Privacy Policy

What TACENZA Chat, TACENZA Mail and these websites store about you, what they never have, and who else sees anything.

Draft. This text hasn’t been reviewed by a lawyer yet and may change before TACENZA 1.0. Parts marked “To be completed” are still open.

TACENZA Chat is built to know as little about you as possible. An account is a username and a password. Everything you write is encrypted on your device before it is sent, and the server can’t decrypt it.

This policy covers TACENZA Chat, TACENZA Mail (in development, see TACENZA Mail) and the public TACENZA websites (see These websites).

Important

Draft – to be reviewed by a lawyer before launch, and published in English and Danish.

Who is responsible

TACENZA is a CARTIQO product.

Important

To be completed: the registered company name, address and company registration number of CARTIQO, as the data controller.

Important

To be completed: how to contact us about privacy (address or form), and whether a data protection officer is appointed.

What the server stores – and what it never has

This is for TACENZA Chat.

The server stores The server never has
A hash of each username Usernames in plain text
Public keys; whether an account is a bot Passwords or private keys (they’re encrypted with your password)
Which users are in which conversation, and their roles Who wrote a given text message
Encrypted, padded messages Message contents or their exact length
Encrypted attachments (padded) Whether an attachment is a photo, a file or a location
Encrypted profiles, account data, group info, invite previews and join-request names Bios, pictures, links, group names, contacts, blocked users, mute/pin/archive choices
Group settings, permissions, slow mode –
Whether you allow being added to groups Your contacts
When disappearing messages expire The time of any other message
Which account created a bot –
Your claim number, the month you last logged in (not the day), and how many invite codes you have made. Accounts nobody logs in to for 6 months are deleted. When or how often you use TACENZA
A hash of your username’s look-alike form, so two names that look the same can’t both exist Your username
Your recovery box: your account key, encrypted with your recovery key, and a check value derived from that key Your recovery key
Hashes of unused invite codes, and totals: how many personal codes were used, and how many people joined through each shared channel code Who made a code, or who used it
Hashes of session tokens (12 hours) IP addresses, device information, cookies, analytics
Your live location, encrypted, while you share it – deleted 10 minutes after the last update Where you are, or who you share it with
Your devices: a random id for each, and the day it was last used (names are encrypted in your account) What kind of device it is, or where it is
For each attachment, which account’s storage it uses (the account that uploaded it, or a bot’s owner) and its size. This is what storage limits are counted from – and it means the server knows who sent a message that has an attachment. What’s in the attachment, its name or its type
If you subscribe: a random billing reference; Stripe’s customer and subscription ids; your plan (Plus or Pro), price, billing interval, status and period dates; for each invoice, the amounts charged, taxed and refunded; and when your plan changed. Invoice records are kept for bookkeeping after an account is deleted, no longer linked to it. Your name, email, card, CVC or address – Stripe holds those, and never learns your username
If a group’s admins list it in Discover: its name, picture, description, tags, language and a public join link, readable by everyone signed in Who is in it, or what anyone searches for (the directory is searched on your device)
If you turn on push notifications on a device: that device’s push address and keys What the notice is about beyond which chat – it has no content and is encrypted to your browser
Only if you turn them on: a sealed two-factor secret; the time and device id of your last 50 sign-ins; when you were last here (to the minute, shown only to people you have a 1:1 chat with who share theirs); your email address for notes IP addresses, places or browsers; anything about who wrote to you, or what
In memory only, for spam protection: that an account is less than a day old; for three days, who started a 1:1 conversation, and whether the other person declined it as an unwanted request What was in it
Important

To be completed: how long invoice records are kept after an account is deleted. This is waiting for legal and accounting review.

No tracking

No analytics, no third-party requests (except the optional push notifications and email notifications below), no access logs, no IP addresses on disk. Rate limits and spam protection work only on how often an account or a network does something, never on what anyone writes. They keep short-lived counters in memory only, under keyed hashes instead of IP addresses or account names. Most are forgotten within minutes; nothing is kept longer than three days.

Optional features

Important

Draft – requires review by legal counsel before launch.

These are off until you turn them on, and each says what it reveals where you turn it on.

  • Push notifications (per device) go through your browser maker’s push service: Google, Mozilla, Apple or Microsoft. That service learns when your device gets a notice. It never learns who wrote, what was written, or which chat it was: the notice is encrypted and has no content.
  • Fetched link previews (for links you send): our server fetches the page for you, so the site sees our server, not you or your readers. We see the link while fetching it and keep nothing. The preview travels inside your encrypted message.
  • Discover: a group listing is public by its admins’ choice. Members’ names are never listed.
  • Two-factor sign-in: we keep a sealed secret to check your codes.
  • Sign-in history: the time and device id of your last 50 sign-ins, never an IP address or a place.
  • Online & last seen: shown only to people you have a 1:1 chat with who share theirs, and we keep when you were last here, to the minute.
  • Email notifications: if you turn them on, we keep your email address in plain text, the only real-world detail we would ever hold, and our mail provider sees it when a note is sent. A note only says you have new messages, never from whom or what. Turning it off deletes the address.
  • Stay signed in and the search index on this device store data only in your browser, encrypted or as keys that can’t be read out, and are deleted when you log out or turn them off. Translation, where your browser offers it, happens on your device.
Important

To be completed: the name of the mail provider used to send email notifications, and the processor agreement with it.

