What the server stores

Everything the TACENZA Chat server stores about you, what it never has, and what changes when you turn on optional features.

The TACENZA Chat server is built to know as little as possible. It stores hashes, public keys, ciphertext, and the small amount of plain information it needs to enforce rules, such as who is in which group and what their role is. This page lists all of it. The legally binding version is the privacy policy.

Always stored

The server stores The server never has
A hash of your username, and a hash of its look-alike form Your username in plain text
Your public keys; whether an account is a bot Your password or private keys
Which users are in which conversation, and their roles Who wrote a given text message
Encrypted, padded messages and attachments Message contents or exact length; whether an attachment is a photo, a file or a location
Your encrypted profile, account data, group info, invite previews and join-request names Bios, pictures, links, group names, contacts, blocked users, mute, pin and archive choices
Group settings, permissions, slow mode, whether you allow being added to groups Your contacts or message requests
When disappearing messages expire The time of any other message
Roles, channels, overrides, bans, timeouts and onboarding status (ids and numbers only) Role and channel names, colours or topics; reports, warnings and the audit log
Which message ids are pinned; whether a message is a small update such as a reaction or edit What they say, or which kind of update
Hashes of session tokens (12 hours) IP addresses, device details, cookies, analytics
Your devices: a random id each, and the day each was last used What kind of device it is, or where
Your claim number, the month you last logged in, and how many invite codes you made When or how often you use TACENZA
Your recovery box and a check value from your recovery key Your recovery key
Your encrypted live location while you share it, deleted 10 minutes after the last update Where you are, or who can see it

Attachments and storage

To count storage against your plan, the server records which account’s storage each attachment uses and its size. This means the server knows who sent a message that has an attachment – but not what’s in it, its name or its type.

Only if you turn it on

Each of these is off by default, and says what it reveals where you turn it on. Turning one off deletes what it stored.

Feature What the server keeps
Two-factor sign-in A sealed secret for checking codes, and the last code step used
Sign-in history The time and device id of your last 50 sign-ins – never an IP, place or browser
Online & last seen When you were last here, to the minute
Email notifications Your email address in plain text, and when the last note went out
Push notifications Your device’s push address and keys
List in Discover The group’s name, picture, description, tags, language and a join link, in plain text
Fetch previews for links I send Nothing – the link is fetched and forgotten
A paid plan A random billing reference, Stripe’s ids, your plan, price, status, period dates and invoice amounts

Stripe handles payments and holds your name, email and card details. It never learns your username, and TACENZA never sees your card.

Logs and spam protection

  • No analytics, no access logs, and no IP addresses on disk. Error logs hold only the kind of error and the route.
  • Rate limits keep short-lived counters in memory under keyed hashes. For spam protection, it also remembers in memory that an account is less than a day old and, for three days, who started a 1:1 conversation and whether it was declined as unwanted. Nothing is kept longer than three days.

When data is deleted

Deleting your account removes your keys and 1:1 chats and takes you out of every group. Accounts nobody logs in to for 6 months are deleted, unless they have a running paid subscription. Invoice records are kept for bookkeeping, no longer linked to the account.

Because the server can’t read your data, TACENZA can’t hand it over in readable form – to anyone. See How encryption works.