Built to know as little about you as possible
TACENZA encrypts everything on your device and keeps the server blind. This page explains what that means in practice – and where the limits are.
What our server stores – and what it never has
For TACENZA Chat. The full list is in the privacy policy.
Stored
- A hash of your username (not the username)
- Your public keys
- Encrypted messages, files and profiles – ciphertext it can’t open
- Which groups an account belongs to, to enforce roles
- A random device ID and the day it was last seen
Never has
- Your password or your private keys
- What you write, send or share
- Group names, channel names, bios and profile pictures
- Your contacts
- Your phone number, email address or real name
- IP addresses on disk
Controls you have
Account security
Your password never leaves your device: it’s turned into a key there, and the server only gets a proof. Sessions end after 12 hours unless you choose to stay signed in on a device.
Account securityTwo-factor sign-in
Add a code from an authenticator app to every sign-in. Each code works once. Your recovery key still works if you lose the phone.
Set up two-factor sign-inDevices and sessions
See every device signed in to your account and sign any of them out. Devices unseen for 30 days are removed automatically.
Sessions and devicesRecovery key
Made on your device when you sign up and shown once. With it you can set a new password. Without your password or recovery key, nobody can open your account – including us.
Recovery keysAbuse prevention
Proof-of-work at sign-up instead of a CAPTCHA, rate limits on every action, and message requests so strangers can’t land in your chats.
Report abuseReliability
Service health is published on the status page, with every incident written up when it happens.
View status
Everyone gets the same app
The code isn’t open source, so you shouldn’t have to take our word for it. For every release, our build pipeline publishes the SHA-256 of the app’s JavaScript in tacenza/releases on GitHub – a record kept apart from the servers that run TACENZA.
You can also open your browser’s developer tools and watch the Network tab: every request goes to TACENZA itself.
# 1. Note the file name and hash in bundle-hash.txt
# of the latest release on GitHub.
# 2. Hash the file your browser is served:
$ curl -s https://chat.tacenza.app/assets/<file> | sha256sum
# 3. The two hashes must be identical.Found a vulnerability?
Please tell us privately through a GitHub security advisory, so it can be fixed before it’s public.
Our disclosure guidelines explain what to include. You’ll also find the contact in /.well-known/security.txt.