Chat & groups · Invitations

Invite someone who isn't on Private.Ki

Two ways to bring an outsider into an encrypted chat — a link or QR code (single use, valid 1, 7 or 30 days) or an emailed invitation — and what they see.

WiA·4 min·Updated 11 Sept 2026·Verified against app release 2026.09
Screenshots for
Same steps on every device — only the pictures change. Show all

A chat needs a key at both ends, so you cannot chat with an ordinary email address. What you can do is invite the person: they get a Private.Ki account in a few seconds, without a sign-up form, and the chat with you opens the moment they arrive. There are two ways to hand over the invitation.

  • A link or QR code — when you do not have (or do not want to use) their email address. You pass the link on yourself, by whatever channel you like.
  • An emailed invitation — when you have their address. Private.Ki emails them the link for you.
  1. Click New chat and choose Invite with a link or QR code at the bottom of the dialog.
    1Invite with a link or QR codeWeb & desktop
    Invite with a link or QR code, at the bottom of the New chat dialog.1
    1Invite with a link or QR codeiPhone
    Invite with a link or QR code, at the bottom of the New chat dialog.1
    1Invite with a link or QR codeAndroid
  2. Choose how long the link should work: 1 day, 7 days or 30 days. Seven days is selected by default. Read the note above the choice — it is the one thing that matters about these links.
    17 days is the default2Create invitation link3Send it to one person, not a groupWeb & desktop
    Pick 1, 7 or 30 days. The note above explains why the link must go to one person only.123
    17 days is the default2Create invitation link3Send it to one person, not a groupiPhone
    Pick 1, 7 or 30 days. The note above explains why the link must go to one person only.123
    17 days is the default2Create invitation link3Send it to one person, not a groupAndroid
  3. Click Create invitation link.
  4. On the Link tab, click Copy link and paste it wherever you are talking to the person. On a phone, and in browsers that support it, a Share button opens the system share sheet instead.
    1Copy link2QR code tab3One person only · Expires in 7 days4Withdraw this invitationWeb & desktop
    Your invitation link. The highlighted part after #k= is the key — copy the whole thing.1234
    1Copy link2QR code tab3One person only · Expires in 7 days4Withdraw this invitationiPhone
    Your invitation link. The highlighted part after #k= is the key — copy the whole thing.1234
    1Copy link2QR code tab3One person only · Expires in 7 days4Withdraw this invitationAndroid
  5. Or switch to the QR code tab and let them point their phone camera at the screen. The page is titled Scan to chat with me.
    1QR code tab2Scan with a phone cameraWeb & desktop
    The QR code tab — point a phone camera at it to start the chat.12
    1QR code tab2Scan with a phone cameraiPhone
    The QR code tab — point a phone camera at it to start the chat.12
    1QR code tab2Scan with a phone cameraAndroid
  6. Click Done. The link keeps working until it is used, withdrawn or expires.
The whole link is the key — including the part after the #

An invitation link is a bearer token. The secret that lets the other person's device set up an encrypted conversation with you travels inside the link, after the #k=, and never touches our server. That has two consequences. First, anyone who gets the link can use it, and there is no second check — treat a forwarded link or a screenshot of it as handing over the invitation. Second, send it to one person, not a group: the link works exactly once, for whoever opens it first.

Withdrawing a link. Below the link is Withdraw this invitation. Use it if you sent the link to the wrong place. Withdrawing only stops the link being redeemed — if someone already used it, you are already talking, and leaving that chat is a separate thing. Once you press Done the link no longer appears anywhere in the app, so withdraw before you close the screen if you have doubts. You can have up to 20 live invitation links at a time.

Invite by email

Type the person's address into New chat. When the hint under the field reads Not on Private.Ki, the button becomes Send invitation. Press it and Private.Ki emails them a message titled " invited you to chat on Private.Ki" containing a link that works for 24 hours. You can send one invitation per address per day, up to 20 a day in total, and the pending ones are listed under Invitations — see Invitations: pending, cancelled, expired.

1Address you typed2Not on Private.Ki3Send invitationWeb & desktop
An address that is not on Private.Ki turns the button into Send invitation.123
1Address you typed2Not on Private.Ki3Send invitationiPhone
An address that is not on Private.Ki turns the button into Send invitation.123
1Address you typed2Not on Private.Ki3Send invitationAndroid

What the invitee sees

Whichever way the link reached them, the person opens it in a web browser and:

  1. Sees Setting up your account... with your name: "Ada invited you to a private conversation on Private.Ki. We're creating your encrypted mailbox and the keys for it here on this device — nowhere else." Their key pair is generated in their browser.
  2. Lands on a short Welcome to Private.Ki screen, then the chat with you opens — empty, encrypted, ready.
    What the other person sees: their account and keys are made in their browser, then a short welcome.Web & desktop
    What the other person sees: their account and keys are made in their browser, then a short welcome.
    What the other person sees: their account and keys are made in their browser, then a short welcome.iPhone
    What the other person sees: their account and keys are made in their browser, then a short welcome.
    What the other person sees: their account and keys are made in their browser, then a short welcome.Android
  3. Gets a Private.Ki identity without filling anything in. From a link or QR code that is a guest: Guest NNNN, with an address like guest_NNNN@… on our domain and no password. From an emailed invitation the address is derived from their own — [email protected] becomes sam@… on our domain — and their email address stays attached to the account, so they can sign back in with a code sent to it.
1Guest account2Chat with the inviterWeb & desktop
iPhone screenshotThe invitee lands in the chat with you as Guest NNNN — encrypted, no sign-up form.Same screen as on the web, single column. This capture is produced by the screenshot pipeline and will appear here.
The invitee lands in the chat with you as Guest NNNN — encrypted, no sign-up form.iPhone
Android screenshotThe invitee lands in the chat with you as Guest NNNN — encrypted, no sign-up form.Same screen as on the web, single column. This capture is produced by the screenshot pipeline and will appear here.
The invitee lands in the chat with you as Guest NNNN — encrypted, no sign-up form.Android

On your side a new conversation appears. For a link it is with Guest NNNN and opens with a system message: "Chat started by someone who opened your invitation link. Verify their identity by asking something only they would know." Do that — the link proves someone had the link, not who they are. For an emailed invitation the chat is with the address you invited.

A guest account lives on one device

Someone who arrived by link is told, above their first messages: the account exists only in that browser or on that phone, with no password and no email address. If they clear the browser or lose the phone, the chat goes with it. They can press Set a password to keep it — and until they do they cannot email people outside Private.Ki. Emailed invitees see a milder version of the same prompt: their messages are temporary until they set a password.

The invitee has to open the link in a browser, not in the installed app: phones do not pass the part after the # to apps, and without it the invitation cannot be read. If they tap the link and the app opens instead, they see Open this invitation in a browser with instructions. Once the account exists they can sign in to the app normally.

The page tells them plainly which case it is: This invitation has expired, This invitation has already been used (someone else with the link got there first — worth knowing), This invitation was withdrawn, We don't recognise this invitation or This link is incomplete (the #… part was cut off, often by an app shortening the link). In every case the fix is the same: send a fresh link, by a channel only they can read.

What our server sees

Cannot see

  • The key inside the link — the part after #k= stays in the two browsers
  • The content of the conversation that follows

Can see

  • That you created an invitation, how long it is valid for, and when it was redeemed
  • For an emailed invitation, the address you sent it to
Article chat/invite-someone-outsideReplaces: Secure Chat request with external users, Anonymous encrypted chatScreenshots regenerated automatically for release 2026.09