← All help articles

What MatrixHost can and cannot see

Which of your data is end-to-end encrypted, what the server needs to know, and where your data lives.

For: everyone

Your team chats on your own private Matrix server, hosted in the EU (Germany). Here is, in plain words, what is protected and how.

What we cannot see

  • Encrypted messages. Direct chats and private rooms are end-to-end encrypted by default. The messages are locked on your device and only unlocked on the devices of the people in the chat. We cannot read them.
  • Your recovery key. Only you have it. That's also why we cannot recover it if it gets lost.
  • Encrypted files you send in encrypted chats, such as photos and documents.

What your server needs to know

To deliver messages, your server keeps some basic information, for example:

  • the accounts on your server (username, display name),
  • which rooms exist and who is in them,
  • when messages are sent.

Messages in rooms where encryption is turned off are not end-to-end encrypted.

Special cases

  • Bridges (WhatsApp, Signal, Telegram, …): the bridge on your server passes messages between Matrix and the other app. On the Matrix side, bridged chats are end-to-end encrypted. See Bridges.
  • The AI assistant: messages you send to @ai are processed by an AI model so it can answer you. See AI and your data.

Backups and location

  • Your server is backed up every day. Backups are encrypted and stored in the EU. See Backups.
  • A data processing agreement (DPA) is included in every plan.

For details, see our privacy policy at https://matrixhost.eu/privacy.

Related

Still stuck? Ask in the chat at the bottom right, or reply to your support email.

Last updated 2026-10-07