Source
Privacy policy — Element
Checked for Element on 15 Sep 2026
- Page
- https://element.io/privacy
- Checked
- 15 Sep 2026, 15:00 UTC
- How we may use it
- Public page, crawling permitted
Technical details
- type
- page
- http status
- 200
- content hash
- sha256:5acb058baff0f76b08f15b4362fe059a7cabe79e108ef53ae0dd0be644fd7cbc
- permission
- robots_ok
- screenshot
- Screenshot on file (internal exhibit, not published)
Cited by
Facts read from this source
-
Controller Report an error
“Where you read 'Element' or 'we' or 'us' below, it refers to Element, a trading name of Element Creations Ltd., its French subsidiary: Element Software SARL, its U.S. subsidiary: Element Software Inc, its German subsidiary: Element Software GmbH, and their agents. Element is the Data Controller for your data.”
-
Address Report an error
“Element c/o Element Creations Ltd 10 Queen Street Place London United Kingdom EC4R 1AG”
-
Customer ownership Report an error
“The Customer owns and controls all messages and files submitted to their homeserver by User accounts registered natively on their homeserver. This ownership does not extend to messages and files submitted over federation or bridging.”
-
Retention ip logs Report an error
“30 days, for Customer IP addresses; 180 days, for Element chat app IP addresses; 180 days, for rageshakes.”
-
Analytics matomo Report an error
“Our analytics are powered by the Free and Open Source analytics platform Matomo , hosted entirely within our network. The servers which host this data are located in London, United Kingdom. We don't share any analytics data with third parties.”
-
Analytics retention Report an error
“The mapping of this data is logged for 28 days - from this point on only aggregated data is kept, for operational and statistical purposes.”
-
Error reporting Report an error
“This information is collated in the application monitoring platform Sentry . Submitted error reports are kept for 180 days.”
-
Deletion retention Report an error
“Currently, when deprovisioning a server or redacting messages these are stored for 7 days before their permanent deletion. This includes all forms of media.”
-
ISO 27001 Report an error
“We also enable logs and have strict access control procedures, in accordance with ISO 27001:2022.”
-
Password storage Report an error
“We never store password data in plain text; instead they are stored hashed (with at least 12 rounds of bcrypt, including both a salt and a server-side pepper secret). Passwords sent to the server are encrypted using SSL.”
-
E2ee access Report an error
“Shared information is exclusively limited to what we are technically able to see, which means end-to-end encrypted information is never accessed by our teams or shared externally.”
-
CCPA addendum Report an error
“This California Consumer Privacy Act and California Privacy Rights Act Addendum ("CCPA and CPRA Addendum") supplements the Element Data Processing Agreement and any applicable Order Forms and Services Addenda (“Agreement”).”
-
Children privacy Report an error
“We never knowingly collect or maintain information in Element, through any of the Services provided, from those we know are under 18, and no part of Element is structured to attract anyone under 18.”
-
Data subject rights Report an error
“For completeness, your rights under GDPR are: The right to be informed The right of access The right to rectification The right to erasure The right to restrict processing The right to data portability The right to object Rights in relation to automated decision making and profiling.”
-
Aws regions Report an error
“Our admin server is hosted in an AWS data centre in Amsterdam; Our deployment server is hosted in an AWS data centre in Stockholm; Customer deployments have the option to select the geographical location which is the most convenient for them;”
-
Payment stripe Report an error
“Paying for hosted homeserver services is handled entirely by our payment processor, Stripe .”
-
Tax quaderno Report an error
“We use a third-party, Quaderno , to help us with tax automation within our billing system.”
-
Twilio 2FA Report an error
“For 2FA over SMS, we will require your phone number. This information will be shared with Twilio , a SMS service provider.”
-
Marketing Report an error
“This information will be stored on our marketing automation platform Salesloft and our CRM systems Salesforce , and will be processed in accordance with this policy. We also use Hubspot to manage our website analytics and marketing automation.”
-
Cloudflare Report an error
“We use Cloudflare to mitigate the risk of DDoS attacks.”
-
Livekit Report an error
“For ESS we use a self-hosted version of LiveKit by default within Element Call, although customers have the option to use LiveKit Cloud. For call.element.io we use LiveKit Cloud”
-
Maptiler Report an error
“The Element clients use the third-party service MapTiler to provide the images used to display maps.”
-
Location sharing Report an error
“We may collect location data on you, if you choose to use the static or live location sharing features within the Element app.”
-
Element call e2ee Report an error
“Element Call is end-to-end encrypted, therefore no additional data about calls is processed.”
-
Push tokens device bound Report an error
“The tokens generated by this function are not linked to a Matrix ID, but to a physical device instead”
-
Segmentation Report an error
“All of the Element user data resides within the same dedicated cluster. We use software best practices to guarantee that only the Customer can access it. In other words, we segment User data via software.”
-
Account data export Report an error
“If you are a customer of Element Matrix Services (EMS) you can access all personal information that we collect by using the account management interface at https://element.io You can download a copy of all your data as per section 2.1.3.”
-
Two factor auth Report an error
“You will be given the choice to set up 2-Factor Authentication to secure your account.”
-
Security disclosure Report an error
“If you have discovered a security concern, please email us at security@element.io.”
-
No profiling users Report an error
“We do not profile homeserver Users or their data, but we might profile metadata pertaining to the configuration and management of hosted homeservers so that we can improve our products and services.”
-
Supervisory authority Report an error
“you can contact the ICO (the statutory body which oversees data protection law in the UK) at https://www.ico.org.uk/concerns .”
1 fact read from this page is not shown because it could not be confirmed on the page as captured.
Scores citing this record
- The Compliance Counsel Encryption & access control
- The Compliance Counsel Retention, discovery & co-determination
- The Compliance Counsel European sovereignty
- The Compliance Counsel Encryption & access control
- The Compliance Counsel Retention, discovery & co-determination
- The Compliance Counsel Deployment & data custody
- The Compliance Counsel European sovereignty
- The Platform Engineer Encryption & access control
- The Platform Engineer Retention, discovery & co-determination
- The Platform Engineer European sovereignty
- The Platform Engineer Encryption & access control
- The Platform Engineer Retention, discovery & co-determination
- The Platform Engineer Deployment & data custody
- The Platform Engineer European sovereignty
- The Security Officer Encryption & access control
- The Security Officer Retention, discovery & co-determination
- The Security Officer European sovereignty
- The Security Officer Encryption & access control
- The Security Officer Retention, discovery & co-determination
- The Security Officer European sovereignty
- The Skeptic Encryption & access control
- The Skeptic Retention, discovery & co-determination
- The Skeptic Deployment & data custody
- The Skeptic European sovereignty
- The Skeptic Encryption & access control
- The Skeptic Retention, discovery & co-determination
- The Skeptic European sovereignty
- The Team Lead Encryption & access control
- The Team Lead Retention, discovery & co-determination
- The Team Lead European sovereignty
- The Team Lead Encryption & access control
- The Team Lead Retention, discovery & co-determination
- The Team Lead European sovereignty
- The Works Council Advocate Encryption & access control
- The Works Council Advocate Retention, discovery & co-determination
- The Works Council Advocate Deployment & data custody
- The Works Council Advocate European sovereignty
- The Works Council Advocate Encryption & access control
- The Works Council Advocate Retention, discovery & co-determination
- The Works Council Advocate Deployment & data custody
- The Works Council Advocate European sovereignty