PRIVACY & SECURITY
Your source belongs on your device.
Txcc is designed so media files and playlist use occur between your device and the source you select. The public website does not host or inspect your catalog.
Direct entry
When you add a playlist inside the app, its details are handled by the device. The app contacts the selected provider directly. Storage behavior varies by platform; review the full Privacy notice before using a shared device.
Website pairing
The pairing page temporarily sees what you type because it must encrypt it in your browser. It does not save the fields in browser storage. Before upload, Web Cryptography encrypts the playlist with AES-256-GCM and encrypts that key with the selected device's temporary RSA-OAEP public key. The relay receives ciphertext, not readable playlist details.
Expiry and deletion
A pending connection expires after ten minutes. Once an encrypted package is submitted, it remains in server memory for at most two minutes. The session is removed sooner when the device confirms receipt. A restart discards all pending sessions because they are never written to the device database or a relay file.
What remains observable
Encryption does not hide ordinary network metadata. Hosting and security infrastructure can process the IP address, time, path, browser information, request size and security events in operational logs. The app-generated device identifier remains inside the app-to-service session. The website uses only a temporary device key and six-digit code; a scanned QR stores them in the URL fragment so they are not included in the page request.
Your safety checklist
- Use only txcc.app/pair.html.
- Confirm the temporary key and code on the device you control.
- Prefer HTTPS provider endpoints.
- Do not email credentials or enter them on imitation pages.
- Remove private playlists before sharing or selling a device.
Encryption protects the relay step. It does not change the security or privacy practices of the external provider you choose.