Wizard Skin Privacy Policy
Effective May 31, 2026. Last updated August 16, 2026.
This policy describes the data handled by a Wizard Skin instance. Each self-hosted operator controls its deployment and should identify itself, its contact information, retention practices, and service providers to its users.
1. Information the service handles
Wizard Skin may handle:
- account identifiers, username, display name, email, password hash, profile About text, pronouns, avatar, and account-security state;
- private one-way Contact relationships and block relationships;
- conversation membership and preferences such as pin, archive, mute, unread, delivery, and read state;
- message content or encrypted message packages, quoted-reply pointers, synced drafts, reactions, expiry settings, and attachments;
- call signaling and operational call metadata, but not call media relayed through the application when peer-to-peer calling succeeds;
- Pocket notes, files, categories, shares, access limits, and storage metadata;
- announcements, notification preferences, push subscriptions, and dismissals;
- location information you deliberately share, plus login/security location metadata when enabled;
- reports, moderation actions, support/audit records, device keys, sessions, request logs, IP addresses, user agents, and operational metrics.
Wizard Skin no longer provides posts, stories, feeds, spaces, follows, forms/campaigns, promotions, loyalty/points, business accounts, games, weather, news, or personal-calendar features.
2. How information is used
Information is used to provide and synchronize chats, contacts, Pocket, calls, notifications, announcements, account recovery, security, moderation, abuse prevention, support, backups, and service operations. Optional GIF, map, AI, push, email, object-storage, and realtime providers receive only the information needed for the feature you or the operator enables.
AI chat tools may send selected draft text or user-directed context to a configured AI provider. Do not submit secrets or sensitive information unless you understand and accept that provider's terms.
3. Encryption and private communications
An operator chooses one message security mode:
- End-to-end mode stores opaque per-recipient packages and relies on account/device keys. The server still handles metadata such as participants, timing, delivery state, reply pointers, and encrypted package identifiers.
- Top-down mode decrypts content on the server when needed to provide the service and encrypts stored content using operator-managed keys.
Encryption reduces risk but cannot prevent a recipient from copying content, a compromised endpoint from exposing it, or authorized access required for operations, support, safety, or law. Drafts follow the active message mode. Client conversation search keeps decrypted text and search terms in browser memory and does not upload search terms.
4. Sharing and disclosure
Information may be disclosed:
- to recipients and people you explicitly share Pocket items or location with;
- to the instance operator, moderators, and support personnel when reasonably needed for security, troubleshooting, moderation, account recovery, or legal compliance;
- to infrastructure providers used for hosting, databases, storage, email, push, maps, GIFs, AI, metrics, and realtime delivery;
- when required or permitted by law, legal process, safety needs, rights enforcement, or a business transfer.
Wizard Skin is not designed to sell personal information or to deliver advertising. It does not use Contact relationships as a public social graph.
5. Retention and deletion
Retention depends on operator settings, message expiry, user actions, backups, audit requirements, and applicable law. Leaving a conversation removes the leaving user's unsent synced draft. Deleting an account or content may not remove copies held by recipients, active shares, backups, security logs, moderation records, or legal holds immediately.
6. Your choices
Settings let you control profile discoverability, who may start a new chat, message/call/announcement push, blocks, encrypted devices, sessions, appearance, and account deletion. You may add or remove Contacts privately, mute or leave conversations, revoke Pocket shares, and dismiss announcements.
Contact the instance operator to request access, correction, export, deletion, restriction, or other rights available where you live. The operator may need to verify your identity and may retain information where legally permitted or required.
7. Children, security, and changes
Wizard Skin is not directed to children under 13. Minors who may legally use the service should do so only with required guardian permission and supervision.
No online service is perfectly secure or always available. Do not use Wizard Skin for emergencies, regulated recordkeeping, or information whose loss or exposure would be unacceptable. Material policy changes should be announced in the application and reflected by a new update date.