Skip to content
Products
Encrypted Email Messenger Group Chat For teams
Security
How encryption works What our servers can and cannot see Account security Private.Ki over Tor Private.Ki and VPNs
Company
Pricing About Careers Statement Help center Contact
Language
EnglishEN DeutschDE · soon EspañolES · soon FrançaisFR · soon
Create a free account Sign in

Encrypted email and chat. We cannot
read it.

One address for encrypted mail and messaging. Nobody can read your messages — not us, not anyone. Your keys are generated on your device and never leave it, so there is nothing on our side to hand over.

Free. No phone number. No invitation needed.

Private.Ki inbox with an encrypted thread open Encrypted chat with reactions, a self-destruct timer and an unsent message Encrypted group chat with five named members
100%
of chats, groups and mail between Private.Ki users encrypted end to end. No exceptions.
0
people who can read your messages. Not us, not our hosting provider, not anyone.
0
passwords we ever receive. Yours never leaves your device.
7
self‑destruct timers, from 30 seconds to a month. Gone on both sides.
3
platforms — web, iOS and Android. One encrypted account, the same keys.
The number one reason

Nobody can read your messages. Not us. Not anyone.

Every mail, every chat and every group is encrypted before it leaves your device. The only people who can open a message are the ones it was written to.

Every mail, encrypted on your device Mail between Private.Ki users is encrypted before it leaves you and decrypted only on the recipient's device. Mail to outside providers is encrypted too when they have a key — and clearly flagged when they do not.
Every chat and every group, the same way There is no unencrypted group and no unencrypted chat. Each message in a group is encrypted to every member's own key. Reactions, voice notes and attachments travel the same way.
Our server stores what it cannot open We hold ciphertext and the keys to none of it. Your private key and your passphrase never reach us — so there is nothing we could read, hand over or lose. What our server can and cannot see →
Encrypted email

Every message tells you whether to trust it

Not a padlock in the corner of the browser. A per‑message verdict on the message itself: was it encrypted to your key, and was the signature actually valid.

Everything about Encrypted Email →

An open message showing the encryption padlock and verified-signature shield
Detail — 3×
1Encrypted to your keyThe green padlock means this body was decrypted on your device. Our server stored ciphertext it could not open.
2Signature verifiedThe shield appears only when the signature checks out against the sender's public key. A bad signature turns red rather than disappearing.
3Replies inherit the protectionEncrypt and Sign stay on when you reply, so a secure thread cannot quietly turn into an insecure one halfway down.
Composer

Encrypt and Sign are switches, not settings buried three menus deep

Both are on by default and visible while you type. When a recipient has no key, the padlock next to their address goes grey before you press send — not after.

“Encrypt ⓘ   Sign ⓘ”

The entire encryption interface, sitting under the message body.
The composer with Encrypt and Sign switched on
Detail — 3.4×
Messenger

A messenger that behaves like one — and forgets on schedule

Reactions, emoji, delivery ticks, typing. And two things ordinary messengers do not give you: a timer that deletes on both sides, and an Unsend that actually removes the message from the other person's device.

Everything about the Messenger →

Encrypted chat showing reactions, a self-destruct banner, an unsent message and a countdown
Detail — 2.4×
1Self‑destruct, announcedWhen someone sets a timer, the chat says who set it and to what. Either side can change it; the change is announced too.
2Reactions, encryptedHover a message and pick from six. The reaction travels inside an encrypted message like any other — our server sees a payload, not a 😂.
3Unsent, on both devicesWithin an hour of sending you can take a message back. The other person sees “Unsent” where it was — not the text.
4Counting downEach message shows how long it has left. When the countdown ends, it is gone from both devices, not hidden on one.
Stickers, from both sidesFour stickers and two lines of text between two accounts. No bubble around a sticker; the time sits underneath.

