You can also reach us over Tor:5tz2mhkg25tgniifrtxpvzf6xfnpogckdt2j2ele7aqtzsr2nvjbbgyd.onion

What a subpoena gets

Transparency reports usually count how often a company handed data over. Ours starts a step earlier, with a list of everything that could be handed over at all. We designed it to be short.

The premise

Nobody can be forced to produce what was never collected

Any operator can be handed a court order, us included, and a promise to fight it is worth very little on the day the letter arrives. So Aphotic makes a different sort of claim. The things most requests are after, meaning who you are and when you were online, never get created in the messenger, so there's nothing to delete on request.

Everything below can be checked against the rest of this site and against how the app behaves.

The full inventory

Everything a seized relay contains

Everything on it falls into one of these two columns, and there is no third.

Could be handed over

  • A random IDA string of characters your phone made up. Nothing connects it to a person, a phone number or a payment.
  • Public keysThe keys other people use to encrypt messages to you. On their own they decrypt nothing.
  • Waiting messages, encryptedScrambled blocks waiting to be collected, at most 7 days old. Direct messages have no sender written on them.
  • Used-up license tokensProof that some valid license was redeemed at some point. The way they're signed makes it impossible to say which one.
  • Times on the messages still waitingA message waiting in the queue shows when it arrived and when it was sent. Both go when it is picked up, or after 7 days.
  • Encrypted group dataGroup membership as random IDs, group names as scrambled text, and for Communities a log of encrypted key changes. A Community that turns on saved history keeps its older messages as well.

Cannot be handed over

  • A name, phone number or email addressNever asked for. There is no field anywhere to put one in.
  • An IP addressTor ends the connection before it reaches our server, so the address never arrives and can't be written down.
  • The sender of a direct text messageSealed sender leaves it off the envelope. Posts in groups and communities, attachment uploads and the fallback path for contacts without a sealed-sender key do show the server your ID.
  • What anyone saidScrambled data only. The keys that open it live on your phone and nowhere else.
  • When you signed up or were last onlineThe chat database has no columns for either, and a column that doesn't exist can't be produced under oath. What times exist belong to a message or an invite link, never to a person.

The shop

The one database with money in it

The shop is the only part of Aphotic with an ordinary web address, which makes it the part most likely to get a letter. An order holds the plan, the price in euros, the amount of crypto, the transaction ID of the payment, and an internal reference to the license it created. The key itself isn't in the order. Crypto checkout never asks for a name, an email address or a postal address, so the order has none of them. The invoice is built from that same row and carries no buyer identity either.

Orders are dated, because an invoice has to be: when it was placed, when it was paid, when the key went out. Those dates describe a purchase, and they are kept as long as tax law says. Nothing in the row, and nothing on the invoice, says who made it.

The link between an order and a chat identity is not in the database, and it cannot be rebuilt from what is, because of the way license tokens are signed. Somebody with complete read access to both databases still couldn't build it.

How the blind-signature flow works →

The record

Requests received so far

None, which mostly reflects how young the service is. Zero is today's number, and this page is where it will change if it ever does.

All of our servers are our own and stand in data centres in the EU. The chat server, the payment node and this website are separate machines. The chat server also runs the license service, so a request served there reaches the relay inventory above and the shop database.

requests for user data, ever
0
identities on file that name a person
0
longest a direct message waits in the queue
7 days
Where the servers are →

Check the claims yourself

The security page explains the mechanism behind every line on this one.

This site sets no cookies and does not track you. On your device it remembers your language choice and which notices you closed, and keeps checkout data only while the tab is open. Privacy policy