CRYPTICO · Security atlas
How it works · What stays private · Where protection ends

Follow the message.
See the boundaries.

A visual guide to how Cryptico encrypts, delivers and stores — and to what it does not hide.

01System map

Only the endpoints can read a message.

Every box between two people carries sealed envelopes. Plaintext exists only on user devices.

Plaintext · user devices
WebBrowser app
AndroidPhone app
iOSPhone app
HTTPS + WebSocket · ciphertext + routing metadata
Cloudflare proxyTerminates TLS for app traffic. Sees request metadata, IP addresses and session tokens — not message content.
Cryptico serverAccounts, public keys, message queue, groups, call set-up, wake-ups. Stores and forwards opaque ciphertext; never decodes message content.
store · fetch
DatabaseCiphertext + routing metadata
File storageEncrypted attachments only
Call media · does not pass the server
Device
encrypted media · 1:1 call
TURN relayRelays encrypted media; hides callers’ IP addresses from each other
Device
Device
encrypted frames · group call
LiveKit media serverForwards encrypted frames; has no room key
Devices
Wake-ups · no content
Cryptico server“there is something new”
no text, no sender
Google FCM · Apple APNs · Web Push
content-free signal
DeviceWakes up, fetches ciphertext, decrypts
Plaintext (user devices)Ciphertext + metadataThird-party service

L2. Encrypted attachments also travel through the Cloudflare proxy on their way to file storage. The server code does not contain the message-content format at all.

02Identity without a phone number

An account is a random number and 12 words.

No phone, no email, no real name on the account.

What an account is
  • Random ID — generated by the server
  • Optional username — 3–32 letters, digits or underscore; unique
  • 12 recovery words — generated on your device, never sent anywhere
What Cryptico never asks for
  • Phone number or SMS code
  • Email address
  • Real name on the account
  • Address-book upload
  • Recovery through support
UsernameOthers can find you only if you set one
or
Invitation linkRandom token · can expire or be limited
or
QR codeShown in person
Lose the 12 words, lose the account.There is no reset: the words are the only key.

L2. A deleted username is never issued again. A display name exists only inside the encrypted profile (section 19). Each linked device has a name that the server can see — on Android it is the phone model by default.

03Key derivation tree

One phrase grows every key — on the device.

Each key has one job, so a key made for one purpose is never reused for another.

12 BIP39 words128 bits of randomness · generated on the device
PBKDF2-HMAC-SHA512
Seed
Argon2id · 64 MiB of memory
Master keyArgon2id makes guessing the phrase deliberately expensive
HKDF-SHA256 · one label per purpose
Storage keyEncrypts the local database, private account storage and mini-app data
Identity keyYour Signal identity (Curve25519)
Sign-in keyEd25519 · signs one-time sign-in challenges
Endorsement keyEd25519 · vouches for your devices
Mini-app branch · derived from the storage key
Per-app identityA separate Ed25519 key for every mini-app, unlinkable across apps
Never leaves the device in readable form: the phrase and every key derived from it.Only public keys are published to the server.

L2. The identity key is derived deterministically, so it is the same on every device of one account; each device still has its own device ID and its own prekeys.

04Account creation

Creating an account proves you hold a secret — without sending it.

The server receives a signature and public keys. The words stay on the phone.

Your device
Cryptico server
01Generate 12 words, confirm 3 of themderive keys locally
02Ask for a challenge
Single-use challengeexpires after a short time
03Sign the challengewith the sign-in key
Registerpublic sign-in key · signature
04Create account + first deviceone transaction
Account ID + session tokens
05Publish public keys onlyidentity · signed prekey · post-quantum (Kyber) prekey · one-time prekeys
Never sent: the 12 words and every private key. The device tops up its one-time prekeys automatically.
Plaintext exists only here (a user device)Sees ciphertext and routing metadataEnd-to-end encryptedVisible metadata- - - dashed arrow: conditional path
05Signing in and sessions

Sign a challenge instead of sending a password.

Each challenge works once, so a signature cannot be reused.

Your device
Cryptico server
01Ask for a challengebound to your public key and to the action
Single-use challenge
02Sign itthe private key stays on the device
Signature
03Verifya wrong key and a wrong signature get the same answer
Short-lived access token + refresh token
Every renewal
04Refresh token
Replace both tokensserver keeps only a hash of the refresh token
New pair
05Each refresh token works oncereuse is treated as theft
AndroidSession tokens wrapped by a hardware-backed key
iOSSession tokens wrapped by a Keychain key
WebTokens kept in browser storage

L2. The same challenge-and-signature step protects linking a device, listing and removing devices, and deleting the account.

