I spent a fair amount of time and money getting Rocket.Chat set up and implemented, but I’m now discovering that it’s just not an option to use it due to the lack of privacy for anything more than a single transparent organisation. It’s a shame since besides this everything else seems excellent. Am I missing something?
I imagine my needs are pretty standard, and maybe the missing privacy options are why RC is not more popular. It doesn’t seem like you can use it with users who don’t know each other without violating their privacy (unless they don’t mind anyone else seeing their profile). The requirements I’m looking for are:
-
Disabling the user directory or have it only showing users who are connected with each other through a team/private channel.
-
Ability to have user directory disable/private but still be able to search for other users, whether that’s only by username or also by name.
-
Ability to choose a preference of a team/channel/discussion’s privacy - e.g. make a channel where users cannot see other members based on role.
-
Potentially also a better system for connecting users in a more private way - friend requests and contacts, or add contact via URL.
I am far from the only person looking for some basic privacy options, here are a few others I saw after a quick search, most of which were ignored. It’s concerning.
This unanswered discussion asks how users can be allowed to search for other users whilst having the global user directory public - disabling the view-outside-room permission hides the directory successfully but then it’s unusable since you can’t find other users at all:
/forums.rocket.chat/t/view-outside-room-whitout-acces-to-all-user-list-in-directory-is-it-possible/8193
Another ignored discussion asking for the ability to keep the userbase list private:
/github.com/RocketChat/Rocket.Chat/issues/14930
This discussion is also looking for better privacy and identifies view-outside-room permission but as I mentioned this makes RC almost unusable since it’s impossible to discover other users:
/forums.rocket.chat/t/disable-user-search-directory-users-for-some-user-groups/10764
The @ command also has the potential to leak all users, the discussion below highlights that even with the directory disabled, @ still reveals them. I’m not sure if this was fixed, but again the discussion went unanswered.
/forums.rocket.chat/t/hide-users-from-command/6505
–
Hopefully some of this is already possible and I’m just missing the setting, if so I would appreciate any guidance. Otherwise I am interested to know when at least some of this will be implemented.
With great privacy for large communities and organisations I can see Rocket Chat becoming very popular, but without it is limited to small organisations that have no need for privacy (who I imagine would be better served by Slack, Teams, Mattermost, etc at a tiny cost anyway).