How Nsibi protects a conversation
Chats are end-to-end encrypted with the Signal protocol. The keys are made on your phone and never leave it, so the copy we carry is one we cannot open.
The keys are made on your phone
Nsibi uses the Double Ratchet, the same design behind Signal, through an audited Rust implementation. Your device generates its own keys on first launch and publishes only their public halves. Nothing that can open a message is ever uploaded.
The server carries sealed messages
A message reaches our servers already locked, and is stored that way. We can route it, hold it until your phone is online and count it, and at no point can we read it. Neither can anyone who reaches the server.
Calls are encrypted too
A one-to-one call flows directly between phones. A group call is relayed by a server that forwards frames it cannot decode, because the frames are encrypted before they leave the caller.
End-to-end encrypted by default
There is no setting to find and nothing to switch on. Every one-to-one and group chat is encrypted from the first message.
Text and voice messages
Sealed on your device and opened only on the devices you sent them to.
Photos, videos and documents
A file is encrypted before it is uploaded, and the key that opens it travels inside the encrypted message rather than with the file.
Audio and video calls
Encrypted end to end, one-to-one and in a group, for both audio and video.
Location and contact sharing
A shared place or contact card is an ordinary chat message, so it is protected exactly like the rest of the conversation.
Your backup
A chat backup is encrypted with a key only you hold. We store a blob we cannot open, and we cannot recover it for you if you lose the key. That is the point of it.
Your notifications
The text on your lock screen is decrypted on your phone, by your phone. The notification we send carries no readable message.
What is not encrypted
Encryption covers your conversations. It does not cover everything in the app, and we would rather say so here than let you assume otherwise.
Posts, comments and statuses
Anything you publish to a feed or post as a status is readable by our servers. It has to be: ranking, search, moderation and enforcing who is allowed to see a post all need the content. Treat a post as public even when its audience is limited.
Who you talk to, and when
To deliver a message we necessarily handle who it is for and roughly when it was sent. We keep as little of this as we can, and it is never the content of what you said.
Your phone number
Your account is your number, so we hold it. Your contact list is not uploaded - your phone hashes each number and asks us only whether a match exists.
You do not have to take our word for it
Every chat has a safety number that both people can compare. If it matches, no one is sitting in the middle. If someone reinstalls or changes phone, the number changes and you can check again.