Privacy Policy
Last updated 29 September 2026 · Applies to the Shack apps and shackmessenger.com
- Your organisation's data lives in its own workspace — its own database, files and keys, never shared with another customer.
- Host it yourself and you hold every key. We never see your server.
- Let us host it and we run the server, not your conversations. We do not access your workspace's contents in the course of business.
- No ads, no analytics, no trackers, and we never sell data or use it to train AI.
- Who holds your data
- If we host your server
- If you host it yourself
- What the apps collect
- What we never do
- Calls
- Notifications
- Encryption
- AI features
- Service providers
- This website
- How long data is kept
- Your rights
- Deleting your account
- Children
- Changes
- Contact
1. Who holds your data
Shack runs in one of two ways, and they give different answers to "who holds my data".
| How it's set up | Who runs the server | Who holds the keys |
|---|---|---|
| Self-hosted (one-time licence) |
Your organisation, on its own hardware or cloud account | Your organisation — every one. We have no access and no copy. |
| Hosted by us (subscription) |
Us, on your organisation's behalf, as its own isolated workspace | Generated for your workspace alone and held on servers we operate — see §2 |
If you use Shack at work, your organisation is in charge of your data: it decides what is kept, for how long, and who inside it can see it. Your administrator's own policy governs your data; this page describes what the software does and what we do.
2. If we host your server
When your organisation chooses our hosting subscription, we set up and run a Shack server for it. Our job is the infrastructure — keeping the server running, secure, updated and backed up. Your conversations are your organisation's business, not ours.
Your workspace is yours alone
- It runs as its own isolated stack: its own database, its own file storage and its own secret keys. Nothing is shared with any other customer.
- The keys that protect it are generated for your workspace when it is created and are never reused for another.
We do not access your contents
We do not read your messages, open your files, or listen to your calls. To run the service we see only operational information: that your workspace exists, its size and version, how many seats are in use, and technical logs when something breaks.
The only times we would access a workspace's contents are:
- when your organisation asks us to — for example, to help with a support problem you describe to us;
- when the law requires it, in which case we will tell your organisation unless the law forbids us to; or
- to stop an active security threat to your workspace or the service.
Said plainly: because we operate the servers, we have the technical ability to reach them — that is true of any hosted service. What keeps your data private on our hosting is this commitment and your contract with us, not an impossibility. If your organisation needs to hold every key itself, so that no access by us is possible at all, choose self-hosting — the same software, on infrastructure you control.
Where it runs
Hosted workspaces run in France, in the European Union, in a data centre operated by Contabo GmbH.
Backups
We back up each workspace every night. Backups are encrypted before they are written and kept for 35 days, then deleted.
Leaving
If your subscription ends, your workspace becomes read-only and its owner can export everything. The workspace is then deleted, and its encrypted backups expire within 35 days. We keep no other copy.
3. If you host it yourself
On a self-hosted server, you control the server and you hold every key: the database, the files, the encryption keys and the backups are all on infrastructure you choose. We do not receive your users' names, email addresses, messages, files or any other content, and we have no way to.
By default a self-hosted server sends us nothing at all. If your administrator chooses to connect it to our licensing service, it sends once a day only your licence key, the number of seats in use, and the software version — never content, never user details.
4. What the Shack apps collect
The iOS, Android, desktop and web apps send data to the server your organisation uses. That server stores:
Account and profile
- Email address, display name, and an optional
@handle - Optional profile picture, short bio and status
- Department and job title, where an administrator sets them
- Your role: owner, admin or member
Your conversations
- Messages you send and receive, including replies and reactions
- Files, images, audio and video you attach, and voice messages you record
- Messages you pin, save, or schedule; reminders you set; tasks you assign or receive
Presence
- Whether you are online, away or in do-not-disturb
- Your working hours and your device's time-zone offset — the offset only, never your location
Security records
- Sign-in events: time, success or failure, IP address, and device or browser type — so an administrator can investigate a compromised account
- Access log: which conversations and files were opened, by whom and when — required where an organisation handles health data
- Brief diagnostics when a call fails
Notifications
- A push token for each device you sign in on, plus its platform and app version, used only to wake that device
Your calendar, if you connect one
- You can connect a calendar by pasting its private read-only
.icsaddress. The server then fetches it and posts your day's agenda into your own private feed, which only you can see. - The address is encrypted at rest and never shown again, not even to an administrator. We ask for a read-only link rather than a Google or Microsoft sign-in, so the server never holds a credential that can reach the rest of your account.
The apps do not ask for your location, your contacts, your phone number, or access to your photo library beyond the files you choose to share.
Stored on your device
To open instantly and work offline, the apps keep a copy of your recent conversations on your device, in plain text. Signing out or removing the app erases it.
5. What we never do
- The apps contain no advertising, no analytics and no tracking software.
- We do not sell or rent personal data.
- We do not profile you, build advertising audiences, or follow you across other apps and websites.
- We do not use your content to train AI models.
6. Calls
Voice, video and screen sharing travel directly between the people on the call, end-to-end encrypted with DTLS-SRTP. Call audio and video never pass through the Shack server. Where two devices cannot connect directly, a relay may forward the encrypted media — it cannot decrypt it.
