What is a text tag?
Privacy Policy
Last updated August 30, 2026
TextTags is a notification service, not a chat app. Someone scans a Tag on your car, your gate, your bike or your package, sends you one short message — "you're blocked in," "your lights are on," "I found this" — and you send a quick reply. That's the whole interaction. There are no threads to keep up with, no friends to add, no presence, no typing indicators, and no ongoing conversations. Brevity isn't a limitation we haven't gotten around to fixing; it's the point.
It works because a stranger can reach you without either of you handing over a phone number — and that only holds if we collect as little as possible. So we do: no accounts, no sign-ups, no email addresses, no phone numbers, no advertising identifiers, and no third-party analytics or tracking of any kind. A short exchange between two anonymous parties simply doesn't generate much to protect, which is the best privacy guarantee there is. This page explains exactly what we do hold, why, and who else touches it.
1. What TextTags is, and what it isn't
TextTags turns a QR code — a "Tag" — into a way to get a short, real-world notification about a specific thing. A Tag owner creates and places a Tag; anyone who scans it can send the owner a brief message, either in the TextTags iOS app or straight from their phone's browser with nothing installed. Most exchanges are one message and one reply. This policy covers the TextTags iOS app, this website, and the TextTags API behind both.
TextTags is not a messaging platform. Tags exist to send and receive short notifications and quick replies — not extended conversations, ongoing dialogue, or sustained back-and-forth — our Terms of Use say exactly this, in Section 1. It shapes the whole of this policy: what follows describes how we handle a handful of short messages between two anonymous parties, not a message archive or a social network. There is no contact list, no friend graph, and no record of who you know, because the service has no concept of either.
Throughout this policy, an owner is someone who created a Tag, and a scanner is someone who scanned one.
2. No accounts, no phone numbers
Neither side ever sees the other's phone number, email address, or real identity. Every message routes through TextTags in both directions. There is nothing to exchange, because we never ask either party for it in the first place.
TextTags has no accounts. You do not sign up, you do not pick a password, and you do not give us an email address or phone number to use it. Instead, when you first open the app, your device generates a random identifier for itself and stores it in the iOS Keychain. That random identifier is your entire identity to us. It is not derived from anything about you or your hardware, and it is not linked to your Apple ID or any other account.
A consequence worth knowing: because your Tags belong to a device rather than an account, they cannot be moved to a different device, and deleting the app can permanently sever your access to them.
3. What we collect
If you create Tags (owners, using the app)
| What | Why |
|---|---|
| A random device identifier generated on your device at first launch | To know which Tags, exchanges and credits are yours, without an account |
| Apple App Attest data (a key identifier and public key) and one Apple DeviceCheck bit | To confirm requests come from a genuine, unmodified copy of the app, and to stop the same device claiming its one free Tag over and over by reinstalling |
| An Apple push notification token | To alert you when someone scans your Tag and messages you |
| An optional display name you type | Shown to the people you're talking to, so they know who replied. Entirely optional and entirely yours to choose |
| The Tags you make: name, category, icon, the quick replies you enable, and any welcome message or welcome image you write | This is the Tag itself — it's what a scanner sees |
| The short messages you send and receive, and any photos attached to them | To deliver them and to show you what was said |
| Purchases of Tag credits: the Apple transaction identifier, product, and quantity | To grant what you bought, and to make sure a retried or replayed purchase can't be counted twice |
| If you order printed merchandise: your shipping name and address, what you ordered and how you customized it, prices at the time of order, and the tracking details the print vendor sends back | To print the item, ship it to you, and show you where it is |
If you scan a Tag from a browser (scanners, no app)
| What | Why |
|---|---|
| The name you type on the scan page, if you type one | So the owner knows who is messaging them. It is optional — leave it blank and your messages simply show as coming from a web visitor |
| The short message you send, the owner's reply, and any photos either of you attaches | To deliver them and to keep the exchange readable while it's open |
| One session cookie | To let you close and reopen the page and still find your conversation. See Cookies below |
| Your IP address, held briefly in memory and never written to our database | Purely to rate-limit scans, so nobody can spam a Tag owner's phone with notifications by scanning the same Tag over and over |
Scanning from a browser requires no app, no account, and no personal information of any kind. You can send an owner a message having given us nothing but the text of that message.
