Self-host template
Privacy
This page describes the privacy-oriented defaults in VoxHF. It is not a privacy policy for every server: each server is operated independently and its operator is responsible for publishing accurate information.
Operator action required
Before enabling account registration for other people, the server operator should replace this template with a notice identifying the operator, contact method, infrastructure providers, purposes, legal bases, retention periods and user rights that apply to that deployment.
Account data
A standard VoxHF relay stores the chosen username and display name, password hashes, hashed authentication and session identifiers, device and pairing records, and passkey public-key data when passkeys are enabled.
Live session data
During an active connection the relay routes radio and transponder state, callsigns, weather, messages, microphone audio and received voice between the local agent and authorised browsers. This data can include communications from other network participants.
Default non-persistence
VoxHF does not intentionally persist voice recordings, permanent chat history, raw FSD traffic, raw TS2 traffic or full authentication tokens. Audit persistence and application-level IP and user-agent storage are disabled by default.
Browser storage
The webapp uses necessary authentication cookies and local browser storage for device identity, pairing, theme, audio and connection preferences. Manual-token mode can store a relay token supplied by the user in that browser.
Default retention
Account and device records remain until deletion or revocation. Invitation codes normally expire within 24 hours and pairing codes within 10 minutes. Optional audit events default to 7 days when enabled. Recognised SQLite backups and pre-restore copies default to 30 days.
Independent servers
The VoxHF project cannot inspect or guarantee the configuration, security, availability or data practices of an independent server. Review the operator and server-specific notice before creating an account.
Project documentation
Technical privacy controls and self-hosting responsibilities are documented in the public source repository. Deployment-specific questions must be directed to the operator of the server you use.