End-to-end private messaging 路 self-hosted
Last updated: September 12, 2026
This Privacy Policy applies to TXaT, the encrypted messaging application, and to its website. Its purpose is to clearly explain what information is processed, what it is used for, who it may be shared with and how it is protected.
Owner: Pispo. For any question about privacy or the processing of personal information, you can write to pispo.tk@gmail.com.
TXaT lets you sign in with a Google account (verified email), a display name and user ID, and manage contacts by their email address. From the website you can send notices or suggestions; in that case your email and the message are stored.
TXaT uses Google Sign-In to identify the account and complete the sign-in. The Google account password is never requested or stored. The use of this external service is also subject to its own privacy policies.
To work, certain technical data is processed: an installation ID, the technical notification token (FCM), message and recipient identifiers needed for delivery, and the IP address (used to apply anti-abuse limits, such as one notice every 5 minutes). No information about the device鈥檚 physical location is collected.
The app uses Firebase Cloud Messaging (FCM) to deliver notifications and messages to the device through a technical token tied to the installation. This data is used exclusively to provide the notification; you can control it from the device settings.
TXaT messages are encrypted before being sent and transmitted as encrypted data (ciphertext). Private keys stay on the devices and are never provided to the delivery infrastructure, which only carries the ciphertext together with the strictly necessary technical metadata (message and recipient identifiers). If the recipient is offline, the encrypted message stays in a server queue until delivered. Messages and conversation data may be stored locally on the device and are deleted when you log out or clear the app data.
The user enters the email address of their contacts to identify and invite them. That data is used only for communication and contact management. Contact lists are not sold or used for advertising.
TXaT uses strictly necessary external services: Google Sign-In (authentication), Firebase Cloud Messaging (notifications and delivery) and Pispo鈥檚 own infrastructure (delivery server and notice storage). Each provider applies its own privacy policy.
TXaT does not use advertising.
Communications use transport encryption (HTTPS/TLS). Message content is additionally protected with end-to-end encryption and private keys are not stored on the server. However, no storage or communication system can guarantee absolute security.
We keep information only for as long as needed to provide the service functions. Notices and suggestions sent from the app or the website are stored in the server database and can be deleted by the administrator. Device data is deleted when you log out, clear the app data or uninstall the app.
TXaT is not specifically designed to collect personal information from children. If a parent, guardian or tutor believes a minor has provided personal information without their consent, they can write to pispo.tk@gmail.com and reasonable measures will be taken.
Under applicable law, users may have rights of access, rectification, deletion, objection, restriction of processing or data portability. To exercise them, write to pispo.tk@gmail.com; we may ask for reasonable information to verify the request.
This policy may be updated to reflect changes in the app, the services used or legal requirements. When there are significant changes, this page will be updated showing the date of the last modification.
For any question about this policy or data processing: Pispo 路 pispo.tk@gmail.com.