Security overview

How OvateChat protects your conversations, in plain language. For the shorter introduction, see What is end-to-end encryption?

The design principle

OvateChat is built so that its security does not depend on trusting us. Messages are encrypted on your device with keys that only your devices hold; our servers relay encrypted data they cannot read and delete it once it has been delivered. Even a full compromise of our servers would not expose the content of your conversations — that is a property of the architecture, not a promise in a policy.

End-to-end encryption

OvateChat uses advanced, independently-audited end-to-end encryption of the kind the world's most trusted private messengers rely on. What that means for you:

Everything you exchange travels this way: texts, photos, videos, documents, voice notes, locations, stickers, reactions, edits and deletions, and the audio and video of your calls. Media files are additionally encrypted with a fresh random key before upload; that key travels only inside the encrypted message.

What our servers can — and cannot — see

Honesty matters more than marketing here. End-to-end encryption protects content; a relay server necessarily handles some metadata to do its job.

Our servers never seeOur servers do see
Message text · photos, videos, files, voice notes · shared locations · stickers & reactions · edits & deletions · your private keys · your chat backup contents (encrypted on-device before upload) Account data you provide (username, optional email/name/profile photo) · which accounts message each other, and when · delivery/read receipt events · friend connections and group membership · device and session records, including login IP addresses · push tokens

Delivered messages are deleted. An encrypted message exists on our servers only until every recipient device has fetched and acknowledged it, then it is erased. We do not keep an archive of your encrypted messages. Undelivered messages expire after a limited period.

We collect no analytics, run no ads, use no trackers, and never sell data. The Privacy Policy is the binding description of data handling.

Keys, devices, and recovery

Abuse controls without content access

Because we cannot read messages, safety tooling works on consent and identifiers instead: verified-account gates on initiating contact, friend-request controls, blocking in both directions, and in-app reporting. Read receipts are reciprocal and optional.

Honest limitations

Reporting security issues

Found a vulnerability? We genuinely want to hear it — email security@ovatechat.com with details and steps to reproduce. Please give us reasonable time to fix before public disclosure; we'll credit researchers who report responsibly (unless you prefer otherwise). Machine-readable contact: /.well-known/security.txt.