Privacy notice
This notice is available in English and Dutch. If the two versions ever differ, the Dutch version is authoritative.
Deze verklaring is beschikbaar in het Engels en het Nederlands. Als de twee versies ooit verschillen, is de Nederlandse versie leidend.
What this app stores
Your account details (username, email, display name), the messages and files you send in ordinary (non-encrypted) conversations, and standard operational data (device registrations for push notifications, login history for security purposes).
End-to-end encrypted conversations
A conversation that is end-to-end encrypted - which new conversations are by default, see below - is protected using the Signal Protocol. For an encrypted conversation, this server never holds a private key, session state, or message plaintext - it only relays opaque, already-encrypted data between participants' own devices. We structurally cannot read an encrypted conversation's content, including in response to a request from us, a government, or anyone else, unless the mechanism described further below applies.
Encryption is on by default
A new direct (1:1) or group conversation is end-to-end encrypted by default. You can choose not to encrypt a specific conversation when you start it; encryption cannot be turned on afterward for a conversation that started without it, since there is no history to retroactively protect.
Where end-to-end encryption is not available
Encryption does not apply everywhere in this app. Here is the complete, current list.
Never encrypted, by design:
- Support conversations (chat with a widget or an agent) - the purpose of support chat is that agents and admins can read and help with it, which real end-to-end encryption would defeat.
- Broadcast channels - the same reasoning as support conversations.
Not currently available in the web app (mobile app only):
- Encrypted GROUP conversations, polls, link previews, on-device search, and local backup/export now work in the web app too. Link previews on the web app work differently than on mobile - see the dedicated section below.
- A browser has no equivalent of a phone's hardware-backed key storage. Your encryption keys in the web app are stored by your browser itself, which is a real, if usually reasonable, weaker guarantee than the mobile app's own protection.
Not yet available within an encrypted conversation on ANY platform, even though available in a regular conversation:
- File, photo, and voice attachments; reactions; live or one-time location sharing; sharing a contact; forwarding a message; reply/quote; starring a message; and editing or deleting a message after it is sent.
Link previews in encrypted conversations: an exception to "the server never sees content"
When you send a link in an end-to-end encrypted conversation, we can show a preview card (title, description, image) for it. On the mobile app, your device fetches that preview data directly - the server is never involved and never sees the link. On the web app, your browser cannot do that same direct fetch for an arbitrary third-party site (a technical browser restriction called CORS), so instead your browser asks this server to fetch that one URL on its behalf, and the server sends the resulting preview back before your message is encrypted. This means that, for that one request, the server transiently sees the URL you are about to send - and only the URL, never your message text, never who you are sending it to, and never any other part of the conversation, all of which stay end-to-end encrypted throughout and never reach the server unencrypted. Nothing about this request is stored; it exists only long enough to fetch and return the preview. Link previews are OFF by default; you can turn them on or off at any time in Settings, and while off, no URL from your encrypted conversations is ever sent to the server this way, on web or mobile.
Conversation review capability
This app includes a standing, disclosed capability: an administrator may mark a specific direct or group conversation - encrypted or not - as under review, for purposes such as responding to a report of abuse or a legal obligation. For an end-to-end encrypted conversation specifically:
- Enabling review does not decrypt or expose anything already sent. Messages already exchanged before review was enabled remain unreadable to us, exactly as they were before.
- From the point review is enabled onward, new messages in that conversation are additionally delivered, in the same encrypted form every other device in the conversation receives them, to a separate reviewer identity. That identity's own private key is kept offline, away from this server, and reviewing its content is a deliberate, logged, manual process - not an automatic or continuous one.
- Every time review is enabled or disabled on a conversation, who did it and when is recorded in a permanent log.
- We do not announce a specific use of this capability to the people affected in the moment - doing so would defeat its purpose for genuine abuse or legal-compliance cases - but its existence, and exactly how it works, is what this section discloses. It is never used to single out a specific person while telling them, falsely, that a conversation remains fully private when it does not.
Support conversations and broadcast channels are never end-to-end encrypted in the first place, by design - their whole purpose already depends on being readable by the agents/admins who staff them, which is disclosed by what those features visibly are, not a hidden exception to encryption.
Questions
If anything here is unclear, contact the operator of this instance through the support channel available in the app.