Tacq Privacy Policy
The Tacq Team has developed this platform to restore your control over your digital space. Our core principle is Zero PD (Zero Personal Data). We do not just promise not to share your data; we build our system so that we do not collect it in the first place.
Our internal privacy standards are designed in the spirit of the world’s strictest data protection regulations, including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), as our architecture physically excludes the collection of personal information by default.
1. What We DO NOT Collect
Tacq does not request, verify, or store:
- Your phone number.
- Your real email address.
- Links to your social media profiles.
- Information about your real name or location (unless you voluntarily choose to broadcast a geo-tag within a specific group). We do not ask for your date of birth either — only your age group (see section 3).
2. How We Identify You (Master ID System)
Instead of traditional logins, we generate a random alphanumeric code (Master ID) for your device. This code is your access key. We do not ask for or store a link between it and your real-world identity — no name, phone number, or email is attached to it. Even so, a Master ID can still qualify as personal data, so we protect it accordingly (see section 8).
3. What Data We Store
To facilitate communication, we store only the information you voluntarily create within the platform:
- Contextual Profiles (Personas): Nicknames and avatars you set for personal sessions or specific business groups.
- Messages and Media: Text, voice messages, and files you exchange in chats.
- Technical Metadata: Timestamps of sent messages (for chat sorting) and system logs to protect against spam.
- Age Group (Tier): on first launch we ask for your age group once, to keep minors safe. We store only the group (e.g., "13–15" or "18 or older"), never your date of birth. Additional limits apply to minors (for example, end-to-end encrypted secret levels are disabled).
4. Where Your Messages are Stored and Who Has Access
By default (Regular mode). Your messages and media are stored on secure cloud servers (Google Firebase infrastructure) and encrypted at rest. Access to the content of any session is strictly limited by database rules: only the direct participants of that session can read the messages. The Tacq Team does not use automated scanners to analyze the content of your private conversations for marketing or profiling purposes.
For anything especially private, you can switch a one-to-one chat to one of two secret modes yourself:
- "Secret" (end-to-end encryption): the message is encrypted on your device; the server stores only the ciphertext, which it cannot read, and deletes it as soon as the message is delivered (or after a short time if it is never picked up). The private keys never leave your device.
- "Top secret" (content not on the server): in addition to end-to-end encryption, the content never passes through the server at all — it waits on your device and is delivered straight to the other person over a direct connection when you are both online. The server only knows that "a message exists", never its content.
Please note, in every mode: the server still sees a message's metadata — who is writing to whom and when (without it, delivery and notifications cannot work). Secret modes are available in one-to-one chats only, not in groups or business tickets. The history of secret messages is stored only on the device where the chat was started; there is no cloud backup, so if you lose or change that device, this history is gone. Secret modes are disabled for minors (see section 3).
5. Non-Transferability of Contacts
Tacq's architecture excludes the systemic exchange of your profiles. No one can export your contact list or transfer your communication session to a third party without your knowledge. The connection exists only between you and your interlocutor.
6. Data Deletion
You can block a session or delete your account at any time. Upon account deletion, your Master ID and all associated profiles are permanently erased from our active databases.
7. Children and Child Safety
Tacq is intended for users aged 13 and older; people under 13 cannot create an account or use the app. On first launch we ask only for your age group (see section 3) — never your date of birth. For users identified as minors, the private end-to-end encrypted secret modes are turned off, and communication stays on a moderated channel so that we can act on reports.
We have zero tolerance for child sexual abuse and exploitation (CSAE). You can report abuse from inside the app or by email, and we remove offending content, ban the account, and report to the appropriate authorities where required by law. Full details are set out in our Child Safety Standards.
8. How Data-Protection Laws Apply (GDPR and Others)
Even though we deliberately avoid collecting your name, phone number, or email, some of the limited data we do handle — your Master ID, device and push identifiers, technical logs and the network (IP) addresses our providers process, message metadata, and any content you choose to send — can still count as "personal data" under laws such as the EU/UK GDPR. So we treat that data according to those laws. Our lawful bases are: performing our agreement with you (to deliver your messages and run the service); our legitimate interests (keeping the service secure and preventing spam and abuse); your consent where we ask for it (for example, before you broadcast a geo-tag); and compliance with legal obligations (for example, child-safety reporting). We keep the amount of personal data to the minimum needed — that is the heart of our Zero-PD approach.
9. Your Privacy Rights
Subject to applicable law, you have the right to access the data associated with your account, to correct it, to delete it, to object to or restrict certain processing, and to receive a copy in a portable form. Because we store so little and tie it to an anonymous Master ID, the simplest way to exercise most of these rights is inside the app: you can edit your profiles, block sessions, and delete your account, which erases your Master ID and associated profiles from our active databases. You can also contact us at support@tacq.app. We will not charge you for exercising your rights or treat you differently for doing so. If you are in California, you have the right to know what personal information we hold, to delete it, and to opt out of its "sale" or "sharing" — and we do not sell or share your personal information. If you are in the EU or the UK, you also have the right to lodge a complaint with your local data-protection authority.
10. International Data Transfers
Tacq runs on global infrastructure (such as Google Firebase and Twilio), so the limited data we process may be stored or handled on servers outside your country, including outside the EU. Where the law requires, we rely on our providers' safeguards for such transfers (for example, standard contractual clauses). By using Tacq, you understand that your data may be processed in other countries whose data-protection laws differ from your own.
11. How Long We Keep Data
We keep data only as long as needed. Regular messages and profiles remain until you delete them or delete your account. Secret (end-to-end encrypted) messages are deleted from the server as soon as they are delivered, or after a short time if they are not picked up. Technical logs kept to protect against spam and abuse are retained for a limited period and then removed. When you delete your account, your Master ID and associated profiles are erased from our active databases; residual copies in backups are overwritten in the ordinary course.
12. Who We Are and How to Reach Us
Tacq is operated by the Tacq Team, which is responsible for the data described here. You can contact us about privacy at support@tacq.app, or by post at P.O. Box 5431, Israel. If you have concerns we cannot resolve, you may also contact the data-protection authority in your country.
Last updated: 19 July 2026.