Every group is completely encrypted. Inviting anyone in takes one link.
Every group and every message in it is end‑to‑end encrypted — there is no unencrypted kind. And bringing in someone who is not on Private.Ki is easy: send them a single‑use link or show them a QR code. They open it, a key is made on their device, and they are chatting with you. No phone number, no waiting.
Encryption first. Every group message is encrypted on the sender's device to each member's own key before it leaves. No one outside the group can read it — including us. Someone added later cannot read what came before. What our server can and cannot see →
Every bubble here was encrypted five times. Nobody else can read one.
The group screen tells you exactly who holds the keys
“Encrypted for these 5 people.” The app counts the keys it encrypted to, shows spots left, and lets any member set a self‑destruct timer or rename the group.
“Older messages cannot be handed to someone new. They were locked to the people who were in the group at the time.”
From the group screen.
Only people with a key. The picker says so before you choose.
The picker offers addresses you have written to. Anyone without a Private.Ki key stays greyed out rather than failing after you pick them. To bring someone new in, send them an invitation first.
Invite anyone outside Private.Ki with a single‑use link or QR code
Bringing in someone who is not on Private.Ki yet is one step: send them a link that works once, or show them the same invitation as a QR code across the table. They open it, get a key on their device, and the encrypted chat with you begins. From then on they can be added to any group.
Open the link, get an account and a key, start talking
The invitation lands on a welcome screen. Someone already signed in is asked whether to accept it into their existing account. Either way the result is a person with a key — the thing a group needs.



Encrypted once per member. Readable by no one else.
Each message is encrypted separately to every member's own key, on the sender's device. Timers and reactions work the way they do in one‑to‑one chats; Unsend is for one‑to‑one conversations. Adding someone shares the future, not the past. Stickers work in groups too: the message carries the sticker's name inside each member's encrypted copy, never a picture. How stickers stay encrypted →
Every group is end‑to‑end encrypted, one key per member. Inviting someone outside Private.Ki takes one link.