TapXO Privacy Policy

Last updated: July 26, 2026

TapXO is a game with optional online play, public community features, and private encrypted communities. No account is required.

Information TapXO processes

TapXO creates a pseudonymous device identifier and security credentials on your device. When you use online play or server-backed community features, the service may process that identifier, display name, session data, IP address, app version, device platform, game activity, room membership, abuse-prevention signals, and push-notification token.

Public community messages and game challenges are visible to participants and may be stored by TapXO for delivery, moderation, and abuse prevention.

Private encrypted communities

Private community messages, direct messages, replies, receipts, and supported small attachments are encrypted and signed on participating devices using Messaging Layer Security (MLS). These private rooms are designed to operate without a central chat database.

Delivery can use three independent routes: a live, stateless ciphertext-only gateway hosted on Render, multiple independently operated Nostr relays, and nearby Bluetooth transports. The Render gateway forwards packets only to currently connected route subscribers and does not save those chat packets or decentralized room membership for history. Nostr retention is controlled by each relay. Nearby devices can temporarily carry encrypted packets for up to 24 hours.

Message text and sealed control details are not intended to be visible to these carriers. Ordinary room lifecycle controls are sealed with MLS epoch-derived keys. Admission uses a secret invite capability, while direct-message invitations, Welcome delivery, and reports use recipient-addressed encryption where applicable.

Delivery metadata

Encryption does not make a device anonymous. Depending on the route, TapXO infrastructure, Nostr operators, nearby peers, and network providers may observe opaque room or route identifiers, envelope or control identifiers, recipient/routing tags, ciphertext or packet size, timestamps, delivery acknowledgements, rate-limit events, source IP or network data for internet connections, and connection or proximity information. Nearby packets also expose bounded hop/TTL information. Infrastructure may retain connection and security logs even though the live TapXO gateway does not persist private chat packets.

Reports and moderation

TapXO cannot silently read private encrypted conversations. When you choose Report, the app first warns that the selected plaintext and evidence will be disclosed. After you confirm, the app sends a recipient-addressed encrypted copy to the community owner and separately attempts an authenticated submission to TapXO moderation. The app identifies whether the TapXO submission was sent or is pending. The report can include the selected plaintext, reason, ciphertext evidence, pseudonymous device identifiers, and message or routing identifiers; it does not disclose unselected room messages.

Public community content and legacy server-backed reports may be stored and reviewed by TapXO for moderation and abuse prevention.

Local storage and deletion

Private-room identities, room state, recent history, and pending delivery records are stored in an encrypted device vault. Nearby courier packets are retained for no more than 24 hours and are encrypted at rest. Leaving a room removes its local room data after the owner confirms membership removal. The in-app privacy wipe erases encrypted chat identities, rooms, history, invites, reports, and courier records on that device.

Services that still use servers or databases

The database-independent design applies to private encrypted chat, not the whole TapXO app. Online matchmaking, the public lobby, game coordination, leaderboards and progression, push notifications, advertising and consent, analytics, abuse prevention, legacy rooms, and confirmed TapXO moderation reports may use TapXO or third-party servers and databases.

Service providers

Depending on your choices and platform, TapXO may use Apple or Google platform services, Firebase Analytics and Messaging, Google Mobile Ads and consent tools, Render hosting, and independent Nostr relays. Their processing is governed by their own privacy terms.

Children and family controls

TapXO asks for an age band before social features are opened. Freeform chat and emotes are off by default for children under 13 and require an adult action to enable. Parents can disable those features again in the app.

Security and limitations

No system can guarantee absolute security or delivery. Private encrypted chat is currently identified in the app as a beta pending an independent cryptographic review. Physical iPhone-to-Android Bluetooth interoperability and background behavior still require completion of the release device matrix. Public rooms are not end-to-end encrypted. TapXO is inspired by BitChat’s transport-diversity goals but does not use or claim BitChat wire compatibility.

Your choices

You can block participants, report messages, leave communities, disable family social features, revoke notification or Bluetooth permissions in system settings, or use the privacy wipe. You can also uninstall TapXO to remove local app data.

Contact and updates

For help or a privacy request, use the TapXO support page. Material policy changes will be posted here with a new effective date. Community features separately require acceptance of the current versioned Terms and Community Guidelines.

Community Guidelines · Terms