What the server stores
Everything the TACENZA Chat server stores about you, what it never has, and what changes when you turn on optional features.
The TACENZA Chat server is built to know as little as possible. It stores hashes, public keys, ciphertext, and the small amount of plain information it needs to enforce rules, such as who is in which group and what their role is. This page lists all of it. The legally binding version is the privacy policy.
Always stored
| The server stores | The server never has |
|---|---|
| A hash of your username, and a hash of its look-alike form | Your username in plain text |
| Your public keys; whether an account is a bot | Your password or private keys |
| Which users are in which conversation, and their roles | Who wrote a given text message |
| Encrypted, padded messages and attachments | Message contents or exact length; whether an attachment is a photo, a file or a location |
| Your encrypted profile, account data, group info, invite previews and join-request names | Bios, pictures, links, group names, contacts, blocked users, mute, pin and archive choices |
| Group settings, permissions, slow mode, whether you allow being added to groups | Your contacts or message requests |
| When disappearing messages expire | The time of any other message |
| Roles, channels, overrides, bans, timeouts and onboarding status (ids and numbers only) | Role and channel names, colours or topics; reports, warnings and the audit log |
| Which message ids are pinned; whether a message is a small update such as a reaction or edit | What they say, or which kind of update |
| Hashes of session tokens (12 hours) | IP addresses, device details, cookies, analytics |
| Your devices: a random id each, and the day each was last used | What kind of device it is, or where |
| Your claim number, the month you last logged in, and how many invite codes you made | When or how often you use TACENZA |
| Your recovery box and a check value from your recovery key | Your recovery key |
| Your encrypted live location while you share it, deleted 10 minutes after the last update | Where you are, or who can see it |
Attachments and storage
To count storage against your plan, the server records which account’s storage each attachment uses and its size. This means the server knows who sent a message that has an attachment – but not what’s in it, its name or its type.
Only if you turn it on
Each of these is off by default, and says what it reveals where you turn it on. Turning one off deletes what it stored.
| Feature | What the server keeps |
|---|---|
| Two-factor sign-in | A sealed secret for checking codes, and the last code step used |
| Sign-in history | The time and device id of your last 50 sign-ins – never an IP, place or browser |
| Online & last seen | When you were last here, to the minute |
| Email notifications | Your email address in plain text, and when the last note went out |
| Push notifications | Your device’s push address and keys |
| List in Discover | The group’s name, picture, description, tags, language and a join link, in plain text |
| Fetch previews for links I send | Nothing – the link is fetched and forgotten |
| A paid plan | A random billing reference, Stripe’s ids, your plan, price, status, period dates and invoice amounts |
Stripe handles payments and holds your name, email and card details. It never learns your username, and TACENZA never sees your card.
Logs and spam protection
- No analytics, no access logs, and no IP addresses on disk. Error logs hold only the kind of error and the route.
- Rate limits keep short-lived counters in memory under keyed hashes. For spam protection, it also remembers in memory that an account is less than a day old and, for three days, who started a 1:1 conversation and whether it was declined as unwanted. Nothing is kept longer than three days.
When data is deleted
Deleting your account removes your keys and 1:1 chats and takes you out of every group. Accounts nobody logs in to for 6 months are deleted, unless they have a running paid subscription. Invoice records are kept for bookkeeping, no longer linked to the account.
Because the server can’t read your data, TACENZA can’t hand it over in readable form – to anyone. See How encryption works.