Privacy Policy
How txtBase handles data, purposes, external processing, visibility, retention and your rights.
1. Device, credential and activity data
Ordinary use does not require name or email registration, but an anonymous display does not mean no personal data is processed. We generate and store a browser UUID device ID, server-issued anonymous credentials, joining and last-view times and read state. Poll answers are associated with the device for counting, without exposing that association to other users. Withdrawn votes leave the totals; deduplication records remain until the poll or room is deleted, when selections and operation records are deleted. Replies are ordinary posts. Report records are handled separately.
For access allowances, we record grants, charges, spending and refunds by device, including time, type, count and retry tokens. Initial-trial consumption records prevent repeated grants. Observing AdSense Offerwall state and a claim action is distinct from verifying completed ad viewing.
2. Information you enter and share
We process messages, Topic names and hashtags, polls, room names and icons, public profile handles and uploaded images. Room images accept JPEG, PNG, GIF and WebP up to 5MB. Albums store their name, linked Talk, photos and thumbnails, creation/addition times, expiry and creating/posting devices. Input photos up to 20MB are converted on-device to JPEG, with images up to 2MB, thumbnails up to 128KB and totals of 200 photos and 200MB. Link holders can view/add photos and open linked Talk. Passcodes and handle-recovery backup codes are stored as SHA-256 hashes, not plaintext. A passcode alone is not necessarily server-side access control for someone who knows the URL.
3. Connection, notification and call data
IP, user agent and related information support delivery, security, rate limits, blocking and lawful sender-information handling. We record Post sender details, and Talk/Topic posts also have sender audit data. Enabling notifications stores an FCM token and subscriptions for delivery; you can disable notifications at any time. Private-room notifications can send the room name and message preview to Google with delivery data and show them in your device notification area. Consider visibility on shared devices. Calls send audio and connection data to Cloudflare for participant delivery, temporarily keeping participant and connection IDs. txtBase does not record or transcribe calls.
4. Cookies and browser storage
Cookies and similar storage support anonymous credentials, features and necessary abuse prevention. Advertising also uses them for delivery, impression counts and invalid-click prevention. Device and user IDs, interface, language and display preferences are stored in the browser. Google advertising involves Google’s cookies and settings. You can restrict or delete cookies and stored data in your browser, but this may remove anonymous credentials or participation information and prevent features from working. Non-personalized advertising may also use cookies.
Personal memo text and linked Talk information stay in the browser; the memo feature does not send them to the server or conversation partners. Clearing browser data loses them, and Talk recovery codes cannot restore them. You can delete or export memos from the memo screen. Sharing exported files with another device or service sends their contents to that chosen destination.
5. Purposes
Data supports messages, images, notifications and translation; device sessions; abuse/spam prevention, rate limits and blocking; predefined-word controls for Post; reviewing reports and public Topic safety candidates; lawful infringement handling and orders; necessary advertising measurement; and fixes and improvement. Post keyword controls do not become monitoring of all Talk or Topic messages. Conversation text, shared keys and inferred nationality are not sent for acquisition analytics, or used to reveal nationality/residence automatically or recommend people.
6. Legal basis and definitions
We assess personal information under Japan’s APPI, including information that identifies someone when combined with other data. We also consider IP addresses and device IDs that are personal data under applicable foreign law. For the purposes above, we process information as needed to provide the service, prevent abuse, address rights violations lawfully and meet legal obligations. Applicable legal grounds and consent depend on the purpose; an anonymous display does not remove personal-data protections. Contact info@txtbase.net for an explanation or an objection to processing.
7. External providers
Cloudflare supports storage, processing, delivery and call relay; Vercel delivers/processes pages; Google's Firebase Cloud Messaging delivers notifications; Google reCAPTCHA v3 prevents abuse. Notifications send necessary identifiers such as FCM tokens to Google. reCAPTCHA sends connection/browser information to Google and is also subject to Google's terms and privacy conditions. External transfers are explained even when no message body is processed.
External providers and their processors may process information outside Japan. Operating from Japan does not mean that all data is processed in Japan. Retention, deletion, training use and subprocessors vary by provider contract, settings and policy; we do not promise no retention or no training based on general marketing statements. The information sent and its purposes are described below. Contact info@txtbase.net with processing questions.
