Encryption

How PinkyBond encrypts messages and calls

Everything she shares with you is encrypted on her phone and decrypted on yours. Our server forwards sealed envelopes it cannot open. We never hold the key.

Built on platform cryptography

We did not write our own crypto. On iPhone we use Apple's CryptoKit. On Android we use Google's Tink. Curve25519 key agreement, HKDF-SHA256 and AES-256-GCM on both, pinned to each other by shared test vectors, so an iPhone and an Android phone produce byte-for-byte identical ciphertext.

Key agreement

Curve25519 (X25519) ECDH

Encryption

AES-256-GCM

Key derivation

HKDF-SHA256

What we do, and what we don't

Every row is checkable. The last three are where we fall short of the best messengers, and we would rather you read that here than find it out later.

DimensionPinkyBond
EncryptionAES-256-GCM, end-to-end between the two phones
Key agreementCurve25519 (X25519) ECDH, then HKDF-SHA256
ImplementationApple CryptoKit on iPhone, Google Tink on Android — byte-for-byte interoperable
Key storageiOS Keychain / Android Keystore, hardware-backed where available
PairingQR code in person, or a 6-character code / link exchanged remotely; both public keys exchanged
VerificationA 6-digit code on both phones confirms no one sat in the middle
AccountNone — no phone number, no email, no password
پیغام اور کال کے مواد تک سرور کی رسائیکوئی نہیں۔ چابی کبھی ہمارے پاس نہیں ہوتی۔
What the relay storesپیئرنگ آئی ڈی، پیغام کی قسم، ٹائم اسٹیمپ، سائز، سائفر ٹیکسٹ — پہنچتے ہی حذف، زیادہ سے زیادہ 30 دن
تصاویر، ویڈیوز اور فائلیں2 GB تک، ہر فائل کے لیے ایک نئی چابی کے ساتھ محفوظ جو صرف آپ کے دونوں فونز کے پاس ہوتی ہے؛ ڈاؤن لوڈ ہوتے ہی حذف، زیادہ سے زیادہ 30 دن۔ ابھی اپڈیٹ نہ ہونے والی پارٹنر ایپ کے لیے: پیئرنگ چابی کے تحت 25 MB تک، 30 دن رکھا جاتا ہے
کال لاگکون سے فون نے کال کی، کب، وائس یا ویڈیو، نتیجہ اور دورانیہ — ہمارا سرور پڑھ سکتا ہے، 90 دن تک رکھا جاتا ہے، جب آپ ان پیئر کرتے ہیں تو حذف ہو جاتا ہے۔ آڈیو یا ویڈیو کبھی نہیں۔
Push notificationsCarry no text; the phone decrypts locally
Safety ModeYes — her phone sends neutral substitute data instead of her real status. Your app shows no indicator, though the flag itself is in the snapshot.
Forward secrecyNo — one key per pairing
Open sourceNo
Independent auditNot yet

How pairing works

No phone number. No email. No account. In the same room, she shows a QR code and you scan it. Apart, she sends you a 6-character code or a link. Either way both phones exchange public keys, derive the same secret, and show a 6-digit verification code so the two of you can confirm no one sat in the middle.

1

She taps “Pair with partner” in PinkyBloom

2

Her phone generates a Curve25519 key pair (Apple CryptoKit on iPhone, Google Tink on Android)

3

She shows a QR code, or sends you a 6-character code or link if you are apart

4

You scan or enter it in PinkyBond, and your phone generates its own key pair

5

Your public key travels back to her the same way; both phones now hold both public keys

6

Each phone runs ECDH and HKDF-SHA256 to derive the same shared secret — nothing secret crosses the network

7

The shared secret is stored in the iOS Keychain or the Android Keystore

8

A 6-digit verification code appears on both phones; if they match, no one sat in the middle

The Blind Relay

ہمارا سرور بند لفافوں کے لیے ایک میل باکس ہے۔ یہ سائفر ٹیکسٹ صرف اس وقت تک رکھتا ہے جب تک دوسرا فون اسے لے نہ لے، پھر اسے حذف کر دیتا ہے — اگر وہ فون آف لائن رہے تو زیادہ سے زیادہ 30 دن بعد۔ اس کے پاس چابی کبھی نہیں ہوتی۔ پش نوٹیفیکیشنز میں کوئی متن نہیں ہوتا؛ فون مقامی طور پر ڈیکرپٹ کرتا ہے۔

