← Back to Taupe

Privacy Policy

Last updated: September 2, 2026

This Privacy Policy describes how Taupe ("we", "us", or "our") handles your data when you use our web application (the "Service"). We are committed to protecting your privacy and minimizing data collection.

1. Information We Do NOT Collect

Taupe is designed to be privacy-first. We do not collect or store the following information:

  • Email addresses or phone numbers.
  • Plain-text messages or files (except unencrypted). All messages and files are End-to-End Encrypted (E2EE) using WebCrypto (AES-GCM). We cannot read your messages, and we do not have access to your encryption keys.
  • Your contact list or location data.

2. Information We Collect

To provide the Service, we temporarily collect and store the following technical metadata:

  • Account Identifiers: A randomly generated 16-digit private number and an 8-digit public number. These are not linked to your real identity.
  • IP Addresses: Used solely for rate-limiting (preventing spam and brute-force attacks) and security purposes.
  • Device Metadata: Randomly generated device names, public encryption keys, and last-seen timestamps to manage your sessions.
  • Encrypted Data: Your encrypted messages (.bin format) and media files, which are stored on our servers but cannot be decrypted by us.
  • Unencrypted Data: Your unencrypted messages and media files will be stored on our servers.

3. Third-Party Services and CDNs

To display content correctly, our application loads static assets (such as icons, fonts, and emoji graphics) from third-party Content Delivery Networks (CDNs). When you load the application, your browser connects to these services, which may temporarily log your IP address:

  • Cloudflare / cdnjs: Used to serve Font Awesome icons.
  • jsDelivr: Used to serve Twemoji (emoji graphics) and client-side libraries.
  • Giphy API: Used for searching GIF images.

We do not control the privacy practices of these external services and encourage you to review their respective privacy policies.

4. Data Retention and Deletion

You have full control over your data. Messages can be manually deleted, or set to "Burn after read" (BAF) or auto-delete after a specified time. When a message or file is deleted, it is permanently removed from our servers.

If you choose to delete your account, all associated chats, encrypted files, and device information are permanently erased from our database.

5. Cookies

Taupe uses a strictly necessary httpOnly cookie to store your authentication JWT token. This cookie is required for the Service to function and is not used for tracking.

6. Children's Privacy

The Service is not intended for individuals under the age of 13. We do not knowingly collect data from children. If you believe a child has provided us with information, please contact us so we can delete it.

7. Contact Us

If you have questions about this Privacy Policy, please open an issue on our GitHub repository or contact us at: taupe.app@proton.me