Privacy Policy
How we handle your data
Data we collect
We collect the email address you use as your mttrly account identity, plus the information needed to operate login, verification, account recovery, passkeys, and approval security. If you choose Telegram sign-in or connect Telegram as an approval channel, we collect your Telegram user ID, username, and first name for that channel. This includes authentication token metadata and security audit records. Server connection data (host, SSH keys) is stored encrypted. We do not sell your personal data.
Email and account identity
mttrly may create an account using your email address without requiring Telegram. We store a normalized version of your email address so we can identify your account consistently. We use email for account identity, login, verification, and recovery-related communication.
Magic links and auth tokens
Email login and verification use one-time links. mttrly stores a SHA-256 hash of the token and related metadata, such as purpose, expiration time, consumed time, email or user association, IP hash, and user agent. The raw token is not stored in the database, and tokens have a limited lifetime.
Passkey credentials
If you register a passkey, mttrly stores the public key and technical metadata needed to verify future dashboard approval and passkey assertions, such as credential ID, transports, friendly name, sign count, timestamps, and revocation state. Your biometric data, PIN, private key, and device secret stay on your device or authenticator. mttrly cannot recover or decrypt your private key.
Security and audit events
We may record email, security, and authentication audit events, such as email verification, magic-link requests and use, passkey registration and use, Telegram linking, and approval-related security events. We use these records for account security, fraud prevention, and debugging access issues.
Email preferences
Sign-in and account emails are transactional. Marketing email is opt-in only and can be unsubscribed at any time. We keep consent evidence, verification state, unsubscribe state, and delivery suppression events so we can honor your communication preferences.
Account recovery
If you lose access to both your email and your passkeys, contact [email protected]. Recovery may require manual verification that you own the account. We review recovery requests case by case and do not promise automatic account restoration or a specific response time.
Right to erasure (GDPR)
If you request deletion of your personal data, your request is registered and processed by our team. Data is deleted within 30 days. You will receive a 2FA confirmation in the dashboard or your connected messenger before deletion. To request deletion, use the API endpoint DELETE /api/consent/data with 2FA confirmation, or contact support.