06A message, step by step

A message is sealed before it leaves the phone.

From “Send” to “Read”. The server only ever holds the sealed envelope.

Alice’s phone
Alice’s other devices
Cryptico server
Bob’s phone
01Composemessage ID = sender + send time
02Encrypt once per devicefor each of Bob’s devices · a separate “sent” copy for Alice’s other devices
03Wrap in an envelopeonly the encrypted part is secret
04Sendvisible: sender, recipient device, size, “wake?” flag
05Queueper recipient device
“Sent” copies
06Wake-up pushcontent-free · when the app is not connected
07Deliver over WebSocket
08Decryptdrop duplicates
09Acknowledge
10Deleteon acknowledgement, or after 7 days uncollected
Plaintext exists only here (a user device)Sees ciphertext and routing metadataEnd-to-end encryptedVisible metadata- - - dashed arrow: conditional path

L2. Delivery is at-least-once; duplicates are dropped by message ID. Chat order follows server time; a message that arrives much later than it was sent is marked late.

07Three layers of a message

The outside of the envelope is not the letter.

Three nested layers — each with a different audience.

1 · Requestvisible to the server and the proxy
recipientsender (from the session)“wake?” flagsize · time · IP
2 · Envelope headernot encrypted · stored as is
sendersender devicerecipient devicemessage type
3 · Encrypted contentonly the devices
textreactionsreceiptsattachment keyscall keysprofile key…

L2. Layer 2 is readable by anyone with access to the server’s database — it tells who sent a message to whom, never what it says. The server code cannot decode layer 3: the content format is not part of it.

08What stays inside encryption

Far more than the text is sealed.

Everything people associate with a conversation travels inside the encrypted envelope.

Inside end-to-end encryption
ConversationText, replies, forwards, edits, delete-for-everyone, reactions
ActivityDelivery and read receipts, typing indicator, @mentions
Shared objectsPolls and votes, checklists, location, contact cards
FilesAttachment key, file ID, hash, encrypted preview, caption
CallsCall set-up and media keys
Profile & groupsProfile key; group name and membership notices
Account deletedNotice sent to contacts
Outside — visible to the server
  • Routing: sender, recipient, time, size
  • A “wake the phone?” flag on each envelope
  • In groups only: which members were @mentioned — so a mention can break through mute

L2. Envelopes are not padded to a fixed size, so the server sees approximate message size. Group membership is also known to the server (section 11).

09Who can see what

Content is private. The fact of communication is not.

Every observer, every kind of data. Read across a row to see what one party learns.

