$ plaintxt --faq
faq
frequently asked questions.
what is plaintxt?
plaintxt is private messaging without accounts, in the browser or the Android app. you pick a username, your device generates encryption keys locally, and you send end-to-end encrypted messages. messages stay until you delete them, and burning your identity erases everything tied to it and frees the username.
do I need an account?
no. plaintxt has no accounts. you pick a username and your device generates an encryption key pair locally. that is your identity, and it is yours until you burn it.
do I need a phone number or email?
no. nothing is required to use plaintxt for free. a payment method is only required for pro or power, and that is handled entirely by Stripe. messaging itself never requires personal contact information.
what is a plaintxt identity?
an identity is a username + encryption key pair stored in your browser. it has no account behind it — no email, no password, no profile. it does not expire: it is yours until you burn it, and burning hard-deletes everything and releases the username for someone else. the one exception is housekeeping — a free identity left completely unused for 180 days is deleted. it only persists in the browser where it was created.
how do people message me?
share your username (e.g. @yourname). they open plaintxt, create their own free identity if they don't have one, go to search, type your username, and start a conversation. there is no friend request, follow, or connection step — just a username search.
can plaintxt read my messages?
no. messages are encrypted in your browser using ECDH P-256 + AES-256-GCM before they are sent. the server stores and relays only ciphertext. we do not have your private key and cannot decrypt your messages.
when do messages delete?
by default they are kept until someone deletes them — you or the other person. deleting is a hard delete: no archive, no soft-delete, no recovery, and burning your identity takes every message with it. power users can switch a conversation into burn-after-read, where messages are deleted 60 seconds after reading (10s/30s/60s configurable) and a background sweep runs every 5 minutes.
what happens if I close the browser?
your identity and private key remain in local storage. you can resume the same identity when you return, as long as you use the same browser and have not cleared site data. the browser does not need to stay open.
what happens if I clear browser data?
clearing site data removes your private key and session token permanently. you will not be able to resume that identity. plaintxt cannot recover it — we never had a copy of your private key. if you have a pro/power recovery code, you can create a new identity and restore your paid tier, but the old username and messages are gone.
what if I close incognito?
incognito sessions clear all local storage on close. your private key and session token are erased. you will not be able to resume that identity. if you want persistence, use a regular browser window.
can I recover my identity?
only from this browser, while local storage remains intact. your private key lives in IndexedDB and never leaves your device. if you clear site data, close an incognito session, or switch devices, the key is gone. plaintxt cannot recover it. pro/power users can restore their paid tier to a new identity with a recovery code, but the old username and message history are unrecoverable.
are paid plans anonymous?
billing is handled by Stripe. Stripe requires a payment method. plaintxt links your paid tier to your browser identity (a random UUID) — not to your name or email. your username, messages, and conversations are not shared with Stripe. see the privacy policy for full details.
why does Stripe appear in my bank statement?
Stripe is the payment processor. the charge will appear as Stripe or plaintxt depending on your bank. this is expected. if you did not intend to subscribe, go to settings → billing → manage billing to cancel immediately.
can screenshots be blocked?
no. plaintxt cannot technically prevent screenshots or screen recording. any visual deterrence is cosmetic only. once a message is on your screen, the recipient can capture it. deleting prevents server-side access — it cannot prevent human action.
is plaintxt for illegal activity?
no. plaintxt is built for legitimate privacy — conversations without phone numbers, anonymous feedback, sensitive coordination without handing over contact details. it is not a tool for illegal activity. abuse protections are active across all tiers. users who violate terms are removed.
how is this different from Signal, WhatsApp, or Telegram?
plaintxt is not replacing those apps. Signal, WhatsApp, and Telegram tie your account to a phone number. plaintxt has no accounts and no phone numbers at all — just a username you can burn whenever you want, which erases everything and releases the name. use Signal when you want forward-secret chat with people who already have your number. use plaintxt when you do not want to hand over a real identity, and want to be able to walk away cleanly.
will there be mobile apps?
no native apps are planned at this stage. plaintxt works in any modern mobile browser. you can install it to your home screen via your browser's 'add to home screen' option for a near-native experience.
can I install it like an app?
yes. on mobile, open plaintxt.app in your browser, tap share, and select 'add to home screen'. on desktop Chrome, look for the install icon in the address bar. this installs plaintxt as a PWA — no app store required.
what do pro and power include?
pro ($4.99/mo): up to 5 active sessions (multi-device), 200 MB attachments (vs 10 MB free), 30-day identity lifetime, a 5-minute message edit window, conversation pinning, and a recovery code to restore paid access. power ($9.99/mo): everything in pro, plus 1 GB attachments, 365-day identity lifetime, up to 20 sessions, multi-identity (up to 5 local identities), and encrypted identity export/import. see the full plans comparison.
what is the encryption model?
each message uses a fresh ephemeral ECDH P-256 key pair. ECDH derives a shared secret, HKDF-SHA-256 produces an AES-256-GCM key, and the message is encrypted with a random 12-byte IV. each message therefore has its own key, but this is not full forward secrecy and not the Signal Double Ratchet: the ephemeral key is agreed against your long-term identity key, so compromising that key exposes stored past messages. we document the limits honestly on the security page.
how do I cancel pro or power?
from settings → billing → [manage billing →]. this opens the Stripe customer portal where you can cancel. cancellation takes effect at the end of the billing period. your paid features remain active until then.
is there a community or support channel?
yes. join the plaintxt Discord for launch testing, support, bug reports, and feedback: discord.gg/7FxxfQCGKU. you can also reach us by email at feedback@plaintxt.app.