Scan records
When a Tag is scanned for the first time by a given visitor, we record that the scan happened — which Tag, whether it came from the app or a browser, whether the Tag was active at the time, and when. This is what lets an owner see that their Tag is being used at all. These records contain no IP address, no location, no device identifier, and nothing that identifies the scanner. Repeat visits by someone we've already seen are not recorded again.
4. What we never collect
- No phone numbers or email addresses. We never ask for either, from either side.
- No location. The app does not request or use your location, and we do not infer it. A Tag's QR code carries a short code, not a place.
- No contacts, calendar, microphone, or health data.
- No advertising identifiers and no tracking. There are no advertising SDKs, no analytics SDKs, no tracking pixels, and no third-party cookies anywhere in the app or on this site. We do not build advertising profiles, we do not track you across other apps or websites, and we do not sell or rent your information to anyone — including data brokers.
- No payment card details. Card numbers are entered directly into Apple's or Stripe's payment sheet and go to them, not to us. We only ever see a reference to the transaction.
- No scraping of your photo library. The app can only see photos you specifically pick.
5. How we use it
We use what we collect only to run the service:
- To notify a Tag owner that someone scanned their Tag and needs to tell them something — this is the core of the service.
- To deliver the scanner's short message and the owner's quick reply between the two of them.
- To show you your own Tags and the exchanges attached to them.
- To screen content for safety before it is delivered or printed — see Content moderation.
- To grant and track the Tag credits you've bought or been given, and to prevent the same free credit being claimed repeatedly.
- To take payment for, print, and ship physical merchandise you order.
- To prevent abuse: rate limiting, blocking, and acting on abuse reports.
- To keep the service working — diagnosing errors and keeping it available.
We do not use your messages, photos, or any other content to train machine learning models, and we do not permit our vendors to do so either.
6. Content moderation and safety
Because TextTags puts strangers in touch with each other — briefly, but with no way for either to vet the other — some content is automatically screened by an AI content classifier (Anthropic's Claude) before it goes anywhere. Screening happens before delivery, so flagged content is never shown to its recipient at all.
What is screened, and when:
- Display names — Tag names, the name a web scanner types, and a device's display name are always screened, on every Tag. A name that trips the filter is quietly replaced with a close, inoffensive alternative before it is saved.
- Tag welcome messages and images — always screened before they can be published to scanners.
- Custom text you put on printed merchandise — always screened before it is sent to the print vendor. Print is physical and irreversible, so this one has no opt-out.
- The messages and photos exchanged through a Tag — screened when the Tag's owner has turned the Safety Filter on for that Tag. When it's on, it applies to both directions, owner and scanner alike. It is a per-Tag setting, off by default, that the owner controls.
To operate and improve the filter we keep a record of each screening: which model ran, the verdict, the categories flagged, and a one-way hash of the content (which lets an identical repeat be recognized without re-analyzing it). When content is blocked, we also retain the original text that was blocked, because that text exists nowhere else and is what lets us tell a real problem from a false alarm later. Blocked content is never shown to the person it was addressed to, and this record is never exposed to any user of the service.
If you report a conversation as abusive, we keep your report — the conversation it concerns, the reason you wrote, and which device reported it — and the conversation is closed.
7. Who else we share it with
We do not sell your information. We share it only with the service providers below, only to the extent each one needs to do its job, and only for that purpose.
| Provider | What they receive | What for |
|---|---|---|
| Apple | Push tokens and notification content; App Attest and DeviceCheck data; in-app purchase transactions | Delivering notifications, verifying the app is genuine, processing purchases of Tag credits |
| Anthropic | The message, name, welcome text, or print text being screened, plus any attached image | Automated safety classification. Anthropic processes this on our behalf as a service provider and does not use it to train its models |
| Stripe | Your payment details (entered directly into Stripe's payment sheet, never seen by us) and the order amount | Processing payment for physical merchandise |
| Printful | Your shipping name and address, and the artwork for the item ordered | Printing and shipping merchandise you ordered |
| Railway | Hosts our servers and database | Running the service |
Apple requires purchases of digital goods (Tag credits) to go through in-app purchase, and prohibits it for physical goods — which is why credits are bought through Apple and merchandise is paid for through Stripe.