can readencrypted — cannot readdoes not receivevisiblepartly visiblenot assessed
ObserverTextFilesProfileContactsWho ↔ whomWhenSizeIP addressGroup membersCall media
Your deviceReadableReadableReadableReadableYesYesYesOwn IPYour groupsReadable
Peer deviceWhat you send themWhat you send themOnce you have chatted, or on request in a shared groupOnly contact cards you sendYour exchanges with themYesYesNot in relayed calls; yes if a call falls back to directShared groupsCalls with you
Cryptico serverEncryptedEncryptedEncryptedEncryptedYesYesYesYesYes, with rolesNot carried; call set-up encrypted
DatabaseCiphertextFile ID, size, ownerEncryptedEncryptedYes — envelope headers, groups, blocks, mutesYesYesNot storedYesNot stored
File storageNot heldEncrypted filesNot heldNot held—Upload timeFile size—Not heldNot held
CloudflareEncryptedEncrypted files in transitEncryptedEncryptedRequest metadataYesYesYesGroup requestsNot carried
Google FCMNoNoNoNoNo sender or chat; wake-up timing can hintWake-up timesNoYesNoOnly that it is a call
Apple APNsNoNoNoNoNo sender or chat; wake-up timing can hintWake-up timesNoYesNoOnly that it is a call
Web Push serviceNoNoNoNoNo sender or chat; wake-up timing can hintWake-up timesNoYesNoNot even the type
LiveKit (group calls)NoNoNoNoWho is in which group callYes—YesCall participantsEncrypted frames
TURN relay (calls)NoNoNoNoCallers’ account IDs and IPsYes—Both sidesNoEncrypted
Mini-appNoNoOnly an app-specific alias, if you set oneNoNoIts own backend: request times—Its own backendNoNo
Someone holding your phone (no app lock)Readable — the app reopens by itselfSameSameSameSameSame——Same—
Someone with your 12 wordsNew messages, plus contacts’ recent messages their apps re-send to a new deviceSame as textYesYesYour chat list——NoYour groups—
Your device5 readable · 5 visible
Text
Readable
Files
Readable
Profile
Readable
Contacts
Readable
Who ↔ whom
Yes
When
Yes
Size
Yes
IP address
Own IP
Group members
Your groups
Call media
Readable
Peer device4 readable · 6 visible
Text
What you send them
Files
What you send them
Profile
Once you have chatted, or on request in a shared group
Contacts
Only contact cards you send
Who ↔ whom
Your exchanges with them
When
Yes
Size
Yes
IP address
Not in relayed calls; yes if a call falls back to direct
Group members
Shared groups
Call media
Calls with you
Cryptico server5 visible
Text
Encrypted
Files
Encrypted
Profile
Encrypted
Contacts
Encrypted
Who ↔ whom
Yes
When
Yes
Size
Yes
IP address
Yes
Group members
Yes, with roles
Call media
Not carried; call set-up encrypted
Database5 visible
Text
Ciphertext
Files
File ID, size, owner
Profile
Encrypted
Contacts
Encrypted
Who ↔ whom
Yes — envelope headers, groups, blocks, mutes
When
Yes
Size
Yes
IP address
Not stored
Group members
Yes
Call media
Not stored
File storage2 visible
Text
Not held
Files
Encrypted files
Profile
Not held
Contacts
Not held
Who ↔ whom
—
When
Upload time
Size
File size
IP address
—
Group members
Not held
Call media
Not held
Cloudflare5 visible
Text
Encrypted
Files
Encrypted files in transit
Profile
Encrypted
Contacts
Encrypted
Who ↔ whom
Request metadata
When
Yes
Size
Yes
IP address
Yes
Group members
Group requests
Call media
Not carried
Google FCM4 visible
Text
No
Files
No
Profile
No
Contacts
No
Who ↔ whom
No sender or chat; wake-up timing can hint
When
Wake-up times
Size
No
IP address
Yes
Group members
No
Call media
Only that it is a call
Apple APNs4 visible
Text
No
Files
No
Profile
No
Contacts
No
Who ↔ whom
No sender or chat; wake-up timing can hint
When
Wake-up times
Size
No
IP address
Yes
Group members
No
Call media
Only that it is a call
Web Push service3 visible
Text
No
Files
No
Profile
No
Contacts
No
Who ↔ whom
No sender or chat; wake-up timing can hint
When
Wake-up times
Size
No
IP address
Yes
Group members
No
Call media
Not even the type
LiveKit (group calls)4 visible
Text
No
Files
No
Profile
No
Contacts
No
Who ↔ whom
Who is in which group call
When
Yes
Size
—
IP address
Yes
Group members
Call participants
Call media
Encrypted frames
TURN relay (calls)3 visible
Text
No
Files
No
Profile
No
Contacts
No
Who ↔ whom
Callers’ account IDs and IPs
When
Yes
Size
—
IP address
Both sides
Group members
No
Call media
Encrypted
Mini-app3 visible
Text
No
Files
No
Profile
Only an app-specific alias, if you set one
Contacts
No
Who ↔ whom
No
When
Its own backend: request times
Size
—
IP address
Its own backend
Group members
No
Call media
No
Someone holding your phone (no app lock)7 readable
Text
Readable — the app reopens by itself
Files
Same
Profile
Same
Contacts
Same
Who ↔ whom
Same
When
Same
Size
—
IP address
—
Group members
Same
Call media
—
Someone with your 12 words3 readable · 3 visible
Text
New messages, plus contacts’ recent messages their apps re-send to a new device
Files
Same as text
Profile
Yes
Contacts
Yes
Who ↔ whom
Your chat list
When
—
Size
—
IP address
No
Group members
Your groups
Call media
—

L2. “—” marks a cell this atlas does not assess. IP addresses are not stored in the database or in the web access log; some error logs can still contain them.

