txtile.eth

$ cat PRIVACY_POLICY.md

Privacy Policy

Last updated: June 11, 2026

1. Overview

txtile.eth ("we", "our", or "the app") is a decentralized, end-to-end encrypted messaging application built on the XMTP protocol and Base network. We are committed to protecting your privacy. This policy explains what data we collect, how it is used, and your rights.

Key principle: We collect as little data as possible. Most of your data lives on decentralized networks, not our servers.

2. Data We Collect

2.1 Data You Provide

  • Display name (stored locally on your device only)
  • Contacts you add (stored locally on your device only)
  • Email or phone number used to create your account via Privy (handled by Privy — see Section 5)
  • If you report or block a user, we receive the target wallet address, conversation identifier, your optional reason, and a short content preview needed to investigate abuse

2.2 Data Generated Automatically

  • Your wallet address and Privy user ID used to identify your account and XMTP inbox
  • XMTP inbox ID (created by XMTP protocol, stored on XMTP network)
  • Push notification subscription token (stored on our server, linked to your wallet address)

2.3 Data We Do NOT Collect

  • Message contents during ordinary use — messages are end-to-end encrypted via XMTP and are not readable by Txtile
  • Private keys — never transmitted to our servers
  • Location data
  • Device identifiers beyond what is required for push notifications
  • Browser history or cross-app tracking

3. How We Use Your Data

  • Push notifications: Your wallet address and push subscription token are stored solely to deliver message notifications when the app is closed. You can disable this at any time in Settings.
  • Authentication: Your wallet address is used to identify your XMTP inbox. We do not use it for marketing or analytics.
  • Payments: Crypto transactions are processed on-chain via Base and Solana networks. For app-initiated transfers, we process limited payment audit fields including amount, asset, wallet addresses, transaction hashes, and transfer status so activity is visible, auditable, and supportable.
  • Safety and abuse handling: If you use the in-app report or block tools, we process the abuse-report payload so we can review it within 24 hours and suspend abusive users from the txtile app interface when necessary.

4. Data Storage & Retention

  • Messages: Stored on XMTP's decentralized network and encrypted. Txtile does not have routine access to message content. A short excerpt is sent to our moderation tooling only when a user deliberately submits a report or block report.
  • Contacts & settings: Stored locally on your device (localStorage). Never transmitted to our servers.
  • Moderation reports: Abuse-report payloads are stored in our server-side moderation tooling so we can investigate reports and act on them.
  • Payment audit events: App-initiated payment metadata may be stored in our server-side payment event tooling and locally on your device. Message contents remain encrypted.
  • Push tokens: Native APNs tokens are stored with your authenticated account and registered with Txtile's XMTP notification service only after you enable notifications. Browser push subscriptions may be stored temporarily by serverless infrastructure.
  • Wallet: Non-custodial embedded wallet managed by Privy. See Privy's privacy policy.

5. Third-Party Services

Privy (privy.io)

Authentication and embedded wallet creation

policy →

XMTP (xmtp.org)

Decentralized encrypted messaging protocol

policy →

Base / Coinbase (base.org)

Blockchain network for wallet-connected transfers

policy →

Vercel (vercel.com)

App hosting and serverless functions

policy →

6. Permissions (Mobile App)

The txtile.eth mobile app requests the following permissions:

CameraTo take photos and videos to share in encrypted messages
Photo LibraryTo select images to share in conversations
NotificationsTo alert you when new encrypted messages arrive

All permissions are optional and can be denied without affecting core functionality.

7. Data Sharing

We do not sell, rent, or share your personal data with third parties for marketing purposes. Data may be shared only:

  • With service providers listed in Section 5, solely to operate the app
  • If required by law or valid legal process

8. Your Rights

  • Delete your account: Open Settings → Danger Zone → Delete account to permanently remove your Privy account from this app.
  • Clear local device data: Logging out removes local session data from this device.
  • Disable notifications: Open Settings in the app → Notifications → disable. Or revoke in your device's system settings.
  • Privacy requests: To request access to or deletion of server-side support, moderation, payment, or notification data, email us at the address below.

9. Children's Privacy

txtile.eth is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us.

10. Security

All messages are end-to-end encrypted using the XMTP MLS protocol. Your private keys never leave your device. We use HTTPS for all communications. Push notification payloads contain only sender metadata — never message content.

11. Changes to This Policy

We may update this policy from time to time. We will notify you of significant changes via the app. Continued use after changes constitutes acceptance of the updated policy.

12. Contact

For privacy questions or data deletion requests:

ENS: txtile.eth
Email: support@txtile.xyz
App: https://txtile.xyz

© 2026 txtile.eth — All rights reserved