Payments

Important

Draft – requires review by legal counsel before launch.

TACENZA Plus and Pro are paid through Stripe, which handles the payment on its own pages as our payment processor. Stripe receives your email, payment details and (where tax requires it) your address from you, and from us only a random billing reference and the plan you chose – never your username, contacts, messages, files or keys. What you pay for is capacity and convenience (storage, devices, bots, larger attachments); it never changes who can read your messages. There are no ads, we don’t sell data, and payment data is never used for anything but billing, bookkeeping and tax.

Important

To be completed: the processor agreement with Stripe, and what Stripe’s own privacy policy covers.

TACENZA Mail

Important

Draft. TACENZA Mail is in development and sign-up isn’t open yet. This section describes what Mail stores as it is built today. It must be reviewed by a lawyer, with GDPR paperwork, before Mail is opened to anyone outside CARTIQO.

TACENZA Mail handles data differently from Chat. Email is not end-to-end encrypted: mail from other providers arrives readable, and the people you write to can read what you send them. What Mail stores:

  • Your mailbox. Your mail is stored on our mail server. Without encryption turned on, we could read it.
  • With zero-access encryption on (optional, under Encryption), new mail you receive and your copies of mail you send are stored encrypted with a key only you can unlock. The sender, recipients, subject and date of each message stay readable to us, as do labels such as who a message is assigned to, whether it’s done, and whether it’s read. Drafts, mail imported from elsewhere and mail from before you turned encryption on are not encrypted.
  • Your encryption key. Your private key is stored locked with your password, and a second time locked with a recovery key that is shown once and never stored.
  • Your password. It passes our server when you sign in, on its way to the mail server. We don’t keep it, but for now you can’t check that.
  • Shared addresses (like support@) can be encrypted too. For a few seconds after a message arrives, it is stored unencrypted before our server encrypts it.
  • Your session. A sign-in token in one cookie (see the Cookie Policy).
  • Team settings. For companies: who is an admin, and whether a password is a temporary one set by an admin.
  • Sign-in attempts. Counted per IP address and per account, in memory, to stop password guessing. They reset when the server restarts.
  • Sending limits. For accounts made through sign-up, a count of how many people the account has sent to in the last 24 hours. No addresses are kept for this.
  • Reports. When someone reports mail from a TACENZA Mail account, we keep who sent it, who reported it, the reason and note, the subject and the first 600 characters of the text – not the whole message. Reports the abuse team has dealt with are removed after 90 days.
  • Suspensions. Whether an account is suspended, and the reason shown to its owner.

A company admin can reset the passwords of people in their company. Without encryption, that lets the admin into their mailbox; with encryption on, a reset doesn’t open encrypted mail.

The Mail web app makes no requests to anyone else: no analytics, fonts or scripts from third parties.

Important

To be completed: what the mail server itself logs (for example IP addresses in delivery and sign-in logs), and for how long.

Important

To be completed: where Mail is hosted. The plan is a server in the EU; the provider and location aren’t decided.

Important

To be completed: how long mail and account data are kept after an account is deleted, and what happens to a company’s mail when a person is removed.

These websites

This covers www.tacenza.app, docs.tacenza.app, support.tacenza.app, blog.tacenza.app and status.tacenza.app.

  • No cookies. The websites set no cookies.
  • Nothing from third parties. Every font, script and image comes from TACENZA itself.
  • Counting visits, only if we turn it on. If the operator enables it, the websites send counts of page views and clicks to TACENZA: the event, which site, the page path without anything after it, and a few fixed details such as which plan was clicked or how many search results there were. Searches are never sent, only their length and whether anything matched. Nothing identifies you: no cookies, no stored ids, no fingerprinting, no referrer. If your browser sends Global Privacy Control or Do Not Track, nothing is sent at all.
  • What your browser keeps. Your theme choice, under the key tz-theme in local storage. On the Help Center, a support ticket you haven’t sent yet is kept as a draft on your device only.
Important

To be completed: what the counting endpoint and the web server keep from each request (a request always reveals an IP address to the server that receives it), and for how long.

Your rights

You can delete your account at any time in Settings. That removes your keys and 1:1 chats and takes you out of every group. Because we can’t read your data, we can’t hand it over in readable form – to anyone.

Important

To be completed: your rights under the GDPR (access, rectification, erasure, restriction, portability, objection), the legal basis for each kind of processing, how to exercise your rights, and the right to complain to a data protection authority, with its name.

Email and phone

Optional, encrypted with your password, and never used for anything.

Recovery key

When you sign up you get a recovery key. It is made on your device and shown once; we never have it. With it, you can set a new password yourself if you forget yours. Without your password or your recovery key, nobody can open your account – including us. Anyone who has your recovery key can take over your account, so keep it private.

Changes

Important

To be completed: how we tell you about changes to this policy.