Security overview
How OvateChat protects your conversations, in plain language.
For the shorter introduction, see
What is end-to-end encryption?
The design principle
OvateChat is built so that its security does not depend on
trusting us. Messages are encrypted on your device with keys that
only your devices hold; our servers relay encrypted data they cannot read
and delete it once it has been delivered. Even a full compromise of our
servers would not expose the content of your conversations — that is a
property of the architecture, not a promise in a policy.
End-to-end encryption
OvateChat uses advanced, independently-audited end-to-end
encryption of the kind the world's most trusted private
messengers rely on. What that means for you:
- Keys are made on your device and never leave it.
Each of your devices generates its own keys. Only the public halves are
shared, so that others can start a conversation with you; the private
halves stay on the device.
- A secret only the two of you share. The first time
you message someone, your devices agree on a shared secret using the
public keys they published in advance — so you can write to someone
securely even while they are offline, and the server never holds a
private key.
- A fresh key for every message. This gives
forward secrecy (a key stolen today cannot unlock
yesterday's messages) and self-healing (the
conversation re-secures itself going forward).
- Groups are encrypted for every member's device. A
group message is many individually encrypted copies, not one shared
key.
- Our servers relay only sealed envelopes. They pass
encrypted messages along and delete them once every recipient device
has fetched and acknowledged them. We keep no archive.
Everything you exchange travels this way: texts, photos,
videos, documents, voice notes, locations, stickers, reactions, edits and
deletions, and the audio and video of your calls. Media files are
additionally encrypted with a fresh random key before upload; that key
travels only inside the encrypted message.
What our servers can — and cannot — see
Honesty matters more than marketing here. End-to-end encryption
protects content; a relay server necessarily handles some
metadata to do its job.
| Our servers never see | Our servers do see |
|
Message text · photos, videos, files, voice notes · shared locations ·
stickers & reactions · edits & deletions · your private keys ·
your chat backup contents (encrypted on-device before upload)
|
Account data you provide (username, optional email/name/profile photo)
· which accounts message each other, and when · delivery/read receipt
events · friend connections and group membership · device and session
records, including login IP addresses · push tokens
|
Delivered messages are deleted. An encrypted message
exists on our servers only until every recipient device has fetched and
acknowledged it, then it is erased. We do not keep an archive of your
encrypted messages. Undelivered messages expire after a limited
period.
We collect no analytics, run no ads, use no trackers, and
never sell data. The Privacy Policy is the binding
description of data handling.
Keys, devices, and recovery
- Private keys never leave your device. They are
generated locally and stored in your device's secure storage. There is
no key escrow and no "master key" — not for us, not for anyone.
- Linked devices require consent. Signing in on a new
device needs approval from an existing device, or your recovery
phrase.
- The recovery phrase is the root of account recovery.
We store only a hash of it. If it is lost and no signed-in device
remains, the account's history is unrecoverable — by design. That
trade-off is what "we can't read your data" costs.
- Safety Numbers let you check for yourself. Open a
contact's details and tap Verify Safety Number, then
compare the number (or scan it) with your contact in person or over
another channel you trust. A match confirms that no one sits between
you.
- On-device data is encrypted at rest. Your message
history lives in an encrypted database on your device, unlocked with a
key held in secure storage; if encryption cannot be enabled, the app
refuses to store messages in the clear. An optional app lock adds face
or fingerprint unlock, or a PIN, on top.
Abuse controls without content access
Because we cannot read messages, safety tooling works on consent and
identifiers instead: verified-account gates on initiating contact,
friend-request controls, blocking in both directions, and in-app
reporting. Read receipts are reciprocal and optional.
Honest limitations
- No independent audit of OvateChat yet. The
encryption we build on has been studied and audited independently, but
OvateChat as a product has not yet had a third-party security audit.
One is on our roadmap.
- Metadata is visible to us, as described above — we
minimize and delete where possible, but a relay service cannot function
with zero metadata.
- Your device is the trust boundary. Encryption
cannot protect a conversation from someone holding an unlocked device —
use the app lock and your platform's device security.
- The people you message can always keep or share
what you send them. Encryption protects transport and servers, not
trust between humans.
Reporting security issues
Found a vulnerability? We genuinely want to hear it — email
security@ovatechat.com
with details and steps to reproduce. Please give us reasonable time to fix
before public disclosure; we'll credit researchers who report responsibly
(unless you prefer otherwise). Machine-readable contact:
/.well-known/security.txt.