Privacy notice
Last updated 4 October 2026
Crocodile is built so that we can't read what you say: messages and voice are end-to-end encrypted and travel directly between the people talking. This notice explains what the servers we run do see, why, and for how long.
Who we are
This website, the server directory at crocodilechat.com and the coordination server at coord.crocodilechat.com are run by the Crocodile maintainer (GitHub user @pwalda), who is the controller for the data described here. Contact: privacy@crocodilechat.com.
Anyone can run a Crocodile coordination server. Servers run by other people are responsible for their own handling of data; this notice covers only ours.
What we never get
- The content of your messages or calls. It is end-to-end encrypted, also when it passes through our mailbox or relay.
- A phone number, email address or password: Crocodile doesn't ask for any.
- Your address book or contacts outside Crocodile.
This website
The website sets no cookies and has no analytics, ads or trackers, and loading it contacts no one but us. When you press the download button, your browser asks GitHub for the latest release and then downloads it from GitHub, so GitHub sees that request. Like any web server, ours sees your IP address and browser when you visit; it keeps access logs for at most 14 days, only to keep the site running and secure.
The app and our coordination server
To connect you with your friends, the coordination server stores and handles the following. Most of it is signed by your device so servers can't forge it, but it is not hidden from the server.
| Data | Why | How long |
|---|---|---|
| Your public profile: name and number tag, and your avatar and bio if you set them. Your public keys and the names of your devices. | So friends can find you and so their apps can encrypt for you. | As long as your account exists. |
| Your friends and blocked list, the spaces you're in, their names, channels and members, and invites. | So your devices and your friends' devices stay in sync. | As long as your account exists, or until you change them. |
| Whether you're online, which voice room you're in, and when you connect. | To show presence and to choose who hosts a call. | Only while you're connected. |
| Your IP address, and connection setup data passed between you and the people you call (which includes IP addresses). | To connect you, and to limit connections per address against abuse. | Kept in memory while you're connected. Addresses that exceed the connection limit appear in server logs, kept for at most 14 days. |
| Mailbox (only if you turn it on): direct messages for friends who are offline, sealed so only their devices can open them. We see who sent one to whom, when, and how big it is. | To deliver messages while your friend is offline. | Until delivered, at most 3 days. |
| Relay (only if you turn it on): your already-encrypted call and message traffic. We see its size and timing, not its content. | For networks that block direct connections. | Passed through live, at most an hour at a time; nothing is stored. |
Other servers. Coordination servers form a network, and the records in the first two rows are copied to the other servers in it so that people on different servers can reach each other. Those servers may be run by other people. The server directory lists those servers; it doesn't store anything about you.
Who you talk to directly. Calls and messages go straight to the other people, or to the member who hosts a group call. They see your IP address, as with any peer-to-peer connection. The host also sees the size and timing of the encrypted audio and who is speaking.
Other services the app contacts. The app checks GitHub for updates. It contacts no other third party: even the small connection tests (STUN) that tell it what kind of network you're on go to the coordination server.
Legal basis
- If you use our servers, we process your data to provide the service you asked for (Article 6(1)(b) GDPR).
- If you use another server, our coordination server keeps copies of your records, as every server in the network does, for our legitimate interest, which we share with you, in running a network where people on different servers can reach each other (Article 6(1)(f)).
- We keep logs and enforce connection limits for our legitimate interest in keeping the service secure and free of abuse (Article 6(1)(f)).
We don't sell data, use it for advertising, or share it with anyone except as described above, or when the law requires it.
Your rights
You can ask us for a copy of the data we hold about you, to correct it, or to delete it. You can also object to or restrict how we process it. Most of your data you can change yourself in the app. Your profile, friends list and space records are signed by you and kept by every server in the network, so we can't delete them for you on our own: a copy we deleted would come back from the other servers. Deleting your account removes them everywhere. Data only we have, such as our logs, we delete on request.
Deleting your account takes a moment in the app: Settings → Profile → Delete account. Our server then immediately erases your devices, friends list, memberships and any mail waiting for you, and so does every other server in the network as the deletion reaches it. Spaces you own are deleted for everyone. What remains is a "Deleted user" marker with your account ID and public keys, and a "Deleted space" marker for each space you owned, so they can't be brought back. Messages you sent stay on the devices of the people who received them. To delete an account you can no longer sign in to, restore it with your recovery key first.
You also have the right to complain to your data protection authority.
Age
Crocodile is not meant for children under 16, or the minimum age for online services in your country if that is higher.
Changes
If this notice changes, we'll update the date at the top. Big changes will also be announced in the app's release notes.