txtile.eth

$ cat PRIVACY_POLICY.md

Privacy Policy

Last updated: August 22, 2026

1. Overview

txtile.eth ("we", "our", or "the app") is a decentralized, end-to-end encrypted messaging application built on the XMTP protocol and Base network. We are committed to protecting your privacy. This policy explains what data we collect, how it is used, and your rights.

Key principle: We collect as little data as possible. Most of your data lives on decentralized networks, not our servers.

2. Data We Collect

2.1 Data You Provide

  • Display name (stored locally on your device only)
  • Contacts you add (stored locally on your device only)
  • Email or phone number used to create your account via Privy (handled by Privy — see Section 5)
  • If you report or block a user, we receive the target wallet address, conversation identifier, your optional reason, and a short content preview needed to investigate abuse

2.2 Data Generated Automatically

  • Your wallet address and Privy user ID used to identify your account and XMTP inbox
  • XMTP inbox ID (created by XMTP protocol, stored on XMTP network)
  • Push notification subscription token, if you enable notifications (stored on our server and linked to your wallet address)
  • Limited product-interaction events such as feature actions, referral or link identifiers, asset, amount, entry source, wallet address, and conversation identifier when those fields are needed to measure an in-app flow

2.3 Data We Do NOT Collect

  • Message contents during ordinary use — messages are end-to-end encrypted via XMTP and are not readable by Txtile
  • Private keys — never transmitted to our servers
  • Location data
  • Device identifiers beyond what is required for push notifications
  • Browser history or cross-app tracking

3. How We Use Your Data

  • Push notifications: Your wallet address and push subscription token are stored solely to deliver message notifications when the app is closed. You can revoke notification permission in iPhone Settings or your browser settings.
  • Authentication: Your wallet address is used to identify your account and XMTP inbox. We do not sell it or use it for cross-company advertising.
  • Payments: Crypto transactions are processed on-chain via Base and Solana networks. For app-initiated transfers, we process limited payment audit fields including amount, asset, wallet addresses, transaction hashes, and transfer status so activity is visible, auditable, and supportable.
  • Safety and abuse handling: If you use the in-app report or block tools, we process the abuse-report payload so we can review it within 24 hours and suspend abusive users from the txtile app interface when necessary.
  • Product interaction: We use limited first-party feature and referral events to understand whether onboarding, messaging, sharing, and payment flows complete. We do not use this data for third-party advertising or cross-app tracking.

4. Data Storage & Retention

  • Messages: Stored on XMTP's decentralized network and encrypted. Txtile does not have routine access to message content. A short excerpt is sent to our moderation tooling only when a user deliberately submits a report or block report.
  • Contacts & settings: Stored locally on your device (localStorage). Never transmitted to our servers.
  • Moderation reports: Abuse-report payloads are stored in our server-side moderation tooling so we can investigate reports and act on them.
  • Payment audit events: App-initiated payment metadata may be stored in our server-side payment event tooling and locally on your device. Message contents remain encrypted.
  • Push tokens: Native APNs tokens are stored with your authenticated account and registered with Txtile's XMTP notification service only after you enable notifications. Browser push subscriptions may be stored temporarily by serverless infrastructure.
  • Wallet: Non-custodial embedded wallet managed by Privy. See Privy's privacy policy.
  • Retention: Account-linked server metadata is retained while your account is active and removed with account deletion unless a limited record must be kept for security, fraud prevention, dispute handling, or legal compliance. XMTP messages and public blockchain records follow those networks' retention properties and cannot be erased by Txtile.

5. Third-Party Services

Privy (privy.io)

Authentication and embedded wallet creation

policy →

XMTP (xmtp.org)

Decentralized encrypted messaging protocol

policy →

Base / Coinbase (base.org)

Blockchain network for wallet-connected transfers

policy →

Vercel (vercel.com)

App hosting and serverless functions

policy →

6. Permissions (Mobile App)

The txtile.eth mobile app requests the following permissions:

CameraTo take photos and videos to share in encrypted messages
Photo LibraryTo select images to share in conversations
NotificationsTo alert you when new encrypted messages arrive

All permissions are optional and can be denied without affecting core functionality.

7. Data Sharing

We do not sell, rent, or share your personal data with third parties for marketing purposes. Data may be shared only:

  • With service providers listed in Section 5, solely to operate the app
  • If required by law or valid legal process

8. Your Rights

  • Delete your account: Open Settings → Danger Zone → Delete account to remove your Privy account and Txtile account metadata. Completed blockchain transactions and encrypted messages already distributed through XMTP cannot be removed from those networks.
  • Clear local device data: Open Settings → Device Data → Clear data on this device. This signs you out and removes local contacts, preferences, payment history, and the local encrypted XMTP cache without deleting your account.
  • Disable notifications: Revoke notification permission in your device's system settings or browser settings.
  • Privacy requests: To request access to or deletion of server-side support, moderation, payment, or notification data, email us at the address below.

9. Children's Privacy

txtile.eth is intended only for users who are at least 18 years old. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, please contact us.

10. Security

Messages are end-to-end encrypted using the XMTP MLS protocol. Txtile does not receive your seed phrase or raw private keys; wallet operations are handled by Privy or your connected wallet provider. We use HTTPS for all communications. Push notification payloads contain only sender metadata — never message content.

11. Changes to This Policy

We may update this policy from time to time. We will notify you of significant changes via the app. Continued use after changes constitutes acceptance of the updated policy.

12. Contact

For privacy questions or data deletion requests:

ENS: txtile.eth
Email: support@txtile.xyz
App: https://txtile.xyz

© 2026 txtile.eth — All rights reserved