§Privacy

Privacy policy.
Short, because there is little to say.

Effective 2 October 2026. This policy covers the Onset desktop app for Windows, published by Fırat Karakaş (“the developer”, “we”).

The short version

The app sends nothing to the developer, and the developer runs no servers. Onset has no accounts of its own, no analytics, no advertising and no crash reporting. The app talks only to the servers you choose to add. Whatever you send to one of those servers is handled by that server and by whoever runs it, not by the developer.

What the developer collects

Nothing through the app. The app does not send any data to the developer, and the developer operates no service that receives data from the app. We do not sell data, share data for advertising, or build profiles of users.

If you email us, we receive your email address and whatever you write. Mail to [email protected] is forwarded by Cloudflare Email Routing to the developer’s mailbox. We use it only to answer you, do not share it, and will delete it if you ask.

Servers you connect to

Onset is a client for Onset Host, a server that you or someone you know runs on their own Windows PC. When you add a server and sign in, the app sends the following to that server:

  • Your account details: a username, a password (the server stores it only as a bcrypt hash) and, if you set them, a display name and an avatar image.
  • Your messages, replies, edits and deletions in text rooms and direct messages, and any files you upload.
  • Your voice during calls, and screen shares with their audio, which the server relays to the other people in the room. Voice is encrypted between your PC and the server, and screen sharing uses DTLS-SRTP, but the server decrypts and re-encrypts voice for each listener. Onset is not end-to-end encrypted.
  • Presence and state: whether you are online, in a room, speaking, muted or deafened, and pings that you send to other people.
  • Call diagnostics, described below.
  • Your network address, which any server necessarily sees when you connect to it.

The person who runs a server (the “server owner”) can technically access everything stored on it, including accounts, messages and files, and can read its call diagnostics. The server owner decides who may register, who moderates, and how long data is kept (by default, indefinitely). They are responsible for their server and for how they handle your data. Only join servers run by people you trust. To have your data removed, or to ask how a server handles it, contact that server’s owner; the developer cannot see or delete data on someone else’s server.

Call diagnostics

While you are in a call, the app records technical statistics every five seconds and sends them in batches to the server you are connected to, so its owner can troubleshoot call quality. They contain counters (packet counts, loss, buffer depth, jitter, and the frame rate and resolution of screen shares), your audio device names and audio settings (such as echo cancellation and input mode), the app version, the platform, and the room and account identifiers that belong to the call. They never contain audio, video, message text or file names.

You can turn this off in Settings > Call diagnostics. The server owner can also switch recording off on the server, and by default the server keeps these records for 30 days. Only the server owner can read them. Nothing is sent to the developer.

What stays on your device

  • Settings and remembered servers. Your preferences, the list of servers you added, and the identity fingerprint of each server (the app uses it to detect a server whose certificate changed) are stored in your Windows user profile, in the app’s data folders.
  • Your sign-in. The app remembers your session so that you do not have to type your password every time. This token is protected with Windows DPAPI, which ties it to your Windows user account. Signing out removes it.
  • Logs. The app keeps a local log. It leaves your device only if you choose to export it and send it to someone yourself.
  • Microphone and screen. The app uses your microphone only for calls and microphone tests, and captures a window or screen only when you start a share through the Windows picker. Neither is recorded by the app.

Messages and files are stored on the servers, not on your PC. When you uninstall the app, Windows removes the app’s own data. If anything remains in your profile (for the direct-download edition: %APPDATA%\com.onset.desktop and %LOCALAPPDATA%\com.onset.desktop), you can delete it yourself.

Updates

  • Microsoft Store edition. Updates are delivered by the Microsoft Store, and the app does not check for updates by itself. Microsoft’s privacy statement applies to the Store.
  • Direct-download edition (the installer from GitHub). The app checks for new versions by requesting an update file from GitHub. GitHub receives the request, including your IP address, as with any download; the developer receives nothing. GitHub’s privacy statement applies to that request.

Children

Onset is a general-purpose communication app and does not target children. Because the people on a server can talk to each other, parents should consider whether a particular server is suitable for a child. The developer does not knowingly collect personal information from anyone, including children.

Changes to this policy

If this policy changes, the new version will be posted at this address with a new effective date.

Contact

Questions about this policy or about Onset: email [email protected]. Bugs can also be reported at github.com/firatkarakas/onset-client/issues.