How to host private video calls without Zoom or Google Meet
Video meetings do not have to pass through a platform owned by a large advertising or cloud company. With the right software and a modest server, you can run your own video conferencing service, control where recordings and metadata are stored, and decide who can access each room. This is often called self-hosted video calling, private conferencing, or running your own WebRTC meeting server.
Self-hosting is not automatically private or simple. The server still has an IP address, the software needs security updates, and a poorly configured installation can expose cameras, microphones, recordings, or user accounts. The practical goal is to reduce unnecessary collection while keeping the experience usable for a family, community group, small business, or distributed team.
What self-hosted video calling actually means
Most browser-based video calls use WebRTC, a set of technologies that allows browsers to exchange audio and video in real time. A meeting service usually provides the web interface, account management, room creation, signalling, and a method for participants to connect through firewalls and home routers. The media may travel directly between participants, through a relay server, or through a central media server.
Hosting your own service means renting or operating the infrastructure that performs these jobs. A small virtual private server in Sydney, Melbourne, or another Australian data centre can host the application, while a TURN server helps participants connect when direct peer-to-peer communication fails. Keeping the server in Australia may improve latency for local users, although it does not guarantee that every third-party component or support service remains within the country.
This arrangement gives you control over access policies, logs, retention, and software versions. It does not provide magical anonymity. The hosting company can generally see network-level information, and a meeting administrator may still know who joined, when they joined, and how long they stayed. Self-hosting is best understood as a way to reduce dependence on a platform, not as a promise that no metadata exists.
Choosing software for your needs
Jitsi Meet is often the easiest starting point. It has a familiar browser interface, supports guest rooms, and can be installed using Docker or packages supplied by the project. It works well for informal meetings and small groups, although larger conferences can require substantial CPU, memory, and bandwidth. Its configuration also needs careful attention if you want to disable public room creation or require authentication.
Nextcloud Talk suits people who already use Nextcloud for files, calendars, and contacts. The video feature can then sit inside an existing private collaboration system, which is useful for a community organisation or small company. BigBlueButton is designed more specifically for teaching and structured online sessions, with features such as breakout rooms, polls, shared notes, and classroom controls. It generally asks more of the server than a lightweight meeting application.
More advanced operators may choose a platform built around SFUs, or Selective Forwarding Units. An SFU receives streams and forwards them to other participants without mixing every video into one output. This is more efficient than a full mesh connection as attendance grows. Projects based on mediasoup, Janus, or LiveKit offer flexibility, but they require stronger Linux, networking, and deployment skills. For most households and small groups, Jitsi or Nextcloud Talk is a more sensible first installation.
A practical server setup
Begin with a supported Linux distribution on a virtual private server. For a small meeting service, two virtual CPUs and several gigabytes of RAM may be enough for a handful of participants, but the real limit depends on camera resolution, screen sharing, recordings, and whether the server relays media. Check the software’s current requirements rather than relying on an old tutorial. A meeting with eight people in Brisbane can consume far more resources than a two-person call between Melbourne and Canberra.
Use a domain name such as meet.example.com and point its DNS record to the server. Put the application behind a reverse proxy such as Caddy or Nginx, then obtain a trusted TLS certificate through Let’s Encrypt. HTTPS is essential: modern browsers restrict camera and microphone access on insecure pages, and encryption protects the connection from ordinary interception. Enable automatic certificate renewal and test it before the first important meeting.
Firewall the server so that only required ports are open. SSH should use keys instead of password logins, and administrative access should be restricted where practical. Run the meeting service with the least privilege needed, keep the operating system patched, and store secrets outside publicly served directories. Automated backups should be encrypted, tested, and limited to information you actually need. A backup that quietly contains years of recordings can become a larger privacy problem than the original service.
Making rooms private and usable
A random-looking room name is a weak security measure. Configure authentication for hosts, require a password or lobby for guests, and prevent participants from creating unlimited public rooms. A waiting room lets the organiser admit people individually, which is useful for a volunteer committee or a telehealth-style discussion where the wrong visitor would be intrusive. Disable anonymous room creation if the service will be reachable from the public internet.
Give participants clear controls for their own devices. Browsers ask for camera and microphone permissions, but people should still know when recording is active, who can share their screen, and whether chat messages are retained. Avoid automatic recording unless there is a specific reason. When recording is necessary, decide where the file will be stored, who can download it, how long it will remain available, and how participants will be informed.
