Last updated August 2026
Privacy Policy
This policy describes the hosted degenerates service at degens.agency, a product developed by ORIA OU.
Overview
degenerates is a private messaging app built on Matrix. We use your data to provide messaging, account access, security, support, and service operations. We do not sell your data, run ads, use tracking SDKs, require contact upload, or provide a public user directory.
Data We Process
- Display name: chosen by you, visible to people you chat with, changeable, non-unique, and separate from your Matrix ID.
- Matrix account ID: an opaque server-generated identifier used to route messages and operate rooms.
- Passkey credential ID: stored so your device can authenticate. Passkey private keys are not extractable by us.
- Encrypted key-backup records: room keys may be backed up to the hosted service as encrypted ciphertext under a key derived from your passkey on your device. The hosted service does not receive the backup key.
- Messages, media, invites, room membership, and related metadata: processed by the hosted Matrix service to provide messaging. In encrypted rooms, message and media content is encrypted on your device before it reaches the hosted service; the service routes and stores encrypted payloads and related metadata, not plaintext message content.
- Device and session data: Matrix device IDs, access tokens, push tokens, E2EE device keys, and sync state needed for login, encryption, notifications, and account operation.
- Optional location messages: processed only when you choose to send a location message. degenerates does not use location for discovery or background tracking.
- Support email: collected only if you contact support.
- Operational logs: limited service logs for reliability, abuse prevention, security investigation, and debugging.
Data We Do Not Require
Hosted degenerates signup does not require a phone number, email address, legal name, password, contact upload, advertising identifier, or public profile directory listing.
Encryption And Recovery
Network traffic uses HTTPS/TLS. Matrix encrypted rooms use device-held keys and are intended to keep plaintext message content unavailable to the hosted service. V1 includes passkey-PRF encrypted key backup for supported room keys, but recovery is exactly as durable as the passkey and its sync. If the passkey is lost, a sole device is wiped, history predates backup, or required room keys are missing, older encrypted history may remain unrecoverable.
The app checks signed Matrix device material before using it for encryption setup, but the app does not currently include an in-app SAS/cross-signing device-verification flow. Do not treat encrypted-room membership as proof of a contact's identity.
Notifications
Push notifications are routed through Apple's APNs service. Encrypted-room notifications are designed to stay generic and event-id-only for V1, without decrypted message previews.
Link Previews
Link previews are setting-controlled and default off or manual. If you choose to load a preview, your device may contact the linked third-party site to fetch metadata.
Storage And Retention
Hosted service data is currently operated in AWS eu-west-2. Messages and room data follow Matrix room behavior. Uploaded media (images, videos, voice messages, files) is stored in encrypted-at-rest object storage and is automatically expired after 180 days. Account data is retained until you delete your account, except for limited operational, backup, security, or legal retention.
Your Choices And Rights
You can request access, correction, export, or deletion help by contacting degenerates@degens.agency. Actual account deletion is handled in-app with passkey re-authentication when you can access the app.
Children
degenerates is not intended for children under 13. We do not knowingly collect data from children.
Contact
Email degenerates@degens.agency.