Vommet diagnostics privacy
Vommet can send diagnostics so we can find what's slow or broken, for example why sending a photo takes a minute on one computer. It's off unless you say yes, and you can change your mind any time in Settings › Privacy. This page covers only these diagnostics.
What is and isn't collected
Collected, if you say yes
- How long things take: starting up, syncing, opening a room and loading older messages, each step of sending a file, joining a call
- Sizes and counts: file size and picture dimensions, how many rooms and accounts, call length and number of people in it
- Whether something worked, and if not, what kind of error (for example "timeout" or "server said too large"), and the server's standard error code from a fixed list (like
M_FORBIDDEN), never its message - When the app crashes: the error's type and where in Vommet's code it happened
- In encrypted chats: how many messages couldn't be decrypted when you opened the room and when you left it, how many were unlocked while you were there, and whether a "retry decryption" worked (counts only, never the messages)
- On Android, why the app was last closed (for example a crash, low memory, or you closing it)
- When your microphone, camera or screen sharing fails to start: what kind of device it was (built-in, USB, Bluetooth…) and how many there are, never their names
- How smooth the app runs (frame rate summary) and memory use
- Your device in broad terms: Windows, Linux, Android…, the system version number, Vommet's version, number of CPU cores
- The file type of things you send (like
image/jpeg), and whether the chat it happened in is encrypted (yes or no, not which chat)
Never collected
- Your messages, in any chat, encrypted or not
- Your voice messages, or the audio or video of your calls and screen shares
- Your photos, videos or files, or previews of them
- File names
- Names or IDs of people, rooms, spaces or servers
- Your Matrix account or password
- Error message text (it can quote what you wrote)
- Your contacts or who you talk to
- Your IP address (see below)
How "never" is enforced
We don't rely on promises alone. Every report must match a fixed list of fields, and each field can only hold a number, a yes/no, a choice from a fixed list, or a location in Vommet's source code. There is no field that can hold free text, so there is nowhere for a message, a file name or a name to go. Vommet checks every report against this list before sending it, and our server checks again and rejects anything that doesn't match.
The list is public: proxy.nether.im/telemetry/schema. The code that does the checking is in Vommet and vommet-proxy.
You can see exactly what is sent
Settings › Privacy › What's been sent shows every report your device sent since Vommet started, exactly as it left your device.
Who receives it, and for how long
- Reports go to
proxy.nether.im, a server run by the Vommet maintainers. They are read only by the people working on Vommet, to fix problems. They are not sold, shared or used for advertising. - Reports are filed under a random ID created on your device, not under your Matrix account. You can find this ID in Settings › Privacy, and share it with us if you want us to look at your reports when you report a problem.
- Diagnostics are pseudonymous, not anonymous. They don't contain your account or anything you wrote or shared, but they do contain exact details such as a photo's file size, when it was sent, how long a call lasted and what device you use. Someone who also runs the server could match those details to your activity, for example to a particular upload or call, and in a small group of testers your device details alone may single you out. We don't do this to snoop. We may use it, for example, to line up your diagnostics with our server logs when you report a problem.
- Our server does not store your IP address. Like the rest of nether.im, it sits behind Cloudflare, which necessarily sees your IP address to deliver the request.
- Reports are deleted automatically after 30 days.
Stopping and deleting
- Turn diagnostics off in Settings › Privacy. Nothing more is sent, and anything waiting to be sent is thrown away.
- Delete my diagnostics in the same place asks our server to delete everything sent from your device, then starts over with a new ID.
Questions
Ask in #vommet:nether.im or open an issue.