EncryptaEncrypta

Security

Encrypta is designed so that only the sender and recipient can read a message. This page explains what we do, and — just as importantly — what we can't do.

End-to-end encryption

Messages are end-to-end encrypted using well-established cryptographic primitives implemented through libsodium. Encryption keys are generated and stored on users' devices and are not transmitted to our servers. Our servers store encrypted message data and cannot decrypt message contents.

Your keys, your device

Identity keys are generated on your device and stored locally. They are never uploaded to our servers.

Zero-knowledge server

Our servers can see who sent a message and when, but not what was said. Even a full database seizure reveals no content.

End-to-end encryption

Every message is encrypted on your device with the recipient's public key before it leaves. The server stores only ciphertext.

Duress protection

Set a second PIN. Entering it under coercion silently wipes your keys and local data — the phone unlocks empty.

Payments: no card data on our servers

All payments are processed by Stripe. Encrypta never receives, stores, or logs your card number, expiry, or CVV. We only know whether a payment succeeded and which account it was for.