What our server stores – and what it never has

A plain list of what the TACENZA Chat server keeps, what it never learns, and the limits we haven't solved yet, like visible group membership.

TACENZA Chat is built so the server knows as little about you as possible. It relays and stores encrypted data, and it can’t decrypt any of it. But “the server can’t read your messages” isn’t the whole story: every messenger’s server learns something just by doing its job. This post lists what ours stores, what it never has, and where it still knows more than we’d like.

The short version

An account is a username and a password. Everything you write is encrypted on your device before it’s sent. The server stores encrypted data, hashes and public keys. It never learns what you write, your contacts, your group names or your bio.

What the server stores

  • A hash of your username, never the name itself. It also keeps a hash of the name’s look-alike form, so two names that look the same can’t both exist.
  • Your public keys, and whether an account is a bot.
  • Your private keys, profile and settings – but only encrypted with keys you have.
  • Encrypted, padded messages and attachments. Padding hides their exact length.
  • Who is in which conversation, and their roles.
  • Group settings and permissions, such as slow mode.
  • When disappearing messages expire.
  • The month you last logged in, not the day, and your claim number. Accounts nobody logs in to for 6 months are deleted.
  • Hashes of session tokens, for 12 hours.
  • A random id for each of your devices, and the day it was last used. Device names are encrypted in your account.

What it never has

  • Your username in plain text, your password or your private keys.
  • What any message says, or its exact length.
  • Who wrote a given text message.
  • Whether an attachment is a photo, a file or a location.
  • Bios, pictures, links, group names, contacts, blocked users, and your mute, pin and archive choices.
  • The time of any message, except when a disappearing message expires.
  • IP addresses, device information, cookies or analytics.

There’s no tracking. No analytics, no access logs, no IP addresses on disk. Spam protection works only on how often an account or a network does something, with short-lived counters in memory. Most are forgotten within minutes, and nothing is kept longer than three days.

Where it knows more than we’d like

Some things the server has to know to work. We’d rather say so than hide it.

  • Group membership is visible. The server knows who is in which group, because it has to enforce roles and permissions. It can’t read names, messages or profiles. Sealed-sender routing, which would hide more of this, is a later step.
  • Attachments have an owner. Storage limits are counted per account, so the server records which account’s storage each attachment uses. That means it knows who sent a message that has an attachment. Text messages are unaffected.
  • A little, briefly, for spam protection. In memory only: that an account is less than a day old, and for three days, who started a 1:1 conversation and whether the other person declined it.
  • No forward secrecy yet. Within one key generation, a leaked key would expose that generation’s messages. Groups get a new key after 50 messages and on every membership change, which narrows this. The Signal protocol for 1:1 chats and MLS for groups are planned for after 1.0.
  • Usernames can be tested. Anyone can check whether a username exists. That comes with a username-based system; proof of work and rate limits slow down anyone trying to list them.
  • Blocking happens on your device. That’s on purpose: blocking on the server would tell it who you block.

What you choose to reveal

Some features need the server to know more. They’re all off until you turn them on, and each one says what it reveals where you switch it on.

  • Discover: a group’s admins can list it publicly. Its name, picture, description, tags and language become readable to everyone signed in. Members’ names are never listed.
  • Push notifications: your browser maker’s push service learns when your device gets a notice. The notice has no content.
  • Two-factor sign-in, sign-in history and online / last seen each store a little more, and never an IP address or a place.
  • Email notifications: your email address, in plain text. It’s the only real-world detail we’d ever hold, and turning the feature off deletes it.
  • Paid plans: Stripe handles payment on its own pages. We keep a random billing reference and your plan. Stripe never learns your username.

Read the full list

Everything above is in the Privacy Policy, in a table you can check line by line. To confirm the app you’re running is the one we published, see Verify the app.