Security
Encrypta is designed so that only the sender and recipient can read a message. This page explains what we do, and — just as importantly — what we can't do.
End-to-end encryption
Messages are end-to-end encrypted using well-established cryptographic primitives implemented through libsodium. Encryption keys are generated and stored on users' devices and are not transmitted to our servers. Our servers store encrypted message data and cannot decrypt message contents.
Your keys, your device
Identity keys are generated on your device and stored locally. They are never uploaded to our servers.
Zero-knowledge server
Our servers can see who sent a message and when, but not what was said. Even a full database seizure reveals no content.
End-to-end encryption
Every message is encrypted on your device with the recipient's public key before it leaves. The server stores only ciphertext.
Duress protection
Set a second PIN. Entering it under coercion silently wipes your keys and local data — the phone unlocks empty.
Payments: no card data on our servers
All payments are processed by Stripe. Encrypta never receives, stores, or logs your card number, expiry, or CVV. We only know whether a payment succeeded and which account it was for.
