Encryption
How PinkyBond encrypts messages and calls
Everything she shares with you is encrypted on her phone and decrypted on yours. Our server forwards sealed envelopes it cannot open. We never hold the key.
Built on platform cryptography
We did not write our own crypto. On iPhone we use Apple's CryptoKit. On Android we use Google's Tink. Curve25519 key agreement, HKDF-SHA256 and AES-256-GCM on both, pinned to each other by shared test vectors, so an iPhone and an Android phone produce byte-for-byte identical ciphertext.
Key agreement
Curve25519 (X25519) ECDH
Encryption
AES-256-GCM
Key derivation
HKDF-SHA256
What we do, and what we don't
Every row is checkable. The last three are where we fall short of the best messengers, and we would rather you read that here than find it out later.
| Dimension | PinkyBond |
|---|---|
| Encryption | AES-256-GCM, end-to-end between the two phones |
| Key agreement | Curve25519 (X25519) ECDH, then HKDF-SHA256 |
| Implementation | Apple CryptoKit on iPhone, Google Tink on Android — byte-for-byte interoperable |
| Key storage | iOS Keychain / Android Keystore, hardware-backed where available |
| Pairing | QR code in person, or a 6-character code / link exchanged remotely; both public keys exchanged |
| Verification | A 6-digit code on both phones confirms no one sat in the middle |
| Account | None — no phone number, no email, no password |
| メッセージと通話内容へのサーバーアクセス | ありません。鍵は私たちが持つことは決してありません。 |
| What the relay stores | ペアリングID、メッセージの種類、タイムスタンプ、サイズ、暗号文 — 配信され次第削除、最長30日間 |
| 写真、動画、ファイル | 最大2GBまで、お二人の端末だけが持つファイルごとの新しい鍵で封印され、ダウンロードされ次第削除、最長30日間。まだアップデートしていないパートナー側のアプリには、ペアリング鍵のもとで最大25MBまで、30日間保存されます |
| 通話履歴 | どちらの端末が発信したか、いつ、音声かビデオか、結果と通話時間 — 私たちのサーバーが読み取れます。90日間保存され、ペアリングを解除すると削除されます。音声や映像そのものは決してありません。 |
| Push notifications | Carry no text; the phone decrypts locally |
| Safety Mode | Yes — her phone sends neutral substitute data instead of her real status. Your app shows no indicator, though the flag itself is in the snapshot. |
| Forward secrecy | No — one key per pairing |
| Open source | No |
| Independent audit | Not yet |
How pairing works
No phone number. No email. No account. In the same room, she shows a QR code and you scan it. Apart, she sends you a 6-character code or a link. Either way both phones exchange public keys, derive the same secret, and show a 6-digit verification code so the two of you can confirm no one sat in the middle.
She taps “Pair with partner” in PinkyBloom
Her phone generates a Curve25519 key pair (Apple CryptoKit on iPhone, Google Tink on Android)
She shows a QR code, or sends you a 6-character code or link if you are apart
You scan or enter it in PinkyBond, and your phone generates its own key pair
Your public key travels back to her the same way; both phones now hold both public keys
Each phone runs ECDH and HKDF-SHA256 to derive the same shared secret — nothing secret crosses the network
The shared secret is stored in the iOS Keychain or the Android Keystore
A 6-digit verification code appears on both phones; if they match, no one sat in the middle
The Blind Relay
私たちのサーバーは、封印された封筒のための郵便受けです。相手の端末が受け取るまでの間だけ暗号文を保持し、その後削除します — 相手の端末がオフラインのままなら最長30日後に。鍵を持つことは決してありません。プッシュ通知に本文は含まれません。端末側でローカルに復号します。
PinkyBloom
Encrypts on her phone
Blind Relay
配信されるまで暗号文を保持、最長30日間
Cannot decrypt
PinkyBond
Decrypts on your phone
私たちのサーバーがメッセージ、ファイル、通話について保存するすべて:
pairingId
Identifier for the pairing; not a name, number or email
senderRole
Which app sent it: PinkyBloom or PinkyBond
messageType
どんな種類の封筒か — たとえばチャットメッセージ、ステータスのスナップショット、受信確認、通話の開始情報など — 中身が何かは決して分かりません
timestamp
When it was sent
ciphertext
AES-256-GCM blob we cannot open; its length is the only thing we can measure
retention
相手の端末が受信し次第削除。オフラインのままなら最長30日間
relayReceipts
配信後に残る、内容を持たない記録: どのメッセージか、そして配信済みか期限切れかどうか。送信者の端末に「未配信」と表示できるよう、30日間保存されます
mediaObjects
写真、ボイスメッセージ、動画、最大2GBまでのファイル。Cloudflare R2上に、暗号化されたメッセージの中だけを通るファイルごとの新しい鍵で暗号文として保存されます。パートナーの端末がダウンロードし次第削除、最長30日間
callLog
2台のうちどちらの端末が発信したか、いつ、音声かビデオか、応答・不在着信・拒否のいずれか、そして通話時間。私たちのサーバーが読み取れます — こうして電源が切れていた端末も不在着信を知ることができます。90日間保存され、ペアリングを解除すると削除されます。音声や映像そのものは決してありません
Calls
Voice and video are peer-to-peer WebRTC with DTLS-SRTP and fresh keys for every call. The call setup rides the encrypted relay like any message. Before media flows, your phone checks the peer's DTLS fingerprint against a key derived from the pairing secret; a failed check aborts the call.
ネットワークが直接経路をブロックすると、リレーが読み取れないパケットを転送します。メディアサーバーが通話を聞くことは決してなく、通話が録音されることもありません。iPhoneとAndroidの間でも機能します。私たちのサーバーが保存するのは通話履歴です — どちらの端末が発信したか、いつ、音声かビデオか、結果と通話時間 — 90日間。端末の電源が切れていたパートナーにも不在着信が表示されるようにするためです。詳しくは /calls.
Safety Mode
Encryption protects her data from outsiders and from us. Safety Mode is for the case where the person on the other end is the concern. She can pause sharing at any time, and he is never notified. She can also turn on Safety Mode, which substitutes neutral data he cannot distinguish from a real update.
When Safety Mode is active, the partner sees:
Phase
“Follicular”
Mood
“Good”
Energy
3 (Moderate)
The neutral data is encrypted and sent through the normal relay, so it looks the same as a real update in transit and on his screen.
