Your message is sealed before it's sent.
Every message and file is encrypted on your own device with authenticated encryption — meaning even a single altered bit is detected and rejected. By the time anything leaves your phone or laptop, it's already sealed.
Your keys never leave your device.
Your devices agree on a shared secret without ever sending it, then turn it into working encryption keys on the device itself. On phones, the keys that sign you in and seal your account key live in your phone's secure hardware (Secure Enclave / Android Keystore) where available. We never hold a key, so we could never hand one over.
Even we can't read your messages.
Our database stores only ciphertext — the scrambled output of encryption, unreadable without your keys. There's nothing readable on our side to leak, steal, or hand over.
A lost device doesn't become a leak.
If a device goes missing, you trigger a remote wipe with a single push, and a four-step cleanup clears it the moment the signal lands — on Android, iPhone, and the Windows and Mac desktop apps alike. The device is wiped whether or not it's in your hands.