Private by design.

Privacy is not a setting you remember to enable. Blink is built so encryption, on-device keys, and ciphertext-only servers are the default path — with device and duress defenses for the day something goes wrong.

Principles

What private by design means here

Four rules that shape the product — not a slogan on a landing page.

Defaults that cannot be switched off

Encryption, ciphertext-only storage, and on-device keys are the product — not a premium mode or a toggle buried in settings. If it can be turned off casually, it is not private by design.

Keys never leave your devices

Blink derives and holds keys on your devices. Servers store scrambled ciphertext in ScyllaDB. There is nothing readable on our side to leak, sell, or hand over.

Privacy reaches the whole surface

Reactions, receipts, filenames in the Secure Locker, and disappearing chats are designed under the same rules as the message body — not bolted on later.

Defense for the worst day

Remote wipe, reverse-PIN duress wipe, screen protection, and the anti-keylogger keyboard exist because private messaging fails when a phone is seized, logged, or shoulder-surfed.

Contrast

Not the leftover privacy model

Common approachBlink

Encryption as a marketing badge

Architecture you can explain: AES-256-GCM on device, ECDH P-256, weekly epochs

Optional secret chats

End-to-end encryption by default for messages and media

Cloud that can still read content

Ciphertext-only servers — no keys that can open your messages

Familiar chat with metadata trade-offs

Device control, Spaces, and duress tools for high-stakes work

Accountability

Promises we keep public

We badge what is not done yet

Fully end-to-end encrypted calls, disguise apps, and Swiss/GDPR residency are on the roadmap and labeled as such. Today Blink runs in the US and India.

We do not sell your content

There is no advertising business model that depends on reading conversations. The product is the privacy itself.

You can verify the story

Cryptography, retention posture, and feature status are published in plain language on Trust & encryption, the change log, and related feature pages.

See the design in the product

Walk encryption, remote wipe, and Spaces with your team — or dig into the cryptography behind the defaults.