Known limits

What TACENZA Chat's encryption and privacy protections can't do today, what's accepted by design, and what's planned.

No messenger protects against everything, and we’d rather you knew where TACENZA Chat’s protections stop. This page lists the limits we know about: some are accepted by design, some are planned to change. If you find one that isn’t here, please report it.

Encryption

  • No forward secrecy within a key generation. Someone who got hold of a conversation’s current key could read the messages sent under it. Groups get a new key after 50 messages and on every membership change, which narrows this. Planned: the Signal protocol for 1:1 chats and MLS for groups.
  • Re-keying cost grows with group size. Each new key is sealed to every member. It works for large groups, but MLS is planned for groups beyond about 1,000 members.
  • No independent security review yet. One is planned before version 1.0. The code isn’t open source at the moment; you can verify the app you’re running against published hashes.

What the server can see

  • Who is in which conversation. The server needs memberships and roles to deliver messages and enforce rules. Hiding memberships is planned for later.
  • Who sent a message with an attachment. Storage is counted per account, so the server knows whose storage an attachment uses, but not what it is.
  • When you’re connected. The server can see when your device has a connection open. Beyond the month you last logged in and the day each device was last used, it doesn’t keep this unless you turn on Online & last seen.
  • Whether a username exists. Anyone can test a specific username. That’s accepted for a username-based system; rate limits and a sign-up check slow down guessing.

Screenshots and copying

  • A web page can’t block screenshots. Protected chats blur when TACENZA isn’t in focus and, by default, can only be read in the desktop app, which keeps its window out of screenshots and screen recordings on Windows. On macOS, not every capture method honours this.
  • Anyone in a chat holds its keys. A member with a modified app can always read and keep what’s sent to them, whatever the chat’s settings.
  • A camera pointed at a screen can’t be stopped by any software.

Rules the app enforces, not the server

  • Blocking happens on your device, so the server never learns whom you block. A blocked person can still send; your device hides it.
  • Sending locations and contact cards can’t be told apart from text by the server, so the “Send photos and files” permission is enforced by members’ apps for those.
  • The look-alike name check relies on the app sending an honest value. A modified app could claim a look-alike name.
  • “One free claim per device” is a browser flag. Anything stronger would mean fingerprinting devices.

Features and platforms

  • Renaming usernames isn’t built. The claim rules promise free renaming until TACENZA Mail launches.
  • Live location only updates while TACENZA is open. Background location needs native apps.
  • No native iOS or Android apps yet. The desktop app is for Windows, and its installer isn’t code-signed yet.
  • Push notifications go through your browser maker’s push service. They’re opt-in, encrypted and content-free, but the service sees when you get one.
  • The search index on a device can hold the first version of an edited message until that chat is loaded again.

Your account

  • Nobody can reset your password. If you lose both your password and your recovery key, the account can’t be opened – by anyone.
  • Your recovery key is as powerful as your password. Anyone who has it can take over your account.
  • Email notifications, if you turn them on, mean the server keeps your email address in plain text.

TACENZA Mail

Mail has different limits, starting with the fact that email isn’t end-to-end encrypted. See TACENZA Mail at a glance.