Encryption
How PinkyBond encrypts messages and calls
Everything she shares with you is encrypted on her phone and decrypted on yours. Our server forwards sealed envelopes it cannot open. We never hold the key.
Built on platform cryptography
We did not write our own crypto. On iPhone we use Apple's CryptoKit. On Android we use Google's Tink. Curve25519 key agreement, HKDF-SHA256 and AES-256-GCM on both, pinned to each other by shared test vectors, so an iPhone and an Android phone produce byte-for-byte identical ciphertext.
Key agreement
Curve25519 (X25519) ECDH
Encryption
AES-256-GCM
Key derivation
HKDF-SHA256
What we do, and what we don't
Every row is checkable. The last three are where we fall short of the best messengers, and we would rather you read that here than find it out later.
| Dimension | PinkyBond |
|---|---|
| Encryption | AES-256-GCM, end-to-end between the two phones |
| Key agreement | Curve25519 (X25519) ECDH, then HKDF-SHA256 |
| Implementation | Apple CryptoKit on iPhone, Google Tink on Android — byte-for-byte interoperable |
| Key storage | iOS Keychain / Android Keystore, hardware-backed where available |
| Pairing | QR code in person, or a 6-character code / link exchanged remotely; both public keys exchanged |
| Verification | A 6-digit code on both phones confirms no one sat in the middle |
| Account | None — no phone number, no email, no password |
| 伺服器對訊息與通話內容的存取權限 | 沒有。我們絕不持有密鑰。 |
| What the relay stores | 配對 ID、訊息類型、時間戳、大小、密文——送達後立即刪除,最多保留 30 天 |
| 相片、影片和檔案 | 最多 2 GB,每個檔案都以一條只有你們兩部手機持有的全新密鑰加密封存;下載後立即刪除,最多保留 30 天。傳送給尚未更新的伴侶應用程式:以配對密鑰加密,最多 25 MB,保留 30 天 |
| 通話記錄 | 哪部手機撥打的、何時撥打、語音還是視像、結果和時長——我們的伺服器可以讀取,保留 90 天,解除配對後刪除。絕不包含音訊或影像內容。 |
| Push notifications | Carry no text; the phone decrypts locally |
| Safety Mode | Yes — her phone sends neutral substitute data instead of her real status. Your app shows no indicator, though the flag itself is in the snapshot. |
| Forward secrecy | No — one key per pairing |
| Open source | No |
| Independent audit | Not yet |
How pairing works
No phone number. No email. No account. In the same room, she shows a QR code and you scan it. Apart, she sends you a 6-character code or a link. Either way both phones exchange public keys, derive the same secret, and show a 6-digit verification code so the two of you can confirm no one sat in the middle.
She taps “Pair with partner” in PinkyBloom
Her phone generates a Curve25519 key pair (Apple CryptoKit on iPhone, Google Tink on Android)
She shows a QR code, or sends you a 6-character code or link if you are apart
You scan or enter it in PinkyBond, and your phone generates its own key pair
Your public key travels back to her the same way; both phones now hold both public keys
Each phone runs ECDH and HKDF-SHA256 to derive the same shared secret — nothing secret crosses the network
The shared secret is stored in the iOS Keychain or the Android Keystore
A 6-digit verification code appears on both phones; if they match, no one sat in the middle
The Blind Relay
我們的伺服器就像一個存放密封信封的郵箱。它只在對方手機取走密文之前保留密文,取走後即刪除——如果對方手機一直離線,最多保留 30 天後刪除。它從不持有密鑰。推送通知不會攜帶任何文字;手機在本機解密。
PinkyBloom
Encrypts on her phone
Blind Relay
保留密文直到送達,最多 30 天
Cannot decrypt
PinkyBond
Decrypts on your phone
我們的伺服器就一則訊息、一個檔案和一通電話所儲存的一切:
pairingId
Identifier for the pairing; not a name, number or email
senderRole
Which app sent it: PinkyBloom or PinkyBond
messageType
信封的類型——例如聊天訊息、狀態快照、送達回條或通話建立請求——絕不包括信封裡的內容
timestamp
When it was sent
ciphertext
AES-256-GCM blob we cannot open; its length is the only thing we can measure
retention
對方手機收到後立即刪除;若對方一直離線,最多保留 30 天
relayReceipts
送達後,會留下一筆不含內容的記錄:是哪一則訊息,以及它是已送達還是已過期。保留 30 天,讓發送方的手機可以顯示「未送達」
mediaObjects
相片、語音訊息、影片和最多 2 GB 的檔案,以密文形式儲存在 Cloudflare R2 上,每個檔案使用一條只隨加密訊息一同傳輸的全新密鑰。你的伴侶手機下載後即刪除;最多保留 30 天
callLog
兩部手機當中哪一部撥打的、何時撥打、語音還是視像、已接聽、未接還是已拒接,以及通話時長。我們的伺服器可以讀取——這正是關機的手機仍能得悉未接來電的方式。保留 90 天,解除配對後刪除。絕不包含音訊或影像
Calls
Voice and video are peer-to-peer WebRTC with DTLS-SRTP and fresh keys for every call. The call setup rides the encrypted relay like any message. Before media flows, your phone checks the peer's DTLS fingerprint against a key derived from the pairing secret; a failed check aborts the call.
當網絡阻擋直連路徑時,中繼伺服器會轉發它無法讀取的數據包。任何媒體伺服器都絕不會聽到通話內容,亦絕不會錄製任何通話。它在 iPhone 與 Android 之間同樣有效。我們的伺服器保留的是通話記錄——哪部手機撥打的、何時撥打、語音還是視像、結果和時長——保留 90 天,讓關機的伴侶仍能看到未接來電。詳見 /calls.
Safety Mode
Encryption protects her data from outsiders and from us. Safety Mode is for the case where the person on the other end is the concern. She can pause sharing at any time, and he is never notified. She can also turn on Safety Mode, which substitutes neutral data he cannot distinguish from a real update.
When Safety Mode is active, the partner sees:
Phase
“Follicular”
Mood
“Good”
Energy
3 (Moderate)
The neutral data is encrypted and sent through the normal relay, so it looks the same as a real update in transit and on his screen.
