Encryption
How PinkyBond encrypts messages and calls
Everything she shares with you is encrypted on her phone and decrypted on yours. Our server forwards sealed envelopes it cannot open. We never hold the key.
Built on platform cryptography
We did not write our own crypto. On iPhone we use Apple's CryptoKit. On Android we use Google's Tink. Curve25519 key agreement, HKDF-SHA256 and AES-256-GCM on both, pinned to each other by shared test vectors, so an iPhone and an Android phone produce byte-for-byte identical ciphertext.
Key agreement
Curve25519 (X25519) ECDH
Encryption
AES-256-GCM
Key derivation
HKDF-SHA256
What we do, and what we don't
Every row is checkable. The last three are where we fall short of the best messengers, and we would rather you read that here than find it out later.
| Dimension | PinkyBond |
|---|---|
| Encryption | AES-256-GCM, end-to-end between the two phones |
| Key agreement | Curve25519 (X25519) ECDH, then HKDF-SHA256 |
| Implementation | Apple CryptoKit on iPhone, Google Tink on Android — byte-for-byte interoperable |
| Key storage | iOS Keychain / Android Keystore, hardware-backed where available |
| Pairing | QR code in person, or a 6-character code / link exchanged remotely; both public keys exchanged |
| Verification | A 6-digit code on both phones confirms no one sat in the middle |
| Account | None — no phone number, no email, no password |
| Serverzugriff auf Inhalte von Nachrichten und Anrufen | Keiner. Wir haben den Schlüssel nie. |
| What the relay stores | Kopplungs-ID, Nachrichtentyp, Zeitstempel, Größe, Chiffretext — gelöscht, sobald zugestellt, spätestens nach 30 Tagen |
| Fotos, Videos und Dateien | Bis zu 2 GB, versiegelt mit einem neuen Schlüssel pro Datei, den nur eure beiden Handys haben; gelöscht, sobald heruntergeladen, spätestens nach 30 Tagen. An eine Partner-App, die noch nicht aktualisiert ist: bis zu 25 MB mit dem Kopplungsschlüssel, 30 Tage aufbewahrt |
| Anrufliste | Welches Handy angerufen hat, wann, Sprach- oder Videoanruf, Ergebnis und Dauer — für unseren Server lesbar, 90 Tage aufbewahrt, gelöscht, wenn ihr die Kopplung aufhebt. Nie Ton oder Bild. |
| Push notifications | Carry no text; the phone decrypts locally |
| Safety Mode | Yes — her phone sends neutral substitute data instead of her real status. Your app shows no indicator, though the flag itself is in the snapshot. |
| Forward secrecy | No — one key per pairing |
| Open source | No |
| Independent audit | Not yet |
How pairing works
No phone number. No email. No account. In the same room, she shows a QR code and you scan it. Apart, she sends you a 6-character code or a link. Either way both phones exchange public keys, derive the same secret, and show a 6-digit verification code so the two of you can confirm no one sat in the middle.
She taps “Pair with partner” in PinkyBloom
Her phone generates a Curve25519 key pair (Apple CryptoKit on iPhone, Google Tink on Android)
She shows a QR code, or sends you a 6-character code or link if you are apart
You scan or enter it in PinkyBond, and your phone generates its own key pair
Your public key travels back to her the same way; both phones now hold both public keys
Each phone runs ECDH and HKDF-SHA256 to derive the same shared secret — nothing secret crosses the network
The shared secret is stored in the iOS Keychain or the Android Keystore
A 6-digit verification code appears on both phones; if they match, no one sat in the middle
The Blind Relay
Unser Server ist ein Briefkasten für versiegelte Umschläge. Er hält Chiffretext nur, bis das andere Handy ihn abholt, und löscht ihn dann — spätestens nach 30 Tagen, wenn dieses Handy offline bleibt. Er hat nie einen Schlüssel. Push-Benachrichtigungen enthalten keinen Text; das Handy entschlüsselt lokal.
PinkyBloom
Encrypts on her phone
Blind Relay
Hält Chiffretext bis zur Zustellung, höchstens 30 Tage
Cannot decrypt
PinkyBond
Decrypts on your phone
Alles, was unser Server über eine Nachricht, eine Datei und einen Anruf speichert:
pairingId
Identifier for the pairing; not a name, number or email
senderRole
Which app sent it: PinkyBloom or PinkyBond
messageType
Welche Art Umschlag es ist — zum Beispiel eine Chatnachricht, ein Status-Snapshot, eine Empfangsbestätigung oder ein Anrufaufbau — nie, was drin ist
timestamp
When it was sent
ciphertext
AES-256-GCM blob we cannot open; its length is the only thing we can measure
retention
Gelöscht, sobald das andere Handy sie empfängt; höchstens 30 Tage, wenn es offline bleibt
relayReceipts
Nach der Zustellung ein Eintrag ohne Inhalt: welche Nachricht es war und ob sie zugestellt wurde oder abgelaufen ist. 30 Tage aufbewahrt, damit das Handy des Absenders „nicht zugestellt“ anzeigen kann
mediaObjects
Fotos, Sprachnachrichten, Videos und Dateien bis zu 2 GB, als Chiffretext bei Cloudflare R2 gespeichert, mit einem neuen Schlüssel pro Datei, der nur in der verschlüsselten Nachricht mitreist. Gelöscht, sobald das Handy deiner Partnerin sie heruntergeladen hat; höchstens 30 Tage
callLog
Welches der beiden Handys angerufen hat, wann, Sprach- oder Videoanruf, angenommen, verpasst oder abgelehnt, und wie lange er dauerte. Für unseren Server lesbar — nur so erfährt ein Handy, das aus war, von einem verpassten Anruf. 90 Tage aufbewahrt, gelöscht, wenn ihr die Kopplung aufhebt. Nie Ton oder Bild
Calls
Voice and video are peer-to-peer WebRTC with DTLS-SRTP and fresh keys for every call. The call setup rides the encrypted relay like any message. Before media flows, your phone checks the peer's DTLS fingerprint against a key derived from the pairing secret; a failed check aborts the call.
Wenn ein Netz den direkten Weg blockiert, leitet ein Relay Pakete weiter, die es nicht lesen kann. Kein Medienserver hört je einen Anruf mit, und kein Anruf wird aufgezeichnet. Es funktioniert zwischen iPhone und Android. Was unser Server behält, ist eine Anrufliste — welches Handy angerufen hat, wann, Sprach- oder Videoanruf, das Ergebnis und die Dauer — 90 Tage lang, damit jemand, dessen Handy aus war, den verpassten Anruf trotzdem sieht. Mehr unter /calls.
Safety Mode
Encryption protects her data from outsiders and from us. Safety Mode is for the case where the person on the other end is the concern. She can pause sharing at any time, and he is never notified. She can also turn on Safety Mode, which substitutes neutral data he cannot distinguish from a real update.
When Safety Mode is active, the partner sees:
Phase
“Follicular”
Mood
“Good”
Energy
3 (Moderate)
The neutral data is encrypted and sent through the normal relay, so it looks the same as a real update in transit and on his screen.