Stickers, sent as a name — never as a picture

Seven Ki Friends. Four packs ship inside the app, 160 stickers, one pack animated. Sending one puts three short tokens inside the encrypted message: pack, number, version. No image is uploaded or stored; the other device draws the sticker from its own copy.

How stickers stay encrypted →

After you press send

Three ways to take something back

Set a timer for the whole conversation, unsend your own message, or destroy one that was sent to you. All three are encrypted instructions to the other device — none of them are something we do for you on a server.

Self‑destruct timerAfter read, or after sent. Off, 30 seconds and up to a month. Either of you can change it, and the change is announced in the chat.
UnsendRight‑click your own message within the hour. The six reactions live in the same menu.
No ambiguity“It will be removed for both of you and replaced by ‘Unsent’. This cannot be undone.”
DestroyThe same menu on a message sent to you offers Destroy instead — it removes the message from both devices.
Emoji, searchableA full picker with categories, search and your frequently used set. Emoji are text; they are encrypted with the rest of the message.
Group chat

Every group is end‑to‑end encrypted. No exceptions.

All groups are encrypted, always — there is no unencrypted kind. Every member has their own name and colour on every message, and each copy is encrypted to that member's own key. Nobody outside the group can read it, including us. Someone not on Private.Ki yet joins with a single‑use link or QR code.

Everything about Group Chat →

A five-person encrypted group conversation
Detail — 2.6×
1Every member, namedThe header lists all recipients. There is no hidden participant, because there is no server‑side member list that could disagree with this one.
2Named, coloured sendersFive people, each with a name and colour on every message. Every bubble here was encrypted five separate times, once to each member's key.
3Size and lock, up frontThe conversation list shows the member count and a lock per row, so encryption state is visible before you open anything.

“A group can only hold people who already use Private.Ki, because each copy is encrypted to their own key. Addresses without one stay greyed out rather than failing after you pick them.”

What the app tells you when you build a group.
Group settings

The group screen tells you exactly who holds the keys

“Encrypted for these 5 people.” The app counts the keys it encrypted to. Add someone and they see messages from then on, never before, because older messages were locked to the people who were there at the time.

“Older messages cannot be handed to someone new. They were locked to the people who were in the group at the time.”

From the group screen — a cryptographic constraint, in one sentence.
Group info: members, spots left, self-destruct and rename settings
Bringing people in

Invite anyone. Encrypt for those who have a key.

Someone not on Private.Ki yet gets a single‑use link or a QR code to scan. Once they have an account and a key, they can be added to a group — and the picker greys out anyone who cannot be encrypted for, before you pick them.

How groups and invites work →

Group member picker explaining that only people with a key can be added
An invitation shown as a QR code: works for one person, expires in 7 days, with a Withdraw button
Detail — 3×
1Link or QR, same invitationTwo tabs, one invitation. Show the code across the table or send the link; either way it opens a chat with you.
2One person, then it is spent“Works for one person · expires in 7 days.” A second use is refused, and the app says so.
3The link is the keyThe part after the # is the secret. Forwarding the link, or a screenshot of it, hands over the invitation — the app tells you before you copy it.
4WithdrawStops the link from being used. A chat that has already started is unaffected — leaving it is a separate step.
The same invitation as a linkCopy it, or send it from the app. It is generated on your device and works once.
Choose how long it livesBefore it is created, you pick how long the invitation stays valid.
What the guest seesThe invitation opens on a welcome screen. Once they have an account and a key, the chat with you starts.
Everything in the box

One account. All of this.

Hover or tap anything to see what it does.

Stickers, encrypted
Sign‑in and devices

Your password never reaches us. Your second factor is yours to choose.

Sign‑in uses OPAQUE, so the password itself is never transmitted. On top of that: a time‑based code from any authenticator app, a PIN or biometrics on iOS and Android, and QR pairing to bring a new device in from one that is already unlocked.

