Tacq Privacy Policy
The Tacq Team has developed this platform to restore your control over your digital space. Our core principle is Zero PD (Zero Personal Data). We do not just promise not to share your data; we build our system so that we do not collect it in the first place.
Our internal privacy standards are designed in the spirit of the world’s strictest data protection regulations, including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), as our architecture physically excludes the collection of personal information by default.
1. What We DO NOT Collect
Tacq does not request, verify, or store:
- Your phone number.
- Your real email address.
- Links to your social media profiles.
- Information about your real name or location (unless you voluntarily choose to broadcast a geo-tag within a specific group). We do not ask for your date of birth either — only your age group (see section 3).
2. How We Identify You (Master ID System)
Instead of traditional logins, we generate a random alphanumeric code (Master ID) for your device. This code is your access key. We do not ask for or store a link between it and your real-world identity — no name, phone number, or email is attached to it. Even so, a Master ID can still qualify as personal data, so we protect it accordingly (see section 8).
3. What Data We Store
To facilitate communication, we store only the information you voluntarily create within the platform:
- Contextual Profiles (Personas): Nicknames and avatars you set for personal sessions or specific business groups.
- Messages and Media: Text, voice messages, and files you exchange in chats.
- Technical Metadata: Timestamps of sent messages (for chat sorting) and system logs to protect against spam.
- Age Group (Tier): on first launch we ask for your age group once, to keep minors safe. We store only the group (e.g., "13–15" or "18 or older"), never your date of birth. Additional limits apply to minors (for example, end-to-end encrypted secret levels are disabled).
4. Where Your Messages are Stored and Who Has Access
Private conversations (one-to-one, including replies to listings). The text of your messages is encrypted on your device and can be opened only on your contact's devices (and on your own linked devices). The server holds an envelope it cannot read, and only until delivery: once the message reaches the recipient's devices, it is deleted from the server (or after a limited time if it is never picked up). The private keys never leave your devices. Your conversation history is therefore kept on your devices, not on our servers; you can keep up to five linked devices and make an encrypted archive file yourself. If you lose all your devices and have no archive, the history cannot be restored by us — we do not have it.
Attachments, groups and business tickets. Photos, files and voice messages, as well as messages in groups and in tickets to organisations, are stored on secure cloud servers (Google Firebase infrastructure) and encrypted at rest. Access is strictly limited by database rules: only the participants of that session can read them. The Tacq Team does not use automated scanners to analyze the content of your conversations for marketing or profiling purposes.
For anything especially private, a one-to-one chat also offers two extra modes you switch on yourself:
- "Secret": the encryption key changes with every message, so a key that leaks later cannot open earlier messages.
- "Top secret": the content never passes through the server at all — it waits on your device and is delivered straight to the other person over a direct connection when you are both online. The server only knows that "a message exists", never its content.
Please note, in every mode: the server still sees a message's metadata — who is writing to whom and when (without it, delivery and notifications cannot work). The extra modes are available in one-to-one chats only, not in groups or business tickets, and are disabled for minors (see section 3).
5. Non-Transferability of Contacts
Tacq's architecture excludes the systemic exchange of your profiles. No one can export your contact list or transfer your communication session to a third party without your knowledge. The connection exists only between you and your interlocutor.
6. Data Deletion
You can block a session or delete your account at any time. Upon account deletion, your Master ID and all associated profiles are permanently erased from our active databases.
7. Children and Child Safety
Tacq is intended for users aged 13 and older; people under 13 cannot create an account or use the app. On first launch we ask only for your age group (see section 3) — never your date of birth. For users identified as minors, the private end-to-end encrypted secret modes are turned off, and communication stays on a moderated channel so that we can act on reports.
We have zero tolerance for child sexual abuse and exploitation (CSAE). You can report abuse from inside the app or by email, and we remove offending content, ban the account, and report to the appropriate authorities where required by law. Full details are set out in our Child Safety Standards.
8. How Data-Protection Laws Apply (GDPR and Others)
Even though we deliberately avoid collecting your name, phone number, or email, some of the limited data we do handle — your Master ID, device and push identifiers, technical logs and the network (IP) addresses our providers process, message metadata, and any content you choose to send — can still count as "personal data" under laws such as the EU/UK GDPR. So we treat that data according to those laws. Our lawful bases are: performing our agreement with you (to deliver your messages and run the service); our legitimate interests (keeping the service secure and preventing spam and abuse); your consent where we ask for it (for example, before you broadcast a geo-tag); and compliance with legal obligations (for example, child-safety reporting). We keep the amount of personal data to the minimum needed — that is the heart of our Zero-PD approach.
9. Your Privacy Rights
Subject to applicable law, you have the right to access the data associated with your account, to correct it, to delete it, to object to or restrict certain processing, and to receive a copy in a portable form. Because we store so little and tie it to an anonymous Master ID, the simplest way to exercise most of these rights is inside the app: you can edit your profiles, block sessions, and delete your account, which erases your Master ID and associated profiles from our active databases. You can also contact us at support@tacq.app. We will not charge you for exercising your rights or treat you differently for doing so. If you are in California, you have the right to know what personal information we hold, to delete it, and to opt out of its "sale" or "sharing" — and we do not sell or share your personal information. If you are in the EU or the UK, you also have the right to lodge a complaint with your local data-protection authority.
10. International Data Transfers
Tacq runs on global infrastructure (such as Google Firebase, and Hetzner in Germany for our own call relay server), so the limited data we process may be stored or handled on servers outside your country, including outside the EU. Where the law requires, we rely on our providers' safeguards for such transfers (for example, standard contractual clauses). By using Tacq, you understand that your data may be processed in other countries whose data-protection laws differ from your own.
11. How Long We Keep Data
We keep data only as long as needed. Envelopes of private messages are deleted from the server as soon as they are delivered, or after a limited time if they are not picked up. Attachments, group messages, business tickets and profiles remain until you delete them or delete your account. Technical logs kept to protect against spam and abuse are retained for a limited period and then removed. When you delete your account, your Master ID and associated profiles are erased from our active databases; residual copies in backups are overwritten in the ordinary course.
12. Who We Are and How to Reach Us
Tacq is operated by the Tacq Team, which is responsible for the data described here. You can contact us about privacy at support@tacq.app, or by post at P.O. Box 5431, Israel. If you have concerns we cannot resolve, you may also contact the data-protection authority in your country.
Last updated: 11 September 2026.