Encrypted calls
A phone line only the two of you can pick up
End-to-end encrypted, and the app knows who is calling: your partner. No numbers, no accounts, no media server — voice and video between the two phones you paired.
Peer-to-peer first
The phones talk to each other. A relay only carries encrypted packets when a network forces it.
Bound to the pairing
Each call’s DTLS fingerprint is authenticated with a key derived from your pairing secret. If the check fails, the call is aborted.
Per-call keys
Fresh key material every call. Signaling is AES-256-GCM under the pairing key, like every message.
No content in the ring
The push that rings the other phone is a wake-up, not a payload. The server never receives audio or video.
Honest comparison
Signal mempunyai rekod audit terpanjang dalam industri, kod sumber terbuka dan kerahsiaan ke hadapan untuk mesej; kami belum mempunyai semua itu dan tidak berpura-pura sebaliknya. Apa yang PinkyBond ubah ialah siapa yang boleh menghubungi anda dan apa yang aplikasi tahu tentang anda berdua. Pelayan kami memang menyimpan log panggilan selama 90 hari, supaya panggilan tidak dijawab tetap sampai ke telefon yang mati; kandungan tepatnya ada dalam soalan terakhir di bawah.
| Dimension | Signal | FaceTime | PinkyBond | |
|---|---|---|---|---|
| Media encryption | SRTP (Signal Protocol keys) | SRTP | SRTP, keys per FaceTime session | DTLS-SRTP, per-call keys |
| Identity | Phone number | Phone number | Apple ID / phone | None — your pairing (QR in person, or a code exchanged remotely) |
| Who can call you | Anyone with your number | Anyone with your number | Anyone with your ID | Only your partner |
| MITM protection | Safety number (manual check) | Security code (manual) | Apple key directory | Fingerprint bound to the pairing secret, checked automatically |
| Server in the audio path | Relay when needed | Relay when needed | Relay when needed | TURN relay when needed; cannot decrypt |
| Audit history | Extensive, public | Partial | Apple internal | Platform crypto (CryptoKit / Tink); no independent audit yet |
| Open source | Yes | No | No | No |
| Forward secrecy | Yes | Yes | Yes | Calls: fresh keys per call. Messages: no — one key per pairing |
| Knows the relationship | No | No | No | Yes — same app as her forecast and your check-ins |
Vendor rows summarize public documentation as of September 2026. Architecture details for messages are on /encryption.
Why a couples app needs its own phone line
The call is not a feature bolted onto a dashboard. It sits next to her forecast, your check-in and the rough-day log, inside the one encrypted space that already knows the two of you. That is what makes it a relationship tool rather than a messenger: on a day the forecast reads stormy, the app can suggest the call that fits — listen, don't fix.
See how the forecast is built on /forecast.
