Vommet diagnostics privacy
Vommet can send diagnostics so we can find what's slow or broken, for example why sending a photo takes a minute on one computer. It's off unless you say yes, and you can change your mind any time in Settings › Privacy. This page covers only these diagnostics.
What is and isn't collected
Collected, if you say yes
- How long things take: starting up, syncing, opening a room and loading older messages, each step of sending a file, joining a call
- Sizes and counts: file size and picture dimensions, how many rooms and accounts, call length and number of people in it
- Whether something worked, and if not, what kind of error (for example "timeout" or "server said too large"), and the server's standard error code from a fixed list (like
M_FORBIDDEN), never its message - Once per session and for each signed-in account (numbered 1st, 2nd and so on, never which account), whether notifications can work: which notification system the app uses, whether it has permission, whether a push app and a push registration with your homeserver exist, whether "mute everything" is on, and how many of your rooms are unread, muted or set to mentions only. Yes/no answers and counts only, never the push address or which rooms
- How many notifications Vommet handled since the last report, and what happened to them: shown, shown quietly (for example because you were chatting in that room on another device), or not shown and why (that room was open, Do Not Disturb, notifications turned off, or another rule), plus how long handling them took. Counts only, never which rooms, who sent them or what they said. These counts are kept on your device until they're sent, only while diagnostics are on, and are deleted when you turn diagnostics off
- Which experiments you have switched on, by their internal code names (for example
vommet_experiment_forward_messages), so we can tell when a feature is ready to leave the Experiments page - When the app crashes: the error's type and where in Vommet's code it happened
- In encrypted chats: how many messages couldn't be decrypted when you opened the room and when you left it, how many were unlocked while you were there, and whether a "retry decryption" worked (counts only, never the messages)
- On Android, why the app was last closed (for example a crash, low memory, or you closing it)
- When your microphone, camera or screen sharing fails to start: what kind of device it was (built-in, USB, Bluetooth…) and how many there are, never their names
- How smooth the app runs (frame rate summary) and memory use
- Your device in broad terms: Windows, Linux, Android…, the system version number, Vommet's version, number of CPU cores
- Your name tag, only if you type one in (see below)
- The file type of things you send (like
image/jpeg), and whether the chat it happened in is encrypted (yes or no, not which chat)
Never collected
- Your messages, in any chat, encrypted or not
- Your voice messages, or the audio or video of your calls and screen shares
- Your photos, videos or files, or previews of them
- File names
- Names or IDs of people, rooms, spaces or servers
- Your Matrix account or password
- Error message text (it can quote what you wrote)
- Your contacts or who you talk to
- Your IP address (see below)
How "never" is enforced
We don't rely on promises alone. Every report must match a fixed list of fields, and each field can only hold a number, a yes/no, a choice from a fixed list, or a location in Vommet's source code. There is no field that can hold free text, so there is nowhere for a message, a file name or a name to go. Vommet checks every report against this list before sending it, and our server checks again and rejects anything that doesn't match.
The list is public: proxy.nether.im/telemetry/schema. The code that does the checking is in Vommet and vommet-proxy.
You can see exactly what is sent
Settings › Privacy › What's been sent shows every report your device sent since Vommet started, exactly as it left your device.
Who receives it, and for how long
- Reports go to
proxy.nether.im, a server run by the Vommet maintainers. They are read only by the people working on Vommet, to fix problems. They are not sold, shared or used for advertising. - Reports are filed under a random ID created on your device, not under your Matrix account. You can find this ID in Settings › Privacy, and share it with us if you want us to look at your reports when you report a problem.
- Diagnostics are pseudonymous, not anonymous. They don't contain your account or anything you wrote or shared, but they do contain exact details such as a photo's file size, when it was sent, how long a call lasted and what device you use. Someone who also runs the server could match those details to your activity, for example to a particular upload or call, and in a small group of testers your device details alone may single you out. We don't do this to snoop. We may use it, for example, to line up your diagnostics with our server logs when you report a problem.
- Our server does not store your IP address. Like the rest of nether.im, it sits behind Cloudflare, which necessarily sees your IP address to deliver the request.
- Reports are deleted automatically after 30 days.
Optional name tag
Under the diagnostics switch you can type a name tag, for example the name you go by in the testers' chat, so we know which reports are yours and can group them across your devices. It's empty unless you fill it in. Vommet never fills it in for you from your Matrix account or display name.
- With a tag, your reports are not anonymous: the developers will know they're yours. Leave it empty to stay pseudonymous.
- It can only contain up to 32 letters, numbers, spaces,
-and_. Both Vommet and our server reject anything else. - The tag is sent with every report while it's filled in. Clearing it stops tagging new reports. Reports already sent keep their tag until they're deleted after 30 days, or until you use Delete my diagnostics.
- Use the same tag on each of your devices if you want them grouped. Deleting is per device: Delete my diagnostics removes everything sent from that device, tagged or not, but not reports from your other devices. Use it on each device.
Stopping and deleting
- Turn diagnostics off in Settings › Privacy. Nothing more is sent, and anything waiting to be sent is thrown away.
- Delete my diagnostics in the same place asks our server to delete everything sent from your device, including reports with your name tag, then starts over with a new ID.
Questions
Ask in #vommet:nether.im or open an issue.