We may also disclose information if we are legally required to, or where we believe in good faith that it is necessary to protect someone's safety or to investigate abuse of the service.
8. Cookies
This site sets exactly one cookie, and only if you actually start a conversation by scanning a Tag. It is an httpOnly session cookie holding a random token, scoped to that single conversation, and it expires after about six hours. Its only job is to let you close the tab and come back to your conversation.
There are no advertising cookies, no analytics cookies, and no third-party cookies. If you clear it or switch browsers, that conversation becomes unreachable to you — there is no account to log back in with, which is the flip side of not requiring one.
9. Camera, photos and notifications
- Camera — used to scan QR codes and to take a photo to send in a conversation. QR scanning is processed on your device; nothing from the camera is uploaded unless you send a photo.
- Photo library — the app asks for permission to save a photo from a conversation to your library. It does not read your library.
- Notifications — used to tell you a message arrived. Declining them is fine; the app still works, you just won't be alerted.
Photo sending in a conversation is off by default for scanners. A Tag's owner has to explicitly allow it, per conversation.
10. How long we keep things
- Exchanges and messages are kept while the service operates, so both sides can see what was said. Because Tags are for notifications and quick replies rather than sustained messaging, what this covers is typically a few short messages, not a running archive of your communications. Deleting a Tag stops it working immediately but preserves the conversation history attached to it; deleting a conversation removes it from your list without erasing the underlying messages for the other participant.
- Web scanner sessions expire after about six hours. The short-lived tokens used to hand a browser conversation over to the app expire after fifteen minutes.
- Rate-limiting counters based on IP addresses live in memory only and are gone when the service restarts. They are never stored.
- Moderation records are retained so the filter can be evaluated and improved.
- Order records are retained for as long as we need them for tax, accounting and dispute purposes.
If you want your data deleted, get in touch and we will delete what is ours to delete. Note that a conversation has two sides: we can remove your content, but we cannot rewrite the other participant's copy of an exchange they were part of.
11. Your choices and controls
- Pause or destroy any Tag at any time. A paused or destroyed Tag stops accepting messages immediately, even though the physical sticker still exists in the world.
- Turn the Safety Filter on or off per Tag.
- Decide whether a scanner can send photos, per conversation.
- Mute a conversation — either side can silence their own notifications without affecting the other.
- Block, delete, or report a conversation.
- Turn off notifications in iOS Settings.
- Don't scan. Scanning a Tag is always voluntary, and even after scanning, sending a message is a separate deliberate step.
Depending on where you live you may have additional rights over your personal information — to access it, correct it, delete it, or object to how it is used. We honor those requests regardless of where you live; contact us and we'll handle it. We will never discriminate against you for exercising a privacy right.
12. How we protect it
- All traffic between the app, this site, and our servers is encrypted in transit.
- Session and refresh tokens are stored only as one-way hashes, never in a form that could be reused if our database were exposed.
- Access tokens are short-lived, and every request from the app is bound to the specific device that made it.
- The app uses Apple's App Attest so our servers can distinguish a genuine copy of the app from an impostor.
- Your device identity lives in the iOS Keychain, protected by the operating system.
No system is perfectly secure, and we won't pretend otherwise. A Tag is for a quick heads-up about a thing, so please keep it to that: don't send sensitive personal, financial, or identifying information through one. You have no way to verify who is on the other end of a Tag, and neither do we.
13. Children
TextTags is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has used the service and sent us information, contact us and we will delete it.
14. Where your data is processed
TextTags is operated from the United States, and the information described here is stored and processed there. If you use the service from another country, you are sending your information to the United States, where privacy laws may differ from those where you live.
15. Changes to this policy
We may update this policy as the service changes. When we do, we'll update the "last updated" date at the top of this page. If a change materially affects how we handle your information, we'll make a reasonable effort to tell you in the app before it takes effect. Continuing to use TextTags after a change means you accept the updated policy.
16. Contact us
Questions about privacy, or a request to access or delete your information? The fastest way to reach us is — fittingly — through a TextTags Tag: message us here. It works from any browser, no app required, and no personal details needed to start.