8. Translation and AI processing
Optional translation sends original text of messages you can view to Microsoft Azure Translator. Before use we explain the destination, scope, storage and stopping method. The original is authoritative; machine-labelled translations are cached within the room. Changes, deletion, loss of visibility or room deletion invalidate/delete associated translations. A viewer's consent alone is not a processing basis for all participants. Provider-side retention depends on verified actual contracts and settings.
@gpt sends to OpenAI and @gemini to Google your instruction and the limited recent conversation needed for a reply, including other participants' statements. There are size limits; deleted messages, join/leave notices and images themselves are excluded. AI answers are stored in the room and shown to participants. Conversation summaries also send necessary conversation to the selected provider. Single-message summaries send only the chosen text, display on the requesting device and are stored in the room for reuse. Deleting the source message or room deletes the associated summary.
Generated icon prompts go to Cloudflare Workers AI. Selected icons appear in the room, and previous images remain until room deletion to preserve historical message display. Translation, AI and generation choices are separate from ad consent and operator review. Operator translations are also external processing with necessity, a legal basis and access records; translated text alone does not determine a sanction.
9. Advertising and optional tracking
Some screens, including chat screens, display Google Ad Manager advertising. Advertising screens for recharges and generation features use AdSense Offerwall. IP addresses, browser and displayed-page information and identifiers such as cookies are sent to Google for advertising delivery, measurement and abuse prevention. We do not supply conversation or Post text or shared access keys as advertising configuration, and remove room identifiers and query parameters from the page URL supplied to advertising. This does not fully isolate advertising scripts from chat screens. Advertising cookies are subject to the explanation above and Google’s policies and settings.
10. Disclosure and international processing
We disclose data only on a lawful basis, for protection of life, body or property when consent is difficult to obtain, for applicable public-health or child-welfare purposes, lawful public functions, explained necessary outsourcing or separately agreed disclosure. An authority's request is not unconditional authorisation: authenticity, powers, scope and deadlines are checked. International outsourcing and onward transfers require an appropriate applicable basis, such as consent, an adequacy decision or contracts, and required information. Direct collection and later transfers are assessed separately; one country's adequacy decision does not resolve every provider's processing.
11. Topic and private conversation visibility
Topic posts, names, images and polls are visible to visitors who have declared they are 18 or older and agreed to the rules, including adults who have not joined. Search engines, visitors who have not agreed and Open Graph previews receive only a safe, operator-edited overview, not actual posts. Unreviewed hashtags are not automatically published as an overview. Topic notifications exclude bodies, images and unreviewed names, and delivery/connections stop when eligibility expires or is withdrawn. Device IDs/IPs are not published. Use invitation Talk for content you do not want public. Copies made externally or already downloaded cannot be guaranteed recoverable.
A room URL is a key for anyone who knows it. Private-room links in Topics may be hidden with an explanation; that is separate from deleting the message. Private Talk has no public directory, person search or recommendations of unknown adults, and rooms are not duplicated by language or age. Protection mode assists device operation and does not replace legal consent or server authorisation.
12. Public review and reports
Only public Topic posts may be reviewed, analysed and selected by rules for safety, abuse prevention and usability, whether or not they have been reported. We do not roam private rooms, Post bodies, deleted/non-public posts or private conversations behind links. Private content is reviewed only when reported. Eligible Topic viewers, private room participants and album link holders may report their respective content. Non-user infringement reports use a separate safe channel and do not authorise listing all private messages. We assess originals and necessary context, not translations alone.
Operator Topic viewing records time, room and action, without copying message text into the record, and is deleted after 1 year. Candidate displays do not create ongoing separate body copies. Reported message copies last 90 days, even if the source or room is deleted, and report/action records last 1 year. We do not save message bodies from encrypted rooms that we cannot decrypt. Reported album photo copies last 90 days; reasons, posting device, action and viewing records last 1 year. These copies are not accessible through ordinary shared links. Device restrictions record reason, duration and action time, retained until 90 days after lifting/expiry; post distribution scope is recorded while the post remains. Reporters are not disclosed to the reported party, and reports or rule matches alone do not automatically delete or suspend.
