$ cat privacy.txt

privacy policy

plain language. last updated: September 2026.


// what we collect

username: the handle you choose. stored with your public key. it does not expire — it is deleted when you burn your identity, which also releases the name for someone else to claim. a free identity left completely unused for 180 days is deleted for housekeeping.

public key: your ECDH public key, generated in your browser. stored so others can encrypt messages to you. it is not a secret.

ciphertext: the encrypted content of your messages and files. we keep this until you delete it. we cannot read it — it is encrypted on your device with a key we do not have. it is hard-deleted when you delete the message, delete the conversation, or burn your identity. in a burn-after-read conversation it is deleted shortly after being read instead.

metadata: we can see which identities are in a conversation and when messages were sent, and we keep that for as long as the conversation exists. message content is not observable. we do not store IP addresses persistently. because messages are now kept rather than expiring, this metadata accumulates until you delete the conversation or burn your identity.

billing (pro and power): Stripe collects your payment details. plaintxt receives only a Stripe customer ID and subscription status — no card numbers, no billing address.

// your private key

your private key is generated inside your browser and stored in IndexedDB. it never leaves your device. plaintxt has no copy of it and cannot recover it. if you clear browser site data, close an incognito window, or switch to a different device, your key — and access to all past encrypted messages — is permanently gone. this is by design.

// ads

plaintxt does not serve ads. we do not accept payment from advertisers. the app is funded by Pro subscriptions.

// android app

the plaintxt Android app follows this same policy. on Android your private key is stored encrypted by the Android Keystore on your device, never in cloud backups, and never leaves the device unencrypted. uninstalling the app destroys your keys.

push notifications (optional): if you allow notifications, a delivery token is registered with Google Firebase Cloud Messaging (Android) or your browser's push service (web). notification payloads contain only opaque message IDs — never message content or usernames. tokens are deleted when your identity is deleted.

deleting your identity and data is immediate and self-service — see plaintxt.app/delete-account.

// contact

privacy questions: contact page. we do not have a legal department — we are a small project. we will respond to reasonable requests as promptly as we can.

// what we do not collect

✗ no email address

✗ no phone number, anywhere

✗ no access to your contacts or address book

✗ no real name

✗ no device fingerprinting

✗ no third-party analytics (no Google Analytics, Mixpanel, etc.)

✗ no advertising trackers

✗ no cookies beyond what is required for session management

✗ no selling or sharing of data with third parties

✗ no persistent logs of message content

// retention and deletion

we keep your messages until you delete them. this changed in September 2026 — messages used to expire automatically after 24 hours. they no longer do, and neither do identities.

you can delete a single message, a whole conversation, or your entire identity at any time. every one of those is a hard delete: the row is removed and the file is removed from storage. there is no archive, no soft-delete, no tombstone and no trash to restore from. we cannot undo it for you.

burn-after-read: Power subscribers can set a conversation so messages are deleted shortly after being read (10, 30 or 60 seconds). it applies to messages sent after the setting is turned on.

inactive free identities: a free identity that goes 180 days without being used is deleted, along with its messages and files, and its username is released. we send a notification 30 days beforehand if you have notifications enabled. paid identities are not deleted for inactivity.

backups: we do not keep our own backups of your messages, so a deletion is not quietly recoverable from a snapshot. that also means we cannot restore anything you delete by mistake.

// legal process

being honest about this matters more now that data is kept. if we receive a valid legal demand, we can only hand over what we actually hold: usernames, public keys, which identities talked to each other, timestamps, file sizes, and ciphertext we cannot decrypt. we hold no message content in readable form, no email, no phone number, no real name, and no persistent IP log.

what you have deleted is gone and cannot be produced. the strongest protection remains the same as it has always been: delete what you no longer need, and burn an identity when you are done with it.

// contacts

you can invite someone straight from your contact list. we never read your address book. no contact data — not even a hashed version — is uploaded to us, and neither the website nor the Android app holds a contacts permission. how it works depends on where you are: in a browser that supports it, your device shows its own contact picker and returns only the one person you choose, to this page, on your device. in the Android app there is no picker at all — the invite is handed to your own messaging app with the text already written, and you pick the recipient there, inside that app.

// third parties

Stripe: payment processing for Pro subscriptions. subject to Stripe's own privacy policy. plaintxt does not see your card details.

Cloudflare: infrastructure (Workers, D1, R2, Durable Objects). subject to Cloudflare's data processing terms. network-level metadata may be visible to Cloudflare as our infrastructure provider.

Google Firebase Cloud Messaging: delivers push notifications to the Android app, if you enable them. payloads contain opaque IDs only — never message content, names, or previews.

// SMS

plaintxt does not send SMS and does not collect phone numbers.when you invite someone by text, the message is sent by your own phone from your own number — it never passes through us, and we never learn who you sent it to. an older SMS opt-in page still exists for reference; its form is inactive and submits nothing.