10First handshake and the ratchet

The first exchange starts a chain of fresh keys.

Bob can be offline: he left public “locks” on the server in advance.

Alice’s phone
Cryptico server
Bob’s phone
01Publish public prekeys in advancesigned prekey · Kyber prekey · one-time prekeys
02Request Bob’s prekey bundle
Bundle (public keys only)
03PQXDHCurve25519 + Kyber-1024 → shared secret
04First messagelets Bob compute the same secret
05Same shared secretboth sides start the Double Ratchet
Shared secret
ratchet
Key 1message 1 only
ratchet
Key 2message 2 only
ratchet
Key 3message 3 only
Post-quantum scope: the first key exchange only.Kyber-1024 protects session set-up against “record now, decrypt later”. The rest of the system is not claimed to be post-quantum.

L2. A new key for every message gives forward secrecy and recovery after compromise: a stolen key opens one message, not the ones before or after.

11Groups

Group keys go to the members the server lists.

The server keeps the member list. The group name and the messages stay on devices.

The server knows
  • Group ID and creation date
  • Members, roles (admin / member), join dates
  • Invitation links and how often they were used
Only devices know
  • Group name
  • Messages
  • Sender keys
Alice’s phone
Cryptico server
Members’ devices
01Who is in the group?
Member list
02Alice’s sender keypairwise, over 1:1 encrypted channels · only to listed members
03One group envelope
04Copy to every member device
Deliver
05Decrypt with Alice’s sender key
Plaintext exists only here (a user device)Sees ciphertext and routing metadataEnd-to-end encryptedVisible metadata- - - dashed arrow: conditional path

L2. Up to 128 members. Alice’s own other devices get a separate “sent” copy, not the group copy.

12Attachments

The file key travels inside the encrypted message.

Storage holds a locked box; the key goes separately, sealed.

Sender’s phone
Server + file storage
Recipient’s phone
01Strip metadatacamera photos re-encoded (location gone) · video metadata blocks neutralised
02EncryptAES-256-GCM · a fresh key for every file
03Fingerprint the ciphertextSHA-256
04Upload encrypted fileshort-lived upload link
Keep 7 daysknows file ID, size, owner, time
05Key + fingerprint + file IDinside an end-to-end encrypted message, with encrypted preview and caption
06Download encrypted file
07Check the fingerprint, then decrypt
7 daysLife of a file on the server
25 MiBMaximum file size

L2. Re-encoding covers camera formats (JPEG, HEIC). PNG, GIF and WebP images are sent unchanged, so check what such files contain before sending.

131:1 calls

Call set-up is encrypted; media goes through a relay by default.

The relay hides the two callers’ IP addresses from each other — while it works.

Caller
Cryptico server
TURN relay
Callee
01Invite and connection detailsinside E2EE messages
Forwarded as ciphertextthe server sees who calls whom
02Encrypted media
Encrypted media
If the relayed connection fails
03Automatic switch to directIP addresses become visible to each other · the app shows a warning
04Compare the 6-digit codeboth screens show the same code if no one is in between
Plaintext exists only here (a user device)Sees ciphertext and routing metadataEnd-to-end encryptedVisible metadata- - - dashed arrow: conditional path

L2. The relay sees both IP addresses and the callers’ account IDs, not the media. Relay credentials are temporary. The code is derived from the call and from both sides’ encryption certificates.

14Group calls

The media server never gets the room key.

Every frame is encrypted with a key the members hand to each other.

Member device
Cryptico server
LiveKit media server
Other members
01Generate room keyrandom, on the device
02Room key to each memberinside end-to-end encrypted messages
03Permission to joingroup members only
04Encrypted frames
Forwarded · no key
Someone joins or leaves
05A member generates a new random keynewer keys always replace older ones
New key via E2EE
Plaintext exists only here (a user device)Sees ciphertext and routing metadataEnd-to-end encryptedVisible metadata- - - dashed arrow: conditional path

L2. Up to 8 video streams and screen sharing. Asked who is in a call, the server tells group members only the number of participants. The media server itself sees which accounts joined, when and from which IP — not the media.

15Devices

A new device gets your account, not your history.

Up to 10 devices per account. Each one is vouched for by the account key.

