What we can collect is very little. So here it is, in full.
This policy is short because there is very little we can collect. The list below leaves nothing out. The full technical boundary lives in the threat model; to verify with your own hands, go to the public verification page.
Last updated: 2026-09-22
Identity: there are no accounts
默·Tacet has no sign-up form, no email, no name. Your identity is an anonymous number generated randomly on the server, connected to your passphrase by a one-way hash. One passphrase maps to exactly one account; we cannot, and never will, know who is using it.
Your passphrase never exists in any of our systems: what travels online is its hashed value (derived with memory-hard Argon2id since 2026-09-10; earlier accounts upgrade automatically on their next login), and the server stores the result of hashing that value once more. These hashes cannot be reversed into the passphrase by design, so there is no "forgot passphrase" reset service.
What we collect
How long each item is kept
Principle: content exists only to provide the feature you asked for; when you delete, it is erased. Below is the actual retention of every item, with no boilerplate.
What we do not collect
How your entries are protected
Keys are generated on your device: the wrapping key is derived from your passphrase with Argon2id (a memory-hard KDF; earlier accounts use PBKDF2 with 600,000 iterations and upgrade automatically on their next login). Entries are encrypted with AES-GCM before they ever leave the device. From start to finish, the server touches only ciphertext.
The precise boundary of "the server cannot read it" (including the conditions under which it holds even against a malicious server) is written in the threat model; you can unwrap and re-verify your encrypted backup with your own hands on the public verification page at any time.
The decryption key stays on your device (the cost of local mode, stated honestly in the threat model). Bound accounts always have "lock on open" enabled: the key is immediately sealed with your PIN, no usable decryption key remains in device storage, and the next open asks for the PIN to unlock. This setting affects only this device and shares the same PIN as login; it cannot be turned off for bound accounts (pure-local mode is not affected). Until an older account completes its one-time PIN setup (guided in the app), a key briefly remains in device storage.
When signing out of this device, you can also choose to erase the journal data on it: the sign-out confirmation in "Devices and sign-ins" inside the app offers an "Also erase the data on this device" option. When checked, entries, image attachments, and the local key are removed from this device immediately; left unchecked (the default), the words stay on this device and belong only to you.
Offline and cache
Tacet can be added to your device's home screen and used as an app. To keep it open even offline, the browser caches the application shell (HTML, CSS, JavaScript) locally. That cache is managed by a Service Worker served from the same origin as the page: it caches the app shell only, and never your journal entries, keys, or passphrases; when online, the app always checks with the server for the latest version, and the cache is only the offline fallback. These pages (including this one) and the share reader never enter any cache. Clearing your browser data removes this cache as well.
The exception when you pay
The yearly plan is billed through Polar. A receipt needs an email; it lives only in Polar, not in our database. After a payment is redeemed, a hash of the payment proof is linked to your anonymous account: "that this identity has paid" becomes linkable. Your journal content remains unreadable. This is the structural exception that comes with paying, written here, not hidden elsewhere.
Payment data goes only to Polar: as merchant of record, Polar alone receives your card number and checkout details; we neither store nor touch them, and refunds, taxes, and payment disputes are carried by Polar under its own policies. Paid status only changes the backup and share quota caps and has zero connection to journal content: the account number is still generated randomly on the server, and entries are encrypted on the device before they ever leave it, paid or not.
Share links
Sharing is available after binding an account (pure local mode has no such option). When you publish an entry as a share link, the server keeps: the hash of the share code, an encrypted wrapping, and a ciphertext snapshot of that entry. A reader needs both the link and your share passphrase to decrypt it locally in the browser; the server can read neither. A share is a snapshot: later edits and deletions do not sync, expiry is tiered by plan (free: 7 days by default; annual pass: up to 90 days), and you can revoke it in the app at any time.
Anyone holding the link can report it: the link alone is enough, no share passphrase required, and we cannot and never use a report to decrypt content. Once a report is verified against the hash, the link immediately loses its read path (the reader shows "taken down after a report"); the report record (hash, optional note) is removed together with the link. We cannot, and never will, read any shared content out of a report.
Deletion
You can delete your account in the app at any time: the account row, all encrypted backups, and login credentials are erased immediately, with no retention period; the share links you created and their report records are removed as well. We also never delete any entry on your behalf; deletion is always your decision and your action.
Service and operator
This service, 默·Tacet (tacet.ink), is operated by an individual based in Taiwan. Service contact: support@tacet.ink; see the terms of service.
Infrastructure
The service runs on Cloudflare (Workers, D1, Pages, R2) with TLS for the entire transfer. Where data is processed is determined by the Cloudflare edge network.
Listed formally, everyone who can touch your data is exactly these two:
The billing email is kept by Polar under its own privacy policy; apart from this, no third party touches your data.
Your rights
The anonymous design is itself the strongest data protection: we cannot know who you are, so we cannot leak, resell, or hand over your journal. Within that anonymity, you still hold these practically exercisable rights:
Legal basis
Our operation and legal entity are in Taiwan, and the governing law is the law of Taiwan (see the terms of service). Taiwan's Personal Data Protection Act is the legal basis for how we process data: we collect only what is necessary to provide the service (data minimization), disclose it honestly and plainly (this page), and provide access and deletion within what is actually possible. Cross-border processing is carried by Cloudflare's global infrastructure; this is the existing reality of every web service, stated as it is, without promises that outrun the facts.
We hold ourselves to the standards of the GDPR: minimal collection, encryption, explicit retention periods, and deletion and portability that actually work. To be precise, the EU's GDPR does not directly apply to an operator based in Taiwan with no EU presence (Taiwan is not on the EU adequacy list), so this page says "held to GDPR standards, jurisdiction stated honestly" rather than "GDPR compliant". That wording is part of the brand: never claim what you do not have.
If a breach ever happens
The worst case is the first line of the threat model: the database holding ciphertext and hashes is stolen, and what leaves is a box of ciphertext. Even then we will state the facts: within a reasonable time after confirming an incident, we will publish on the threat model page and the introduction page what was affected, whether content could be read, and what you can do, and coordinate the investigation with Cloudflare. With no email list we cannot notify anyone individually; please rely on announcements rather than proactive notices. We also ask users to treat passphrase strength as the first line of defense: with a strong passphrase, a stolen box of ciphertext stays sealed.
Boundary statement
默·Tacet is a writing tool. It is not medical care, psychotherapy, or crisis intervention, and it cannot provide any emergency help. If you are in danger or in deep distress, please contact professional help channels in your region.
Changes to this policy
If this policy changes in substance, we will update this page and change the "last updated" date. With no account system and no email list, we cannot notify you proactively; bookmarking this page and returning once in a while is all we can suggest.