Updated: 2026-09-29
Direct messages, encryption and key verification
Direct message text is encrypted in your browser. The server only ever receives the encrypted text and does not hold the key that reads it — reading the conversation server-side is technically impossible.
That does not mean encryption is always active. Below is what is actually protected, what is not, and what you should verify yourself.
1. What is encrypted, and how
Direct message text is encrypted with XChaCha20-Poly1305. The conversation key is derived from your private key and your contact's public key using X25519, then expanded with HKDF-SHA256.
The private key never leaves your device and is never uploaded. Only the public key is sent to the server — it can be used to encrypt, not to decrypt.
Every message gets its own random nonce, so two identical messages are encrypted differently.
The same mechanism protects channel messages and member notes once their keys exist.
2. The main caveat: check the badge
If your contact has not published a public key yet, the app sends the message as plain text — silently, without a warning dialog. The same happens on a first login while keys are still being generated.
The only indicator is the badge in the conversation header. "End-to-end encrypted" means the text is encrypted. "Not encrypted" and "Waiting for your contact's key" mean the message went out in the clear.
Check that badge before discussing anything sensitive. It changes as your contact signs in.
3. Comparing the safety number
Click the padlock badge in the conversation header to open "Security verification", which shows a 32-character safety number and both key fingerprints.
The safety number is identical on both sides and does not depend on who is looking. Compare it over a different channel — a voice call, in-game, or in person. If it matches, the conversation really is protected against a server swapping keys.
One comparison is enough. You do not need to redo it for every message.
4. What the app does not do
The app does not remember that you verified anything, and it does not warn you when a contact's key changes. A number you verified once may differ next time, and the only way to notice is to check again by hand.
Public keys are stored on the server and served to anyone who asks, so a compromised server could in theory substitute its own. Verifying the safety number is the only protection against that scenario.
Keys are long-lived with no ratchet, so compromising a device exposes the entire conversation history with that person, including old messages.
5. What is not encrypted
Images and attachments are not encrypted. They are uploaded as-is and the server can read them like any other file.
Voice calls, announcements, scheduled broadcasts and polls are not encrypted — they are announcements for the whole alliance.
Metadata is always visible: who wrote to whom, when, how many messages, of what size, who belongs to the alliance and who is currently online. The content of a conversation is encrypted; the fact of the exchange is not.
6. Keys and changing device
Keys live in the browser and are not backed up server-side. On a new device, or after clearing browser data, the app generates a new key pair and the old conversation stops being readable.
Contacts receive no warning about the key change. If someone suddenly asks you to re-verify the safety number after a long gap, make sure it really is them first.