Nobody can read your messages. Not us. Not anyone.
That is the whole reason this company exists. Every mail between Private.Ki users, every chat and every group is encrypted on your device before it leaves. The keys are made there and stay there. We keep ciphertext.
One address. Mail and messenger. No phone number, no invitation.
Encrypted email has existed for decades. Almost nobody used it.
01It asked people to manage keys by hand. People did not.
02Encrypted messengers fixed that, then asked for your phone number and left email behind.
03We wanted both, in one app, with the keys handled on your device and the operator’s position written down.
Four rules. The product is what is left after applying them.
-
01
Encryption on your device, or it does not count.
Keys are generated on your device and never leave it. Server‑side encryption is a promise about behaviour. Device‑side encryption is a fact about mathematics. We only sell the second kind.
-
02
Say what the server sees.
Every encrypted product has a metadata column. Most hide it in a policy. We publish ours as a table: what we hold, what we cannot hold, and what a database dump would contain. The table is here →
-
03
Tell the truth about the cost.
If you lose your passphrase, nobody can recover your messages. Not support, not an engineer, not us. The app says so before your key exists, not after.
-
04
Do not oversell.
We have no independent audit yet. We say so in our own comparison table, in amber, and we will keep saying so until one is published. Standard, published cryptography is what we can point to today.
Most of our product decisions were made by saying no.
Each of these would have made the product easier to build or easier to sell. Each would also have put something readable on our side of the wire. There is nothing on our side worth taking, and we intend to keep it that way.
“Your messages are encrypted with it. We hold no copy, so only this passphrase opens them.”
Shown the moment your key is made, before you can continue.
We could make this warning smaller. We could add a “forgot passphrase” link that quietly keeps a copy on our side. Both would make sign‑up smoother and both would make the first line on this page untrue. So the warning stays large, and the link does not exist.
Nothing invented here. Published cryptography, standard parts.
- Keys
- Ed25519, generated on your device
- Message bodies
- AES‑256‑GCM
- Packaging
- OpenPGP, so the output is readable by other tools
- Sign‑in
- OPAQUE — your password never reaches the server
- Sessions
- DPoP‑bound tokens
- Clients
- One codebase for web, iOS and Android. The mobile apps are built and not yet in the stores.
A small, remote team of engineers. That is the whole org chart.
01Not funded by advertising. We do not sell data. There is nothing readable to sell.
02Something ships every day, into a product real people use for encrypted mail right now.
03No job titles, no CVs, no meetings where a written paragraph would do. How we work, in full →
Questions, corrections, or something we got wrong on this page: [email protected]
Private by construction, not by promise.
If the first line on this page ever stops being true, the product has failed. Everything else is detail.