Encryption
How PinkyBond encrypts messages and calls
Everything she shares with you is encrypted on her phone and decrypted on yours. Our server forwards sealed envelopes it cannot open. We never hold the key.
Built on platform cryptography
We did not write our own crypto. On iPhone we use Apple's CryptoKit. On Android we use Google's Tink. Curve25519 key agreement, HKDF-SHA256 and AES-256-GCM on both, pinned to each other by shared test vectors, so an iPhone and an Android phone produce byte-for-byte identical ciphertext.
Key agreement
Curve25519 (X25519) ECDH
Encryption
AES-256-GCM
Key derivation
HKDF-SHA256
What we do, and what we don't
Every row is checkable. The last three are where we fall short of the best messengers, and we would rather you read that here than find it out later.
| Dimension | PinkyBond |
|---|---|
| Encryption | AES-256-GCM, end-to-end between the two phones |
| Key agreement | Curve25519 (X25519) ECDH, then HKDF-SHA256 |
| Implementation | Apple CryptoKit on iPhone, Google Tink on Android — byte-for-byte interoperable |
| Key storage | iOS Keychain / Android Keystore, hardware-backed where available |
| Pairing | QR code in person, or a 6-character code / link exchanged remotely; both public keys exchanged |
| Verification | A 6-digit code on both phones confirms no one sat in the middle |
| Account | None — no phone number, no email, no password |
| 服务器对消息和通话内容的访问权限 | 没有。我们从不持有密钥。 |
| What the relay stores | 配对 ID、消息类型、时间戳、大小、密文——送达后即删除,最多保留 30 天 |
| 照片、视频和文件 | 最多 2 GB,每个文件都用一把只有你们两部手机持有的新密钥加密封存;下载后即删除,最多保留 30 天。发送给尚未更新的伴侣应用:使用配对密钥加密,最多 25 MB,保留 30 天 |
| 通话记录 | 哪部手机拨打的、何时拨打、语音还是视频、结果和时长——我们的服务器可以读取,保留 90 天,解除配对后删除。绝不包含音频或视频内容。 |
| Push notifications | Carry no text; the phone decrypts locally |
| Safety Mode | Yes — her phone sends neutral substitute data instead of her real status. Your app shows no indicator, though the flag itself is in the snapshot. |
| Forward secrecy | No — one key per pairing |
| Open source | No |
| Independent audit | Not yet |
How pairing works
No phone number. No email. No account. In the same room, she shows a QR code and you scan it. Apart, she sends you a 6-character code or a link. Either way both phones exchange public keys, derive the same secret, and show a 6-digit verification code so the two of you can confirm no one sat in the middle.
She taps “Pair with partner” in PinkyBloom
Her phone generates a Curve25519 key pair (Apple CryptoKit on iPhone, Google Tink on Android)
She shows a QR code, or sends you a 6-character code or link if you are apart
You scan or enter it in PinkyBond, and your phone generates its own key pair
Your public key travels back to her the same way; both phones now hold both public keys
Each phone runs ECDH and HKDF-SHA256 to derive the same shared secret — nothing secret crosses the network
The shared secret is stored in the iOS Keychain or the Android Keystore
A 6-digit verification code appears on both phones; if they match, no one sat in the middle
The Blind Relay
我们的服务器就像一个存放密封信封的邮箱。它只在对方手机取走密文之前保留密文,取走后即删除——如果对方手机一直离线,最多保留 30 天后删除。它从不持有密钥。推送通知不携带任何文本;手机在本地解密。
PinkyBloom
Encrypts on her phone
Blind Relay
保留密文直至送达,最多 30 天
Cannot decrypt
PinkyBond
Decrypts on your phone
我们的服务器就一条消息、一个文件和一通电话所存储的一切:
pairingId
Identifier for the pairing; not a name, number or email
senderRole
Which app sent it: PinkyBloom or PinkyBond
messageType
信封的类型——例如聊天消息、状态快照、送达回执或通话建立请求——绝不包括信封里的内容
timestamp
When it was sent
ciphertext
AES-256-GCM blob we cannot open; its length is the only thing we can measure
retention
对方手机收到后立即删除;如果对方一直离线,最多保留 30 天
relayReceipts
送达后,会留下一条不含内容的记录:是哪条消息,以及它是已送达还是已过期。保留 30 天,以便发送方手机能显示“未送达”
mediaObjects
照片、语音留言、视频和最多 2 GB 的文件,以密文形式存储在 Cloudflare R2 上,每个文件使用一把只随加密消息一起传输的新密钥。你的伴侣手机下载后即删除;最多保留 30 天
callLog
两部手机中哪一部拨打的、何时拨打、语音还是视频、已接听、未接还是已拒接,以及通话时长。我们的服务器可以读取——这正是关机的手机仍能得知未接来电的方式。保留 90 天,解除配对后删除。绝不包含音频或视频
Calls
Voice and video are peer-to-peer WebRTC with DTLS-SRTP and fresh keys for every call. The call setup rides the encrypted relay like any message. Before media flows, your phone checks the peer's DTLS fingerprint against a key derived from the pairing secret; a failed check aborts the call.
当网络阻断直连路径时,中继服务器会转发它无法读取的数据包。任何媒体服务器都绝不会听到通话内容,也绝不会录制任何通话。它在 iPhone 与 Android 之间同样有效。我们的服务器保留的是通话记录——哪部手机拨打的、何时拨打、语音还是视频、结果和时长——保留 90 天,以便手机关机的伴侣仍能看到未接来电。详见 /calls.
Safety Mode
Encryption protects her data from outsiders and from us. Safety Mode is for the case where the person on the other end is the concern. She can pause sharing at any time, and he is never notified. She can also turn on Safety Mode, which substitutes neutral data he cannot distinguish from a real update.
When Safety Mode is active, the partner sees:
Phase
“Follicular”
Mood
“Good”
Energy
3 (Moderate)
The neutral data is encrypted and sent through the normal relay, so it looks the same as a real update in transit and on his screen.
