Private by design.
Privacy is not a setting you remember to enable. Blink is built so encryption, on-device keys, and ciphertext-only servers are the default path — with device and duress defenses for the day something goes wrong.
Principles
What private by design means here
Four rules that shape the product — not a slogan on a landing page.
Defaults that cannot be switched off
Encryption, ciphertext-only storage, and on-device keys are the product — not a premium mode or a toggle buried in settings. If it can be turned off casually, it is not private by design.
Keys never leave your devices
Blink derives and holds keys on your devices. Servers store scrambled ciphertext in ScyllaDB. There is nothing readable on our side to leak, sell, or hand over.
Privacy reaches the whole surface
Reactions, receipts, filenames in the Secure Locker, and disappearing chats are designed under the same rules as the message body — not bolted on later.
Defense for the worst day
Remote wipe, reverse-PIN duress wipe, screen protection, and the anti-keylogger keyboard exist because private messaging fails when a phone is seized, logged, or shoulder-surfed.
Contrast
Not the leftover privacy model
Encryption as a marketing badge
Architecture you can explain: AES-256-GCM on device, ECDH P-256, weekly epochs
Optional secret chats
End-to-end encryption by default for messages and media
Cloud that can still read content
Ciphertext-only servers — no keys that can open your messages
Familiar chat with metadata trade-offs
Device control, Spaces, and duress tools for high-stakes work
Accountability
Promises we keep public
We badge what is not done yet
Fully end-to-end encrypted calls, disguise apps, and Swiss/GDPR residency are on the roadmap and labeled as such. Today Blink runs in the US and India.
We do not sell your content
There is no advertising business model that depends on reading conversations. The product is the privacy itself.
You can verify the story
Cryptography, retention posture, and feature status are published in plain language on Trust & encryption, the change log, and related feature pages.
See the design in the product
Walk encryption, remote wipe, and Spaces with your team — or dig into the cryptography behind the defaults.