Security settingsTwo‑factor, password and unlock method on one screen.
TOTP two‑factorScan once with any authenticator app, or copy the secret. The code is asked for at every sign‑in.
QR device pairingA new device is signed in by scanning a code shown on one that is already unlocked.
Unlock methodPassphrase, or your password if you chose that at signup. On iOS and Android, a PIN or fingerprint / face recognition. Locking is immediate, from the account menu.
The lock screenNothing is shown until the passphrase is entered. A wrong one says so and stays locked; there is no “forgot it” button, because we cannot know it.

Two‑factor and devices, in detail →

Adding a phone

Pairing shows the same code on both screens. You compare, then approve.

The phone scans a QR code from your signed‑in desktop. Both devices then display a short code. Only if the two match do you press approve — and the app is blunt about what approving means.

Desktop dialog: a phone is asking to sign in, showing the code 5WTKX1 with Deny and Approve buttons
Detail — 2.6×
1One code, two screensThe desktop shows the code the phone should be showing. If the phone shows anything else, someone else scanned your QR — deny.
2Said plainly“Approving hands over your mailbox. The phone will be able to read your entire mail history.” The dialog says it before you decide.
3Timed, and deniableThe request counts down and expires on its own. Deny is one click; approve is labelled “Codes match — approve”, so it cannot be pressed by reflex.
Phone showing the pairing code 5WTKX1 and waiting for approval
On the phone“Check this code.” It waits for the desktop to approve.
Phone unlocked after pairing, showing the inbox
ApprovedThe phone is signed in and shows the same inbox, decrypted with the same key.
Phone showing a single-use QR sign-in code with a 26-second countdown
QR sign‑inFrom the sign‑in screen, a device shows a single‑use code and a signed‑in device scans it. It expires in seconds.
Mail, day to day

The ordinary parts of email, still encrypted

Undo send with a window you choose. Signatures with a default. Attachments up to 25 MB, encrypted like the message. Archive and Trash that search respects. On phones, swipe to act.

A full inbox with unread counts, starred and archived mail
Undo sendOutgoing mail is held for 5, 10, 20 or 30 seconds — your choice — so you can cancel it. Or switch the delay off.
SignaturesSeveral signatures, one default. Attached below the body, encrypted with it.
📎Attachments to 25 MBFiles are encrypted on your device before upload and stored as ciphertext, like the message.
Archive, Trash, swipeStandard folders; Trash joins a search only when you say so. On phones, swipe a row to act on it.
Undo send“Message sent” with an Undo button, for as long as your window lasts. Press it and the mail comes back as a draft.
SignaturesA list in Settings, one marked as default. Edit, add, or pick a different default.
Attachments in the composerThree files listed with their sizes, under a body that ends “the files too”. Encrypt and Sign stay on.
ArchiveIts own folder in the sidebar, next to Inbox, Sent, Drafts and Trash.
Phone inbox with a row swiped to reveal Archive
Swipe to archiveSwipe a row one way and it goes to Archive without opening.
Phone inbox with a row swiped to reveal Trash
Swipe to trashThe other way sends it to Trash. Restoring is a right‑click on the desktop.
Phone search results across folders
Search on the phoneSame search as on the desktop: senders, subjects and addresses, on the device.

Everything about Encrypted Email →

Voice messages

Record, listen back, send. It travels as an encrypted attachment.

Hold the microphone in a chat and talk. Before sending you can play it back or throw it away. What leaves your device is ciphertext, the same as a file; the other side gets a waveform they can play.

RecordingThe composer turns into a recording bar while you hold.
Listen back firstRelease, and the note waits: play it, delete it, or send it.
Playing, on the other sideA play button and a duration inside the bubble; the audio was decrypted on this device.
Phone chat while holding the microphone to record a voice message
Hold to recordKeep your thumb down and talk; let go to stop.
Phone chat with recording locked for hands-free voice message
Locked recordingFor a longer note, lock the recording and put the phone down.
On the phone

Long‑press a message. Everything is one thumb away.

