your XMPP address, account status, creation and deletion dates, and authentication data processed by Prosody. The website does not retain submitted passwords.
  • Service data: contact lists, XMPP metadata needed for delivery and, when corresponding server features are used, queued or archived messages and uploaded files.
  • Recovery data: an optional email address, preferred language, verification status, and hashes of one-time links.
  • Technical and security data: IP address, request time, browser or XMPP-client technical information, error and security records, and rate-limit counters.
  • Legal acceptance: the accepted policy and terms version and time of acceptance.

3. Purposes and legal bases

We process account and communication data to create and authenticate accounts, deliver XMPP messages, provide recovery, and supply requested features. This is necessary to perform the service contract (GDPR Article 6(1)(b)). We process technical data, rate limits, and logs for our legitimate interests in securing and operating the service, preventing spam, and investigating incidents (Article 6(1)(f)). We may also process data when necessary to meet a legal obligation or establish and defend legal claims.

4. Recipients

Access is limited to service administrators and necessary infrastructure or email providers acting under contractual obligations. When Cloudflare Turnstile is used on registration, sign-in, and account-recovery forms, Cloudflare receives the IP address and browser and challenge signals needed to identify automated abuse; form-field contents are not sent to Cloudflare. See the Cloudflare Turnstile Privacy Addendum. When a recipient is hosted by another XMPP server, addressing and message data are transmitted to that server. We may disclose data to authorities when legally required. We do not sell personal data or use it for advertising profiles.

5. International transfers

XMPP is a federated network. If you choose a recipient outside the European Economic Area, the communication data needed for delivery may be transferred to their server in that country. Where applicable, transfers by our service providers use safeguards recognized by the GDPR.

6. Retention

  • Account data is held while the account is active. A deletion request disables the account immediately and schedules permanent deletion after 7 days.
  • A recovery email is held until changed, removed, or the account is deleted. Verification links expire after 24 hours and password-reset links after 30 minutes.
  • Website rate-limit records are normally removed within 2 days. Nginx access and error logs are ordinarily rotated within approximately 15 days.
  • Archive and file retention depends on the XMPP features used. Deleting an account cannot remove copies of messages already delivered to recipients or other servers.

Specific records may be retained longer when required to investigate a security incident, comply with law, or defend a claim. Residual backup copies are removed through the normal overwrite cycle.

7. Cookies and automated-abuse protection

The website uses an essential session cookie for authentication, CSRF protection, and secure account management. Cloudflare Turnstile performs a short-lived browser check on protected forms; if the operator enables Turnstile pre-clearance, Cloudflare may also set the essential cf_clearance cookie. We do not use advertising or visitor-analytics cookies.

8. Your rights

Under the GDPR, where applicable, you may request access, correction, erasure, restriction, portability, or object to processing based on legitimate interests. Contact admin@xmpp.lt. We may need to verify control of the account before acting.

You may also complain to the Lithuanian State Data Protection Inspectorate or the supervisory authority where you live.

9. Security and changes

We use access controls, encrypted transport, short-lived one-time links, and rate limiting. No internet service can guarantee absolute security. Material changes will be published on this page with an updated effective date.

xmpp.lt · Independent XMPP service
HelpPrivacy policyTerms of serviceXMPP compliance badge

Hosted by: FreeHosting.lt