Under the hood

Built to be checked,
not trusted.

This page is for the people who ask "prove it." No hand-waving — here is exactly how TalkOnce protects you, and the honest boundary of what any server must handle.

Sealed from hello

Meeting someone new never leaks a thing.

Most apps are weakest at the start of a conversation. TalkOnce protects the first message as hard as the thousandth.

Invite links the server can't read

Share talkonce.app/i#code anywhere. The code lives in the link's #fragment — a part of a URL your browser never sends to any server. We literally cannot see who invited whom.

Or just scan a QR code

Meet in person, scan, and you're paired end-to-end. Nothing personal is exchanged — no number, no email, no handle.

Forward secrecy from message one

Devices publish batches of one-time pre-keys — each hybrid X25519 + ML-KEM-1024. Your very first message uses a key that's consumed and gone, so even it can't be unwound later.

Verify who you're talking to

Every conversation has a 60-digit safety number you can compare in person or by QR scan. Want it stricter? Turn on the gate that blocks sending until a contact is verified.

Radical honesty

Exactly what our servers can — and can't — see.

Every messenger's servers touch something. Most won't say what. Here is the whole truth, in plain language.

Cannot see

  • Your messages, calls, photos, and files. They're end-to-end encrypted; we hold no keys and could not decrypt them if forced.
  • Who you are. No phone number, email, or name is ever attached to your account.
  • Who sent a message. Sealed-sender envelopes hide the sender's identity even from the server that routes them.
  • Your contacts or social graph as identities. We never upload your address book, and invite codes ride in URL fragments our servers never receive.
  • Your backups. Encrypted on your device with a passphrase only you know. If you use the optional cloud copy, our servers store ciphertext we cannot open.
  • Your notifications. Push is a content-free wake-up; message previews are end-to-end encrypted and decrypted on your device — Apple and our servers see neither sender nor text.

Must handle

  • An opaque routing address — a random identifier that tells the server which device to deliver an encrypted message to. Not your name, phone, or email.
  • Encrypted envelopes in transit — ciphertext we cannot open, held only until delivered.
  • Rough timing and size of encrypted traffic — an unavoidable property of any network. Blackout mode fights this with Tor, cover traffic, and size padding.
  • A push token, only if you turn notifications on — a device identifier Apple requires for delivery, stored encrypted, never linked to who you are, never used for tracking.

We'd rather tell you the honest boundary than market a promise we can't keep. Read the full detail in our Privacy Policy.

The strongest setting

Blackout, honestly explained.

Blackout routes all traffic over Tor to hide your IP address, sends cover traffic so real messages hide in a crowd of decoys, and pads every message into fixed-size buckets so length reveals nothing. It also blocks first messages to unverified contacts.

Honest fine print: while Blackout is on, calls and instant push pause — both would expose your network address. That's the trade-off working as designed, and it's yours to flip on or off anytime.

On the record

The cryptography, exactly.

Standard, published algorithms — NIST post-quantum standards hybridized with proven classical cryptography, so breaking one layer still leaves the other standing.

Identity & signatures
Ed25519 + ML-DSA-87 (hybrid — both must verify, or the signature is rejected)
Key exchange
X25519 + ML-KEM-1024 (hybrid PQXDH)
First-message secrecy
One-time pre-keys (hybrid X25519 + ML-KEM-1024), consumed on use
Message ratchet
Post-quantum Double Ratchet with encrypted headers
Content encryption
AES-256-GCM
Sender privacy
Sealed sender — the server never sees who sent a message
Traffic analysis
Fixed-bucket size padding; Tor routing + cover traffic in Blackout
Verifiability
Crypto core & server reproducible byte-for-byte; iOS app reproducible up to Apple's re-signing

TalkOnce is preparing for independent third-party security audit, and our security documentation is honest about what we don't yet claim — metadata minimization is a direction we keep pushing, not a solved problem for any messenger.

Say it once. Trust no server with the rest.

TalkOnce is arriving on the App Store, with Android to follow. Privacy will always be free.