Skip to content

Legal

Privacy Policy

Last updated: September 2026

Zero-Knowledge Architecture

Tallow is designed so that we never have access to your data. All files are encrypted end-to-end on your device before transmission. The relay server only sees encrypted ciphertext and cannot decrypt your files, read filenames, or inspect file contents.

What We Don't Collect

Tallow does not collect personal information, usage analytics, telemetry, crash reports, or any form of tracking data. There are no accounts, no sign-ups, and no cookies. The relay server does not log IP addresses, transfer metadata, or connection timestamps beyond what is required for active session management. That exception is narrow and concrete: room routing state is held in memory only and expires with the room, and no request log records a join identifier — access logs carry the request path with the client IP fields stripped before anything is written.

Relay Server

The default relay server facilitates encrypted connections between peers. Room codes are ephemeral and destroyed after use. No transfer history is retained. If you prefer complete infrastructure control, you can self-host your own relay server.

Web Application

The Tallow web app runs entirely in your browser via WebAssembly. Cryptographic keys are generated locally and never transmitted to any server. Session keys exist only in browser memory and are zeroed on disconnect. No data is stored on remote servers.

Local Browser Storage

The web app keeps a small set of IndexedDB stores on your device only — never on our servers. Deliberately persistent: contacts, trust records, your local identity, transfer history, and chat messages or media you chose to keep (sensitive fields in these stores are encrypted at rest, and the keys never leave your device). Transfer-scoped state is ephemeral: resume checkpoints are removed once a transfer completes or the session is cleaned up, and join codes never touch persistent storage — they are cleared from the URL on arrival and held only in memory or session storage. You can erase everything at any time from Settings → Clear all data, or with the panic wipe, which zeroes memory and clears every store in under a second.

Open Source Verification

Tallow is licensed under the AGPL-3.0, and the browser client ships as hash-pinned WebAssembly — the exact bytes your browser runs are verifiable on your own device at /selftest.html. Our cryptographic implementation uses well-established libraries from the RustCrypto ecosystem, and the transparency page documents exactly what the service does and does not store.

Contact

For privacy-related questions, contact us at tallowteam@proton.me or read what we hold (and what we answer) on the transparency page. Data-subject requests under the GDPR (access, rectification, erasure, objection) go to the same address and are answered in writing — the service holds no accounts and nothing tied to you to hand over, but every request gets a reply.

In short

  • No analytics, telemetry, or tracking of any kind
  • No accounts, cookies, or personal data collected
  • End-to-end encrypted — the relay never sees plaintext in End-to-end mode (Transport-only is relay-carried)
  • Hash-pinned WebAssembly — verifiable on your device