PinkyBloom

Encrypts on her phone

→

Blind Relay

پہنچنے تک سائفر ٹیکسٹ رکھتا ہے، زیادہ سے زیادہ 30 دن

Cannot decrypt

→

PinkyBond

Decrypts on your phone

ایک پیغام، ایک فائل اور ایک کال کے بارے میں ہمارا سرور جو کچھ محفوظ کرتا ہے:

pairingId

Identifier for the pairing; not a name, number or email

senderRole

Which app sent it: PinkyBloom or PinkyBond

messageType

یہ کس قسم کا لفافہ ہے — مثلاً ایک چیٹ پیغام، ایک اسٹیٹس سنیپ شاٹ، ایک رسید یا کال سیٹ اپ — کبھی یہ نہیں کہ اندر کیا ہے

timestamp

When it was sent

ciphertext

AES-256-GCM blob we cannot open; its length is the only thing we can measure

retention

دوسرا فون وصول کرتے ہی حذف؛ اگر وہ آف لائن رہے تو زیادہ سے زیادہ 30 دن

relayReceipts

پہنچنے کے بعد، بغیر مواد کا ایک ریکارڈ: یہ کون سا پیغام تھا اور یہ پہنچا یا میعاد ختم ہوئی۔ 30 دن تک رکھا جاتا ہے، تاکہ بھیجنے والے کا فون "نہیں پہنچا" دکھا سکے

mediaObjects

تصاویر، وائس نوٹس، ویڈیوز اور فائلیں 2 GB تک، Cloudflare R2 پر سائفر ٹیکسٹ کے طور پر محفوظ، ہر فائل کے لیے ایک نئی چابی کے تحت جو صرف اینکرپٹڈ پیغام کے اندر ہی سفر کرتی ہے۔ آپ کے پارٹنر کا فون ڈاؤن لوڈ کرتے ہی حذف؛ زیادہ سے زیادہ 30 دن

callLog

دونوں فونز میں سے کس نے کال کی، کب، وائس یا ویڈیو، اٹینڈ کی، مس ہوئی یا مسترد کی، اور کتنی دیر چلی۔ ہمارا سرور پڑھ سکتا ہے — اسی طرح بند فون کو بھی مس کال کا پتا چلتا ہے۔ 90 دن تک رکھا جاتا ہے، ان پیئر کرنے پر حذف۔ آڈیو یا ویڈیو کبھی نہیں

Calls

Voice and video are peer-to-peer WebRTC with DTLS-SRTP and fresh keys for every call. The call setup rides the encrypted relay like any message. Before media flows, your phone checks the peer's DTLS fingerprint against a key derived from the pairing secret; a failed check aborts the call.

جب نیٹ ورک براہ راست راستہ بلاک کر دے تو ایک ریلے وہ پیکٹس آگے بھیجتا ہے جو وہ پڑھ نہیں سکتا۔ کوئی میڈیا سرور کبھی کال نہیں سنتا، اور کوئی کال ریکارڈ نہیں ہوتی۔ یہ iPhone سے Android تک کام کرتا ہے۔ ہمارا سرور جو رکھتا ہے وہ ایک کال لاگ ہے — کون سے فون نے کال کی، کب، وائس یا ویڈیو، نتیجہ اور کتنی دیر چلی — 90 دن کے لیے، تاکہ جس پارٹنر کا فون بند تھا وہ بھی مس کال دیکھ سکے۔ مزید معلومات /calls.

Safety Mode

Encryption protects her data from outsiders and from us. Safety Mode is for the case where the person on the other end is the concern. She can pause sharing at any time, and he is never notified. She can also turn on Safety Mode, which substitutes neutral data he cannot distinguish from a real update.

When Safety Mode is active, the partner sees:

Phase

“Follicular”

Mood

“Good”

Energy

3 (Moderate)

The neutral data is encrypted and sent through the normal relay, so it looks the same as a real update in transit and on his screen.

Questions

Encrypted between the two phones. We never hold the key.

No phone number, no email, no account. The same cryptography on iPhone and Android, and a relay that forwards ciphertext it cannot open.

Download on the App StoreGet it on Google Play
Download on the App StoreGet it on Google Play