New device
Cryptico server
Your other devices
Contacts’ devices
01Enter the same 12 words
Signed link request
New device IDnever reused
02“New device” noticecontent-free wake-up
03Endorse the device with the account keycovers account, device, identity key, expiry
Upload endorsement
04Public keys + endorsementthe server stores it, cannot forge it
05Check against the remembered account keya forged device fails
Moves to the new device
  • Profile
  • Contacts
  • Folders
  • Some settings
  • Chat list
  • Blocks
  • Mini-app data
Does not move
  • Your message history
  • Attachments
  • Call history
  • Drafts
  • “Verified” marks
Removing a deviceIts sessions end; its keys, queued messages and push registration are deleted. A device unused for 30 days is retired automatically.

L2. Contacts’ apps may automatically re-send their own recent messages to a new device. A forged device is caught once a contact remembers your account key; the very first sighting is trust on first use.

16Verifying the other person

Check the first contact once — then a change raises an alarm.

The app remembers a key the first time it sees it. Comparing a number proves nobody is in between.

First contactThe other person’s identity key is remembered (trust on first use)
compare the 60-digit number
VerifiedMark kept on your device for that contact
key changes
Warning“Verified” removed · sending to that contact stops
Safety number60 digits · read aloud or compare side by side
In a call6-digit code; both screens match if no one is in between
The first contact is not automatically protected.Only comparing the safety number closes it.

L2. Available on web, Android and iOS. The “verified” mark is not synced to your other devices.

17Protection on the device

A stolen phone shows locked files — if it has an app lock.

Data at rest is encrypted; the app lock decides who can open it.

12 words
derive
Storage keynever stored in readable form
encrypts
Local chat database + Signal keysSQLCipher on phones · AES-256-GCM in the browser
PIN or biometrics
unlocks
Protected copy of the derived keysnot the phrase itself
too many wrong PINs
Protected copy erasedthe 12 words are needed again
Set a PIN on phones.Without one, the phone keeps a hardware-protected copy so the app reopens by itself — anyone who can unlock the phone can open the app.
MechanismWebAndroidiOS
Chat databaseEncrypted (AES-256-GCM)SQLCipher · one file per accountSQLCipher · one file per account
Signal key storeEncryptedSQLCipherSQLCipher
Hardware key storeNoneAndroid KeystoreKeychain (this device only); Secure Enclave for biometrics
PINArgon2id + AES-256-GCMSame + hardware layerSame + Keychain
BiometricsWebAuthnFingerprint / face; invalidated when enrolment changesFace ID / Touch ID; no passcode fallback
Auto-lockYesYesYes
Lock when the connection dropsYes, with a PINYes, with a PINYes, with a PIN
Screen captureCannot be blockedBlocked on the phrase and PIN screens onlyPhrase and PIN hidden while recording; app hidden in the switcher when a PIN is set; screenshots cannot be blocked

L2. A PIN is a convenience barrier; the strong secret is the 12-word phrase. In a browser there is no hardware key store, so someone with a copy of the browser’s data can try PINs offline.

18Private account storage

Your settings sync, but the server sees only random names.

How contacts, chats and folders reach your other devices.

Your device
Cryptico server
Your other device
01Name → HMAC-SHA256 under the storage keye.g. “contacts” becomes a random string
02Contents → AES-256-GCM under the storage key
Saverandom name + ciphertext
Stores itsees: a record exists, its size, when it changed
Fetch
03Decrypt and mergenewest change wins
Syncedcontacts · chats · folders · settings · profile · mini-app data
Never syncedApp-lock (PIN) state · message history

L2. This is not a message backup: history does not travel this way.

19Profile

Your name and photo are locked with their own key.

The profile is encrypted; the key is handed out inside encrypted chats.

Your device
Cryptico server
A contact’s device
01Random profile key
02Encrypt name, photo, bioAES-GCM
Encrypted profile
03Profile keyinside E2EE · to people you chat with 1:1, and to shared-group members who ask
Encrypted profile
04Decrypt and show
Anyone who starts a chat with you can see your name and photo.Do not put anything in your profile you would not show a stranger.

L2. The server sees that a profile exists, its size and when it changed. A username, if you set one, is separate from the encrypted profile.

20Push notifications

A push wakes the app; it does not carry the message.

Google, Apple and browser push services learn that something happened and when — not what or from whom.

