TillTom

Privacy Policy

Last updated: 11 July 2026. This explains what TillTom does and doesn’t do with your information. It’s written to be honest, including the inconvenient parts.

Short version

No account or verified identity

TillTom needs no registration. There are no usernames, passwords, profiles, friend lists, or verified contact details. A nickname you enter for a chat is only a display label so the two participants can tell the chat apart. It is not verified; use a first name or situational label if you like, but avoid contact details or sensitive information.

What is stored on your device

Your browser uses local storage for a random device token, a list of your known rooms, and, for each chat, a participant token, the chat’s encryption key, your nickname, the other nickname when known, and message-position information. During joining, the key may also be held briefly in session storage so the browser can move from the QR confirmation screen into the chat.

These records live in that browser only. There is no account backup and no cross-device recovery. If you clear browser data, use a private window that you then close, or switch devices, access to those chats is lost.

What is stored on the server

The server stores what is needed to run a temporary room: the room’s lifecycle state and timers, participant records, the two participants’ nicknames in plain text as display labels, message sequence information, and encrypted message payloads. The server does not store the chat’s encryption key and cannot read or recover encrypted message content from the server alone.

Encryption, stated plainly

Messages are encrypted and decrypted in your browser. The server relays and stores encrypted payloads and does not store the key, so we cannot provide a readable transcript if access is lost. Because TillTom has no out-of-band identity check, we do not claim this rules out every active man-in-the-middle attack, and we do not use the unqualified phrase “end-to-end encrypted.” See the Encryption Explainer.

Metadata and logs

Some metadata necessarily exists: the existence and timing of rooms and messages, room state, nicknames, message counts and sequence numbers, approximate request times, and technical request information. IP addresses and server logs may exist at the web-server, hosting, CDN, or security layer. Where IP-derived data is stored in the TillTom database for rate limiting or abuse prevention, it is stored as a salted hash, not as a raw address.

Metadata may be used to operate the service, apply rate limits, investigate abuse, debug reliability problems, protect the site, and comply with lawful obligations.

Lifecycle and deletion

Unused QR waiting rooms expire after 10 minutes. Active chats expire 24 hours after the second person joins, unless either person ends the chat earlier. Either participant can end the chat for both people. After a chat ends or expires, encrypted messages are deleted by routine cleanup, targeted immediately and at most within 24 hours.

Temporary does not mean impossible to save. The other participant can screenshot, copy, photograph, or otherwise keep what appears on their device.

Removing a chat from your device

“Remove from this device” deletes local access and the dashboard entry for ended or expired chats in your browser only. It does not affect the other participant or the server’s room state.

Cookies, analytics, and advertising

TillTom uses Google Analytics on public information pages to understand basic site traffic. We do not load Google Analytics on chat, QR creation, dashboard, API, or admin pages. TillTom does not use advertising cookies, ad retargeting, or social-media tracking pixels. The app uses browser storage to keep the local device and room records described above.

Sharing and disclosure

We do not sell personal information. We may disclose limited information where needed to operate, host, secure, or troubleshoot the service; to respond to lawful requests; to enforce these terms; or to protect users, the service, or others from abuse, fraud, security threats, or legal harm.

Children and sensitive use

TillTom is not designed for children, sexual content involving minors, medical, legal, financial, emergency, workplace-compliance, or other sensitive regulated communications. Do not use TillTom if your situation requires identity verification, formal records, moderation, audit trails, guaranteed retention, or guaranteed deletion.

What we don’t do

We don’t require or verify contact details or real identity, and we don’t offer structured contact matching or exchange. Images, files, attachments, voice notes, and video are not supported. There is no report-submission or moderation-review flow in this version. You can still screenshot, copy, photograph, or otherwise save what you see; no app can prevent that, and we don’t claim to.

Changes

We may update this policy as the service changes. The current version on this page applies when you use TillTom.

Contact

For privacy questions about TillTom, email contact@tilltom.com.