Calls between users on Australian NBN connections can be perfectly reliable, but regional and rural users may face variable upload speeds, mobile broadband limits, or carrier-grade NAT. A TURN relay can make the connection work when direct paths fail, though it increases bandwidth costs and gives the relay a copy of the encrypted media stream at the transport layer. Offer audio-only participation and lower-resolution video for users in regional New South Wales, Western Australia, or remote Queensland, where connectivity may be less predictable.
Protecting privacy beyond the server
A self-hosted meeting page can still include analytics, fonts, advertising scripts, or external integrations. Remove unnecessary third-party resources and inspect the browser’s network requests. The same principle applies to the devices people use to join: a meeting server cannot prevent an operating system, browser extension, or unrelated application from collecting information locally. The practical advice in disable cross-app tracking is relevant here because device-level profiling sits outside the controls of your video platform.
Separate identities when that improves the threat model. An organiser might use one browser profile for administration and another for ordinary browsing, while participants can join with a display name that reveals less personal information. This does not defeat a determined investigator, but it limits accidental leakage through autofill, extensions, profile photos, and linked accounts. It is especially useful when a community group includes people who do not need to know one another’s full names.
Privacy also includes the surrounding web activity. A person researching high-RTP casino games, reading health information, or attending a confidential meeting may prefer separate browser profiles and blocked third-party trackers. The point is not to label a particular type of website as inherently unsafe; it is to prevent unrelated browsing histories, cookies, and advertising identifiers from being combined with a meeting identity.
Australian operators should consider legal and organisational duties as well. The Privacy Act and the Australian Privacy Principles can apply when an organisation handles personal information, although obligations depend on the entity, activity, and circumstances. A small private installation may fall outside some requirements, but that is not a reason to collect everything. Write a short privacy notice, nominate an administrator, and establish a deletion process for accounts, logs, chat, and recordings.
Keeping the service reliable
Video calls are demanding because audio and video move continuously. Monitor CPU, memory, disk space, network traffic, and the number of active connections. Set alerts for a full disk and unusual bandwidth use. If the service becomes popular, do not simply increase the virtual machine size without checking whether the bottleneck is the media server, TURN relay, database, or network link.
Test from several networks before depending on the service. Try a home NBN connection, a phone hotspot, a work network, and a connection behind a restrictive firewall. Check camera permissions in Chrome, Firefox, Safari, and mobile browsers. Test screen sharing, audio-only mode, reconnection after a brief outage, and the behaviour of a participant who joins from an older laptop.
Updates require a routine rather than occasional attention. Subscribe to security announcements for the operating system, reverse proxy, container images, and meeting software. Read release notes before upgrading, keep a tested backup, and use a staging instance when the service is important. Review administrator accounts regularly and remove old access. Logs should be retained for troubleshooting for as short a period as is practical, with access limited to people who genuinely need them.
Knowing when self-hosting is the wrong fit
Running your own meeting platform is a good match when privacy, control, and independence matter more than convenience. It can work well for a neighbourhood association in Adelaide, a study group in Hobart, a small consultancy in Perth, or a family spread across Sydney and regional Victoria. Participants can use ordinary browsers, and the organiser can publish a simple link without requiring every person to create an account with a global platform.
There are costs, however. The server must be paid for every month, even when unused. Someone must handle updates, abuse reports, backups, certificate failures, and account recovery. A public service may also attract scanning, password attacks, or unwanted meeting activity. If no one can take responsibility for maintenance, a reputable hosted provider with a clear privacy policy may be safer than an abandoned server.
A sensible compromise is to start privately. Install the software for a small group, use invitation-only rooms, avoid recordings, and monitor performance for several weeks. Once the routine is reliable, add features gradually. Resist installing chat, calendars, storage integrations, transcription, and analytics simply because they are available. Each additional feature expands the amount of data collected and the number of components that require updates.
The central benefit of hosting your own calls is control over decisions that commercial platforms usually hide behind defaults. You decide whether a meeting needs a recording, whether a log should survive for a year, whether a guest must wait for approval, and where the server is located. That control is meaningful only when paired with strong authentication, current software, restrained data collection, and an honest understanding of what the system can reveal.
A private video call is therefore less about finding a magical replacement for Zoom or Google Meet and more about choosing a smaller, accountable system. Use WebRTC software suited to your group, secure the domain and server, test Australian network conditions, and treat recordings and metadata as sensitive information. What the reader should remember is simple: self-hosting can give you real control, but privacy comes from careful operation rather than from the software name alone.