One-to-one text messages in the PIING app are end-to-end encrypted when both people use a current version of the app. A post-quantum handshake (ML-KEM-1024 combined with X25519) sets up each chat, and the Double Ratchet gives every message a fresh key, so only the two phones can read those messages. Messages with a lock icon are end-to-end encrypted. Our servers store only scrambled text for them, and notifications for them never contain the message. You can verify any chat with its safety code, in person or by scanning a QR code.
Not end-to-end encrypted yet: photos, videos and voice messages, group chats, Stories, the web chat, and messages to someone on an older version of the app. These are encrypted in transit (HTTPS/TLS), so PIING's servers can technically access them.
Passwords are stored only as a strong one-way hash (PBKDF2), never in a readable form.
One-to-one calls are encrypted between the two phones with WebRTC (DTLS-SRTP), and relay servers can't decrypt them. The keys for a call are agreed through PIING's servers and are not yet checked against your safety code. Group calls are encrypted in transit and relayed by our calling provider, so they are not end-to-end encrypted.
Nearby messages sent over Bluetooth are sealed so the phones relaying them can't read them.
We do not collect behavioral data for advertising. There are no ad trackers and no analytics pixels in the app, and we never sell your data. We use a small number of service providers to run PIING (listed in the privacy policy), and AI services from other companies only if you allow it.
Email support@piingapp.co.uk. Please don't share details publicly until we've had a chance to fix it.