The hard questions
This page grew out of a message someone sent us. They accused us of surrendering to control all over again by going into the App Store — and argued that encryption is pointless anyway, because everything lies open on the device.
We thought the questions were good. Here they are, with our answers. Including the answer that does not flatter us.
The short version
One point in that message was wrong: we do not only encrypt the transport layer.
One point was right: whoever takes over your device reads along — with any messenger.
And one point was a good question: why use the App Store at all? Answer: on Android you do not have to.
Why is the messenger in the App Store if you promise independence?
Because the store is where people look. A doctor who needs a secure messenger for her practice searches there — not on a download page she has never heard of.
For Android you do not need the store. The app is available directly from us, with the fingerprint of our signature so you can verify it. On iPhone that route does not exist: Apple does not allow installing from another source, there is no switch for it. That is Apple's decision, not ours — and we would rather write it down than pretend we had a choice.
Read more: Get the app without a store
Can Apple or Google see my messages?
No. Your messages are encrypted on your device and only become readable again on the recipient's device. Neither Apple nor Google nor we hold the keys.
What the store actually sees: that you bought and installed an app. That is also why the route without a store exists — anyone who finds even that too much can bypass it on Android.
Read more: Technical measures
Do you only encrypt the transport layer?
No — and the difference matters. Transport encryption protects the line; at the provider the message then lies open. That is precisely what we do not do.
We encrypt end to end using the
Matrix standard with Olm and Megolm
(m.megolm.v1.aes-sha2), implemented with the open source
matrix-rust-sdk — the same in the iPhone app, the Android
app and the browser. The keys are created on your device and never leave
it. Our server holds ciphertext we have never had the key to.
Why this counts: nobody can audit a home-made encryption scheme. An open one can be audited by anyone — including against us.
Read more: Technical measures · The method, verifiable
Are my messages stored unencrypted on my phone?
Partly yes. And we tell you exactly when.
An iPhone is not simply "encrypted". It has four states:
- Switched off: everything is locked. Without your passcode nobody gets to anything. The strongest state.
- Just booted, not yet unlocked: our message database is not readable. Face ID does not work — only the passcode does.
- Unlocked once, now locked — everyday life: here is the honest part. The key for app data stays in memory, even with the screen off. That is deliberate, because otherwise no message could arrive while the phone sits in your pocket. The price: anyone who gets hold of your running device with the right tools has an easier time. The door is shut, but the key is in the lock on the inside.
- Unlocked: everything is open. Whoever holds your unlocked phone reads along.
That is why we never say "nobody can read your messages". We say: we cannot. And we give the advice that actually helps: when it matters, switch the device off. Switched off is the strongest state, and it costs one long press of a button.
Read more: The four states of your iPhone
What about government spyware?
No messenger protects a compromised device. Not Signal, not Threema, not ours. Whoever reads along on your phone sees what you see — after decryption, exactly as you read it. That is not a gap that can be closed. It is the limit of the matter.
It matters to us that this sentence stands here and not in the fine print. Because it defines what we do protect against: what happens millions of times every day — the provider reading along, metadata being harvested and sold, address books being matched, the phone number becoming your identifier.
A targeted state attack on one individual is a different threat model. No messenger helps there — only a different device, or none at all.
Read more: What we do not promise
Could a faked iOS update take over my phone?
That is not how it works in practice. iOS updates are signed and the signature is verified at boot. A planted update would need Apple's private key — and nobody has that but Apple.
Real attacks at that level, such as Pegasus, take a different route: unknown flaws in the processing of images and messages, often without the user tapping anything. The risk is real — but the described mechanism is not the actual one.
What does help is unspectacular: install updates promptly, restart the device regularly (afterwards the passcode is required again, not your face), and switch it off when it matters. Since iOS 18.1 a locked iPhone reboots by itself after 72 hours without being unlocked, closing itself up again.
Read more: The restart after inactivity
Does it work without Google Play?
Yes. The Android app is available as a file directly from us. You download it, tap it, allow "install from this source" once — done. No Google account, no corporation's approval.
Because Google does not vet the file for you, we publish the SHA-256 fingerprint of our signature. Anyone downloading an app outside a store should be able to compare that value — and with us they can. If a file shows a different value, it did not come from us.
This is not a back alley. Signal has offered its Android app this way for years, explicitly for people who want to avoid Google.
Read more: Download the app and check the fingerprint
Is the messenger open source?
The cryptographic core yes, our interface no.
Encryption uses the open source matrix-rust-sdk following the open Matrix standard — the part that matters and that anyone can audit, including against us. We did not invent our own encryption; that would be the point at which you should get suspicious.
The app around it — interface, administration, workflows — is our product and proprietary. We prefer to say that plainly rather than blur it. Anyone who hears "open source" and assumes it covers everything should not be disappointed on closer inspection.
Read more: Technical measures · Licences and components
Isn't this a US solution again?
The server is in Germany, operated by Hetzner Online GmbH. There is no US corporation in the path.
- No mandatory phone number — you sign up with an email address.
- No covert address book matching. If you use “Find people”, the check runs only at your request — the server stores nothing and passes nothing on.
- No advertising, no tracking, no sharing.
- No connection to foreign Matrix servers — which rules out the largest metadata leak from the outset.
What comes from Apple and Google is the operating system and the distribution channel. On iPhone that is unavoidable as long as you want to use an iPhone. On Android it is avoidable, and we offer that route.
To be fair: an argument that applies equally against every messenger on every phone distinguishes none from none. The question is not whether an operating system sits underneath — the question is who reads along on top. With us: nobody.
Read more: Privacy policy · What we are building
We have a question too
We are building a messenger that earns nothing from advertising and nothing from data. It can only do one thing: cost money. Before we settle on a price, we would like to know what it would be worth to you — anonymous, no sign-up, ten seconds.
Still have a question?
Write to us at [email protected]. We reply within 72 hours — to uncomfortable questions too. This page grew out of one.
What would it be worth? · To the messenger · Technical measures · Device protection · What we are building · Privacy policy