To find a direct route, each device asks a STUN server for its own public network address. By default that is Google's public STUN server, which therefore sees your device's IP address when you join a call — nothing else, and never the call's contents. An administrator can replace it with their own.
7. Notifications
Notifications reach your phone through Apple's or Google's push service. By default they contain no content: just "You have a new message" or "Incoming call" — no text, and not who sent it.
If you turn on message previews in your settings, the preview text and the sender's name are included, and so pass through Apple or Google to reach your lock screen. That is your choice, per person, and off until you turn it on.
8. Encryption
- In transit: everything between the Shack apps and a server is encrypted with TLS (HTTPS). The iOS, Android, desktop and web apps connect only over HTTPS and refuse a server that doesn't offer it, whether it's our hosting or a self-hosted server.
- Calls: end-to-end encrypted, as described in §6.
- Attachments at rest: can be encrypted on disk with AES-256. This is a setting of the server; the key is held by whoever runs it.
- Passwords are stored hashed, never in readable form. Two-factor sign-in, single sign-on and network restrictions are available, and administrators can require them.
- Backups on our hosting are encrypted, as described in §2.
Said plainly: message text is stored on the server without end-to-end encryption. On self-hosting that server is your organisation's, so its administrators can read messages. On our hosting it is operated by us, under the commitments in §2. Shack does not yet offer end-to-end encrypted messaging; calls, as above, are end-to-end encrypted.
9. AI features
AI features are off unless your administrator turns them on. When they are on, the administrator chooses where the processing happens: on your device, on your organisation's own server, or through an AI provider they select. In that last case the text being processed is sent to that provider, under its terms. Shack never uses your content to train AI models.
10. Service providers
We use a small number of providers to run the service. None may use your data for their own purposes.
| Provider | What for | What they receive |
|---|---|---|
| Contabo GmbH (Germany) | Servers for our hosting, in France | Hosted workspaces, stored on their infrastructure. Hosted customers only |
| Brevo (France) | Sending email — invitations, password resets, account notices | The recipient's address and the email itself. Hosted customers, and self-hosted servers configured to use it |
| Google (Firebase Cloud Messaging) | Waking Android devices for notifications and calls | A device token and a notification — content-free unless you turn previews on (§7) |
| Apple (Push Notification service) | The same, for iPhone and iPad | The same |
| Google (STUN) | Helping call devices find a direct route | Your device's IP address when you join a call (§6) |
| Stripe | Taking payment, if you buy from us online | Your payment details, directly — we never see your card number |
11. This website
When you request a workspace or buy a licence on shackmessenger.com, we collect your organisation's name and domain, your name, your email address, the number of seats and your plan, and the IP address the request came from, which we use to stop abuse. We use these to set up and administer your account, to contact you about it, and to invoice you.
This site uses no analytics and no tracking cookies. It loads its typefaces from Google Fonts, so your browser connects to Google, which sees your IP address. The Shack apps do not — they carry their own fonts.
12. How long data is kept
On self-hosting your administrator decides. The defaults the software ships with, which our hosting uses:
| Data | Kept for |
|---|---|
| Messages and files | Until deleted by their author or an administrator, or until the workspace is closed |
| Sign-in events | Until the account is deleted |
| Access log (health-data organisations) | Six years — the documentation period for health data. Configurable |
| Call diagnostics | Seven days |
| Push tokens | Until you sign out on that device or remove the app |
| Backups, on our hosting | 35 days |
| Your account with us (this website) | While you are a customer, and afterwards only as long as tax and accounting law requires |
13. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict its processing, and to complain to a data-protection regulator.
For data in a Shack workspace, ask your organisation first — it controls that data. If your organisation uses our hosting, it can instruct us, and we will act on its instructions. For data we hold about you as our own customer, contact us directly (§17).
14. Deleting your account
You can delete your own account from inside Shack: Settings → Account → Delete my account. You confirm with your password, then follow a link we email you. Nothing is deleted until you follow that link, and it expires after 24 hours.
What is deleted
Your profile and photo, name, email address, handle, password, two-factor setup, devices and push tokens, sign-in history, saved items, reminders, scheduled messages, diagnostic reports and personal settings. Your email address is released, so you can sign up with it again later.
What is kept, and why
Messages and files you shared into your organisation's conversations remain — they are its records and part of other people's conversations. They are shown as from "Deleted user" rather than from you.
You can delete your own messages at any time, so remove anything you want gone before deleting your account. The app does not yet let an administrator remove other people's messages; to have specific content removed, ask your administrator — on a self-hosted server they can do it directly, and on our hosting they can instruct us to.
Where your organisation operates under HIPAA, the access log required by §164.312(b) is kept. Your name is removed from it; the entries themselves cannot be deleted without defeating the purpose of an audit log.
Can't use the app? Ask your administrator to remove your account, or email support@shackmessenger.com with the workspace address and your email, and we will pass it to your organisation or, on our hosting, act on your organisation's instruction.
15. Children
Shack is a workplace tool for adults. It is not directed at anyone under 18, and we do not knowingly collect data from children.
16. Changes
If this policy changes materially we will update the date at the top and, where the change affects you, tell you in the app or by email before it takes effect.
17. Contact
Questions, requests or complaints about privacy: support@shackmessenger.com.
For data held in your organisation's Shack workspace, contact your own administrator first — your organisation controls that data.