The same controls as on the desktop, arranged for a hand: the reactions and Unsend on a long‑press, the self‑destruct picker from the chat header, a full emoji keyboard from the composer.

Phone: long-press menu on a message with a strip of six reactions and Unsend
Long‑press menuSix reactions along the top, then the actions — including Unsend, on your own messages, within the hour.
Phone: quick reaction strip above a message
Quick reactionsTap one and it is sent, encrypted, like a message. The other side sees it under the bubble.
Phone: self-destruct picker with Off, 30 s, 1 min, 10 min, 1 h, 1 day, 1 week, 1 month
Self‑destruct pickerOff, 30 s, 1 min, 10 min, 1 h, 1 day, 1 week, 1 month — counted after read or after sent.
Phone: emoji picker open above the chat composer
Emoji pickerCategories, search and your frequently used set. Emoji are text and are encrypted with the message.
Phone: an encrypted one-to-one chat
A chatDelivery ticks and reactions, the same as on the desktop.
Phone: an encrypted group chat with named, coloured senders
A groupNamed, coloured senders. Every copy encrypted to its reader.
Phone: the chat list with locks and member counts
The chat listA lock on every row, as on the desktop.
Phone: account menu with Settings and Lock
Account menuThe same account menu as on the desktop, including Lock.

Everything about the Messenger →

Settings and keys

The account pages are short, because there is little to configure

A setup checklist that tells you what is still off. Your public key, ready to export. Other people's keys, importable. A recovery address for account notices — stored as a hash, so we could not read it back if we wanted to.

Setup checklistTwo‑factor, recovery address, and what is still to do — with a button next to each.
Key managementYour public key, exportable in one click. Below it, the external keys you have imported.
Recovery addressYou enter it once; a verification mail goes out; we keep only the hash. It cannot recover a passphrase.
Import an external keyPaste someone's armoured public key. From then on, mail you send them is encrypted — even if they are on another provider.
Recipient autocompleteThe addresses you have written to, kept on your device and suggested as you type. Remove any of them here.
The honest part

If you lose your passphrase, we cannot help you

Your private key is encrypted with a key derived from your passphrase, on your device. We never receive either one. That is the whole point, and it has a cost we would rather tell you now than later.

“Have you saved your passphrase? Without it your account and all messages are unrecoverable.”

Shown during signup, before a single key exists.
Signup warning: without the passphrase the account is unrecoverable
Transparency

What our server can and cannot see

Every encrypted product should be able to publish this table. Here is ours — both columns.

What it cannot read

Never transmitted, ciphertext only, or hash only
  • Message bodies, subjects of internal mail, attachments, reactions and drafts — encrypted on your device
  • Who you correspond with — conversations are keyed by an HMAC under your own key, and no column links two accounts
  • Group rosters — one encrypted, signed copy per member, no shared value
  • Your passphrase, private key, and password — OPAQUE means the password is never sent
  • Your recovery address — stored as a salted hash; in memory only long enough to send the verification code
  • Your IP address or when you were connected — we keep no access or connection logs; the only trace is a keyed rate-limit hash that expires within an hour

What it can see

For delivery, in passing — or stored because the service needs it
  • Recipient addresses while a message is delivered — read once, one encrypted copy written per recipient, not stored on any row
  • Stored: username, display name, public key, message sizes and timestamps, read flags, push tokens
  • Headers of mail that crosses the open internet, on arrival — then encrypted to your key

Delivery needs an address; a service needs a few facts about an account. Everything else is ciphertext, a hash, or gone once the request is done. Read the full matrix →

Compared

Where we stand — including where we're not there yet

What you get here that you do not get elsewhere — and where others are ahead. Plain questions first; the technical version is one click below.