13. Conversation and media retention
Private rooms stop access at expiry and are removed by scheduled cleanup. Messages without an expiry are stored indefinitely, so you may request deletion. An unused room with no posts and no confirmed use by another device is periodically removed only after at least 7 days of confirmed inactivity; uncertainty prevents that cleanup. Topic rooms are periodically removed if there have been no posts for at least 72 hours since creation, or if there is only 1 participating device, at most 2 posts and at least 48 hours of inactivity, except while connected or with an open poll. News candidates leave the list after 48 hours; Topics where conversation has started are not deleted for that reason.
Albums stop delivery at 30 days or the linked Talk's expiry/deletion, whichever is earlier. Photos, thumbnails, metadata and unfinished uploads are periodically removed; congestion or failures may delay file deletion but not authorise delivery after expiry. Translation/summary copies follow source and room deletion, while previous generated icons last until room deletion. Report copies and individual legal holds are distinct from ordinary deletion.
14. Audit, credential and consent retention
IP addresses and user agents for Talk and Topic posts and Anonymous Post submissions are normally deleted by periodic cleanup 180 days after posting or sending. Specific lawful preservation is subject to the exception below. FCM tokens are retained until notifications are disabled or no longer needed, then deleted with unnecessary subscriptions. Device-transfer tokens are deleted 30 minutes after issue. Allowance grant and consumption history is kept for 90 days; initial free-trial usage records have no fixed expiry to prevent repeated grants.
Public Topic declaration and agreement records contain only the necessary device, accepted version, time, expiry, withdrawal status and operator-imposed Topic suspension status. Agreement lasts 30 days. Ordinary expired records are deleted by periodic cleanup; operator-imposed suspensions are retained until lifted. We do not provide guardian identity checks or verifiable parental consent. Retention may be extended only for lawful orders or specific lawful preservation, recording the scope, basis and deadline. This does not justify continuous monitoring or blanket long-term storage of private communications.
15. Security and incident handling
Controls include HTTPS, hashed codes, room-separated message storage, server authorisation for inbox/handle operations, CSP script/outbound restrictions and allowed image-URL checks. Allowing an image URL does not guarantee safe image content, and anonymity or absolute confidentiality is not guaranteed. We manage access, deletion and processors and assess incidents for notification to authorities and affected people where required by applicable law.
16. Controls and your rights
You can reset the device ID, disable room/browser notifications, leave rooms, delete individual inbox messages and delete/export memos. Leaving deletes that room's display name, icon, personal passcode and last-opened record. These actions differ from erasing all server data; expiring rooms stop access at their deadline. Contact us about whole-room deletion or other participants' posts.
Applicable law may give rights of access, correction, erasure, restriction, objection, portability and withdrawal. Contact info@txtbase.net safely about the relevant data. Credentials or ownership evidence verify identity and scope with minimal information, without automatically disclosing others' data. If that is impossible we offer minimal alternative checks, normally without new identity documents. We respond within applicable deadlines and explain refusals and appeals. Legal holds and others' rights are handled as distinct exceptions; you may complain to a competent authority.
17. Children, age and parental consent
Private Talk has no blanket 18+ restriction, but it is not a child-specific service or a system that checks age and region and obtains parental consent. Protection lock only assists with navigation restrictions in the current browser; it does not establish age, guardian consent or safety of the whole device. Uses that require a verifiable parental-consent procedure under applicable law, such as covered processing of data from children under 13 in the United States, are outside the supported scope. Contact info@txtbase.net about a child’s information. We address applicable requests to inspect or delete data without unconditionally disclosing other participants’ entire conversations.
Public Topics use a self-declaration of being 18 or older and agreement to the rules, without an external age-verification service. This procedure does not collect identity documents, face images or birth dates, and we do not describe it as verification of actual age. Declaration and agreement are recorded on the server separately from device-operation credentials. Age declarations are not reused for ads or public profiles. Where a region or feature requires stronger age assurance, self-declaration is not treated as sufficient; availability conditions require separate assessment. Ordinary device revocation records are removed in scheduled cleanup once 30 days have elapsed after revocation. Operator-imposed Topic suspension records remain until the operator lifts the restriction; declaring again does not lift it. Suspension applies to the same device credential and does not identify the person across other devices.
18. Changes, operator and contact
We give advance notice of material changes, their timing and required choices, and obtain separate consent where required. Continued use alone is not consent to new optional processing. This page displays the effective version and date. The operator is a sole proprietor trading as txtBase事務局; contact info@txtbase.net. On a request from the person concerned about retained personal data, we provide the proprietor’s legal name, address and other legally required information by email without delay.