Cryptico server
Push service
Your phone
01Wake-upno text, no sender
Content-free signal
02Fetch encrypted messages
03Decrypt locally
ChannelWhat the push carriesWho draws the notification
Google FCM (Android)Only “message” or “call”The app itself, after decrypting · hidden on the lock screen
Apple APNs (iOS)A fixed “New message” phrase, the same for everyone · a separate call signaliOS, from that fixed phrase
Web Push (browser)One fixed “wake” signal, the same for messages and callsThe open tab after decrypting, otherwise a generic “New message”
Push services can see
  • That the app is installed
  • The exact time of every wake-up
  • Message or call (FCM, APNs)
  • IP address
Push services never receive
  • Message content
  • Keys or the 12 words
  • Who sent it
  • Which chat

L2. New messages, calls and account notices (new device, added to a group) wake the phone; reactions, receipts and edits do not. Message previews are off by default. Muted chats are not woken — for that, the server keeps the list of chats you muted. Wake-up timing for two people can statistically suggest they talk.

21How long things live

Messages and files are short-lived on the server.

Maximum lifetimes on the server.

1 day ── 7 days ── 30 days (log scale)
Default contact link (in the app)
1 day
Queued message
≤ 7 days / until delivered
Attachment
7 days
Unused device
retired after 30 days
ProfileNo expiry
Deleted usernameReserved forever; the record has no account link and no date
Kept as recordsRetired devices stay in the database. Expired session and link records are removed after a short grace period

Queued messages are deleted as soon as they are acknowledged — 7 days is the ceiling, not the norm.

22What the server stores

Stored metadata is part of the security model.

The kinds of records the server keeps — and what is deliberately absent from them.

RecordStored / revealsDeliberately absent
AccountRandom ID, optional username, public keys, creation datePhone, email, name, password, phrase
DeviceDevice list, device name, last connection, endorsement · retired devices are keptPrivate keys
Signal public keysIdentity and prekeys (public only)Private keys, session state
Message queueRecipient, envelope header with the sender, ciphertext, timeReadable content · deleted on delivery or after 7 days
SessionsHash of each refresh token and when it was issued — removed after a short grace period once expiredThe tokens themselves
GroupMembers, roles, join dates, invitation links with use countsGroup name
Contact linksWho created a link, its limits and how often it was used — removed after a short grace period once it stops workingWho used it
Push registrationPlatform, device push tokenContent, sender name
AttachmentFile ID, size, owner, expiryFile key, content
Private storageThat a record exists, its size and change timeRecord names, content
ProfileThat it exists, size, change timeName, photo (ciphertext only)
BlockWho blocked whomReason
MuteWhich chats or people you muted—
Mini-app cataloguePublic catalogueWhich user uses which app
Deleted usernameThe username aloneAccount ID, date

L2. IP addresses are not stored in the database or in the web access log; some error logs can still contain them. Service logs exclude message content and tokens but can contain account and device IDs, so “no logs” is not claimed.

23Checks in the code

The server cannot read messages — end-to-end encryption, not a promise.

Automated checks in our development process flag server code that would cross a privacy boundary.

Server code change
Privacy-boundary checksfor example: storing message content, personal data or call keys is flagged

L2. These checks enforce the boundary in code. They are not an independent security audit.

24Deleting the account

Deletion is immediate and final — on the server.

Copies already on your contacts’ phones stay there.

Your device
Your contacts
Cryptico server
01“Account deleted” noticeend-to-end encrypted · to the chats on this device
02Delete requestsigned with the key from your 12 words — a session is not enough
03One transactionusername reserved forever · files, queued messages and keys removed · empty groups deleted, admin passed on · account and everything attached to it deleted
04Close every connection
Stays on your contacts’ devicesMessages they already received and your cached profile. Files they have not downloaded yet become unavailable.

L2. No waiting period and no restore.

25Mini-apps

A mini-app sees a stranger, not you.

Each app gets its own identity, unlinkable to your account and to other apps.

Cryptico appholds your account
account IDusernameavatarSignal keys
Sandboxisolated web view
Mini-appcan receive
its own app-specific IDits own storagean alias — only if you set one
Signed appthe developer’s signature is checked
Revocation listsigned list of blocked apps
Per-app identity“Reset identity” → a new, unlinked ID
Never given to the app
  • Your account ID
  • Your username
  • Your avatar
  • Your Signal keys
Still visible to its own backend
  • IP address
  • Request times
Anonymous reports
  • Privacy Pass tokens: the server cannot tell who reported an app

L2. Reports use VOPRF tokens (RFC 9497).