In plain words

  • In your favour
  • Partly
  • Not in your favour
  • Not offered or not published
The questionPrivate.KiProton MailTutaGmail
Can the company read your mail?Between users of the same service1NoNoNoYes
Can it read your chats and group chats?NoSeparate appNo chatYes
Does your password ever reach their server?NoNoA hash of it doesYes
Can you take a message back from the other person's device?After it has been deliveredYes, within 1 hourOnly before it leavesNoOnly before it leaves
Do messages delete themselves on both sides?A timer you set, 30 seconds to a monthYesExpiry only2NoConfidential mode, not end‑to‑end
Do you need a phone number?NoNoNoUsually
Encrypted group chat in the same app?YesSeparate appNoNot end‑to‑end
Can you take your encryption keys to another app?Standard OpenPGP keys, exportableYesYesOwn formatNo keys
Is message metadata stored encrypted?Who wrote to whom, and the subject line3YesSubjects in clearSubjects yes, addresses noNo
Does the company keep logs of your IP address?No logs4On legal requestOn court orderYes
Show the technical versionHide the technical versionFor professionals: protocols, ciphers and key types, with a one‑line explanation of every term.
PropertyPrivate.KiProton MailTutaGmail
End‑to‑end schemeOpenPGPOpenPGP + Proton's ownTuta's own (AES + RSA/Kyber)TLS only
Password protocolOPAQUESRPClient‑side Argon2 hash, sent to the serverPassword sent over TLS
Session tokensDPoP‑bound JWT5BearerBearerBearer
Where keys are generatedOn your deviceOn your deviceOn your devicen/a
Key typeEd25519ECC or RSARSA + Kyber hybridn/a
Message body cipherAES‑256‑GCM, fresh key per messageAES‑256 via OpenPGPAES‑256Encrypted at rest with Google's keys
Subject line encryptedYesNoYesNo
Metadata handlingSender line, subject and correspondent history encrypted; routing timestamps in clearSubject and addresses in clearSubject encrypted; addresses in clearAll in clear
Group encryption modelOne encrypted copy per memberNot end‑to‑end
Unsend window1 hour, removed from both devicesUndo before delivery onlyNoneUndo before delivery only (≤ 30 s)
Self‑destruct options30 s to 1 month; after read or after sent; both sidesExpiring messages2NoneConfidential mode, enforced by Google's server
Two‑factorTOTPTOTP + security keysTOTP + U2FTOTP + keys + prompts
Adding a deviceQR pairing, code lives ≤ 2 minutesStandard sign‑inStandard sign‑inStandard sign‑in
Independent auditNone yetPublished6Compliance certifications
Open source6ClientsClientsNo

Hover or tap a dotted term for a one‑line explanation.

  1. Within the same service. Mail exchanged with an outside provider is only as private as that provider makes it.
  2. Proton offers an expiry date on Proton‑to‑Proton and password‑protected mail; there is no timer that runs on the recipient's device.
  3. Private.Ki encrypts the sender line, the subject and your correspondent history under your own key; message sizes and routing timestamps remain in clear. Details on the server page.
  4. No web‑server access or connection log is written; the only trace of an IP address is a keyed rate‑limit hash that expires within an hour.
  5. A DPoP‑bound token only works from the device that holds the matching key. A bearer token works from any device that has a copy of it.
  6. Not published, or no claim made.
  7. Competitor entries reflect what each provider publicly documents in its help pages, privacy policy and transparency reports, as of September 2026. Cells marked — are not offered by the provider or not published by it.
iOS and Android

Same guarantees, same badges, either theme

One codebase across web, iOS and Android. The app follows your system theme — these are the same build twice.

Private.Ki on a phone, light theme
Private.Ki on a phone, dark theme
Phone inbox with unread counts and per-message locks
InboxUnread counts and a lock per message.
Phone navigation drawer with Inbox, Sent, Drafts, Archive and Trash
FoldersInbox, Sent, Drafts, Archive, Trash — in a drawer.
Phone chat list
ChatsOne tap from mail to messenger and back.

“Your messages are encrypted with it. We hold no copy, so only this passphrase opens them.”

What the app tells you the moment your key is made.