Privacy Policy
Last updated: September 2026.
1. Who we are and what this covers
All0e is a video meeting, calling and messaging service operated by WebBoxes. This policy describes what we collect, where it is stored, and what we deliberately do not do. It covers the All0e website and the All0e Android app (package com.webboxes.all0e). Where we do not yet have a verified answer we say so instead of guessing.
2. Your account and profile
Your account is created and stored in our Supabase database.
- Your email address and a password hash, handled by Supabase Auth. We never see your password in plain text.
- Profile details you provide: display name, full name, an optional alias (handle), bio, location, a link, and a cover image.
- Operational preferences: interface language, time zone, and which notification categories you want.
- A Matrix user id on our own homeserver (for example @alex:matrix.all0e.com), which is how chat and calls are addressed.
- If you sign in with Google, Supabase Auth receives the identity information Google returns for the sign-in.
3. Messages and chat content — read this one
All0e does not use end-to-end encryption. Your chats are transported over an encrypted connection (TLS), but they are decrypted and stored in readable form on our own Matrix homeserver (Synapse) at matrix.all0e.com. That means message text, attachments, room names, and room history can be read by us and by anyone who has administrative access to our server. We cannot tell you that “nobody but you can read your messages”, because that would not be true. If you need end-to-end encrypted messaging, do not use All0e for that content.
- Messages and their attachments are stored on our infrastructure in readable form.
- Server administrators can access them, for example for moderation, abuse handling, or support.
- We do not currently offer an end-to-end encryption option.
4. Calls, meetings and screen sharing
Calls and meetings run over LiveKit, which is a selective forwarding unit (SFU): your audio and video are relayed through it to the other participants. LiveKit is part of our own infrastructure, not the other person's device.
- We do not record calls. All0e ships no recording feature, and the app has no way to record a call — so nothing is stored as audio or video.
- Call metadata is recorded: room identifiers, participant identities, and start and end events, retained in our database as call history and for diagnostics.
- Screen sharing is live only. What you share is sent to the other participants in the call and is not stored on our servers.
- While you share your screen, Android shows a persistent notification and keeps a screen-capture service running. It stops as soon as you stop sharing or leave the call.
5. Importing your contacts
The “Import contacts” feature in the app reads phone numbers and email addresses from your device address book, sends them to our server, and checks them against existing All0e accounts so we can show you which of your contacts already use All0e. Phone numbers are kept. This includes the phone numbers and names of people who do not have an All0e account and who have never agreed to anything — we are telling you plainly because that is the truth of how the feature works.
- Imported phone numbers and the contact name from your address book are stored in our database, linked to your account.
- Email addresses are used only for the matching lookup and are not stored by the import feature.
- People who are not All0e users can appear in that data. They can ask us to remove it: see contact details in section 17.
- Deleting your account removes your imported contacts with it.
- You can use All0e without ever importing contacts. The app only reads your address book after you choose to import and grant the permission.
6. Profile pictures are public
Avatars and cover images are stored in a public storage bucket. Anyone who knows or guesses the URL can load your profile picture without signing in. Do not upload a picture you would not be comfortable seeing published. You can remove your picture at any time from your profile, which removes it from the bucket.
7. Push notifications
To deliver notifications when the app is closed, All0e registers a push token for your device and hands it to Google.
- On Android, message notifications are delivered through Google Firebase Cloud Messaging (FCM), via our push gateway (Sygnal) connected to our Matrix homeserver.
- Friend requests and other in-app alerts are sent through FCM and Expo push as well.
- The token identifies the app installation, not you personally, but it is stored against your account and removed when you sign out or delete your account.
- Notification content shown on the lock screen is visible to anyone holding your unlocked-adjacent device; you can change this in Android's notification settings.
8. Analytics, and only if you allow it
On the website we use PostHog, hosted in the EU, to understand which features are used. It is off until you press “Allow analytics” in the banner, and pressing “Decline analytics” keeps it off. Essential cookies for signing in and security are used either way. The Android app does not send analytics events to PostHog today.
- You can change your analytics choice at any time from the cookie preferences link in the banner.
- We do not use analytics data for advertising, and we do not build advertising profiles.
9. Where your data is stored and who processes it
We keep the list of processors short and name them plainly.
- Supabase Cloud — our managed database host and processor: authentication, the Postgres database, and file storage (avatars, attachments). Your account, profile, friend graph, imported contacts, push tokens and call history live here.
- Synapse (Matrix), self-hosted on our own servers — chat rooms, message content and attachments.
- LiveKit, self-hosted on our own servers — call audio, video and screen media in transit only.
- Google Firebase Cloud Messaging — delivery of push notifications to Android devices.
- Expo push service — delivery of app-level push notifications.
- Our hosting provider (Coolify on a virtual private server) — runs the website and the services above.
10. What we do not do
Some promises are easier to keep when they are explicit.
- We show no advertising, and the app contains no advertising SDK or advertising identifier.
- We do not sell, rent, or trade personal data, and we do not share it with data brokers.
- We do not sell or share your data for cross-context behavioural advertising.
- We do not use your chats or calls to train advertising or recommendation models.
11. How long we keep things
Retention follows the feature, not a single number.
- Account and profile data: until you delete your account.
- Messages and attachments: until you delete them, the room is deleted, or your account is deleted.
- Imported contacts: until you delete your account.
- Call metadata and notification records: retained as operational history.
- Push tokens: removed when you sign out or delete your account.
- Backups: infrastructure backups are taken by our hosting and database providers on their own schedules, so data you delete may persist in a backup for a limited period before the backup ages out. We are still confirming the exact backup retention window with our providers, and we would rather say that than quote a number we have not verified.
12. Security, honestly stated
We protect the service with TLS for data in transit, row-level security rules in the database, and an app-private on-device media cache that keeps authorised media off the shared filesystem. We also have to be straight with you about the limit: because there is no end-to-end encryption, our own administrators can read stored message content. No system is perfectly secure, and we cannot promise absolute security.
13. Children
All0e is not intended for children. You must meet the minimum legal age for digital services in your region (at least 16 where that is the applicable threshold) to create an account. If we learn that a child has created an account, we will delete it.
14. Your choices, and deleting your account
You can delete your account at any time. The fastest way is in the app: open the Settings tab and choose the delete-account option on your profile screen; the same control exists on the website account settings page. Deletion removes your account and the data that cascades from it, including your profile, imported contacts and push tokens.
- You can also request deletion by writing to us through https://all0e.com/support or by emailing webboxes.com@gmail.com from the address on the account.
- Messages you sent in rooms with other people may remain visible to those other members, because they are part of a shared conversation.
- Depending on where you live you may also have the right to access, correct, restrict or export your data, and to object to processing. Ask us and we will help.
16. Changes to this policy
If we change how All0e handles your data, we update this page and change the date at the top. Material changes that affect what we collect or who we share it with will be announced in the product as well as here.
17. Contacting us
For any question about this policy, or to exercise a privacy right, contact us through https://all0e.com/support or by email at webboxes.com@gmail.com. All0e is operated by WebBoxes.