26Blocking

A blocked person is not told they are blocked.

The server gives them the same answer as a successful send.

ContextWhat happensWhat the blocked person sees
1:1 messages and callsNot deliveredThe same answer as a successful send
Shared groupDelivered without a wake-up; shown as a hidden placeholderNo block notice
Group callBlocking does not apply — both are legitimately in the roomThe call continues

L2. Blocks are temporary: the app shows when a block will end, and you can renew it.

27Threat model

Every defence has an edge.

What each attacker can try, what stops them, and what is left.

ThreatDefenceWhat remains
Server hacked / curious adminEnd-to-end encryptionMetadata: who talks to whom, when, how much
Server tries to add a fake deviceDevice endorsements checked against a remembered account keyTrust in the very first contact
Traffic interceptionTLS + end-to-end encryptionThe TLS proxy (Cloudflare) sees metadata and session tokens
Man in the middle at first contactSafety number / call codeUnprotected until compared
Future quantum computer vs recorded trafficKyber-1024 in the first key exchangeCovers session set-up only
One message key stolenDouble RatchetThat one message
Guessing the phrase or PINArgon2id; on phones, limited PIN attempts backed by the hardware key storeA PIN is a convenience barrier — in a browser it can be guessed offline from a copy of the browser’s data
Lost or stolen phoneEncrypted storage, hardware key store, app lock, remote device removalA phone with no app lock opens the app
Screen recording / shoulder surfingPhrase and PIN screens protectedOrdinary screenshots
IP exposure in callsTURN relay by defaultDirect connection when the relay fails (with a warning)
Location in photos / videosCamera photos re-encoded; video metadata neutralisedPNG, GIF and WebP are sent as they are
Malicious mini-appSandbox, per-app identity, revocationIts backend sees IP and time
Google / Apple / browser pushContent-free pushWake-up times and IP
Phrase leakedKeep it secretFull account access, including contacts’ recently re-sent messages
28What Cryptico does not hide

Know where the protection ends.

Encryption hides what you say. It does not hide that you are talking.

01 Communication metadataThe server knows who writes to whom, when, how much, from which IP, group membership and your devices.
02 CloudflareSees request metadata, IP addresses and session tokens.
03 Push servicesSee the time of every wake-up and the IP address.
04 Message sizeEnvelopes are not padded to a fixed size.
05 First contactTrusted on first use until you compare the safety number.
06 Lost phraseNo phrase, no account. There is no recovery.
07 New deviceYour own message history does not transfer.
08 AuditNo independent security audit has been performed.
09 ScreenshotsCannot be blocked in chats on any platform.
10 Call fallbackIf the relay fails, a 1:1 call goes direct and IP addresses become visible to each other.
11 Call infrastructureThe relay and the group-call server see who takes part in calls and their IP addresses — not the media.
12 Your profileAnyone who starts a chat with you can see your name and photo.
Content privacy ≠ metadata privacyThe content of conversations is protected cryptographically; the fact and time of communication are not.
29Technical reference

The cryptography behind the boundaries.

One table for the technical reader.

PurposeTechnology
MessagingSignal Protocol via libsignal on every platform
Session set-upPQXDH · Curve25519 + Kyber-1024
1:1 messagesDouble Ratchet
GroupsSender Keys · up to 128 members
Recovery phraseBIP39 · 12 words · 128 bits
Key derivationPBKDF2-HMAC-SHA512 → Argon2id (64 MiB) → HKDF-SHA256
Sign-inEd25519 signature over a single-use challenge
Device endorsementEd25519
AttachmentsAES-256-GCM · key per file · SHA-256
Local dataSQLCipher (phones) · AES-256-GCM (browser)
Private storageHMAC-SHA256 names + AES-256-GCM
App lockPIN · Argon2id + AES-256-GCM
Safety numberlibsignal fingerprint · 60 digits
1:1 callsWebRTC DTLS-SRTP · TURN relay by default · 6-digit code
Group callsLiveKit media server + end-to-end frame encryption (AES-GCM) · new key on join / leave
Mini-app reportsVOPRF (Privacy Pass, RFC 9497)

L2. The system as a whole is not claimed to be post-quantum.