Invite someone who isn't on Private.Ki
Two ways to bring an outsider into an encrypted chat — a link or QR code (single use, valid 1, 7 or 30 days) or an emailed invitation — and what they see.
A chat needs a key at both ends, so you cannot chat with an ordinary email address. What you can do is invite the person: they get a Private.Ki account in a few seconds, without a sign-up form, and the chat with you opens the moment they arrive. There are two ways to hand over the invitation.
- A link or QR code — when you do not have (or do not want to use) their email address. You pass the link on yourself, by whatever channel you like.
- An emailed invitation — when you have their address. Private.Ki emails them the link for you.
Invite with a link or QR code
- Click New chat and choose Invite with a link or QR code at the bottom of the dialog.
1Invite with a link or QR codeWeb & desktop
11Invite with a link or QR codeiPhone
11Invite with a link or QR codeAndroid - Choose how long the link should work: 1 day, 7 days or 30 days. Seven days is selected by default. Read the note above the choice — it is the one thing that matters about these links.
17 days is the default2Create invitation link3Send it to one person, not a groupWeb & desktop
12317 days is the default2Create invitation link3Send it to one person, not a groupiPhone
12317 days is the default2Create invitation link3Send it to one person, not a groupAndroid - Click Create invitation link.
- On the Link tab, click Copy link and paste it wherever you are talking to the person. On a phone, and in browsers that support it, a Share button opens the system share sheet instead.
1Copy link2QR code tab3One person only · Expires in 7 days4Withdraw this invitationWeb & desktop
12341Copy link2QR code tab3One person only · Expires in 7 days4Withdraw this invitationiPhone
12341Copy link2QR code tab3One person only · Expires in 7 days4Withdraw this invitationAndroid - Or switch to the QR code tab and let them point their phone camera at the screen. The page is titled Scan to chat with me.
1QR code tab2Scan with a phone cameraWeb & desktop
121QR code tab2Scan with a phone cameraiPhone
121QR code tab2Scan with a phone cameraAndroid - Click Done. The link keeps working until it is used, withdrawn or expires.
An invitation link is a bearer token. The secret that lets the other person's device set up an encrypted conversation with you travels inside the link, after the #k=, and never touches our server. That has two consequences. First, anyone who gets the link can use it, and there is no second check — treat a forwarded link or a screenshot of it as handing over the invitation. Second, send it to one person, not a group: the link works exactly once, for whoever opens it first.
Withdrawing a link. Below the link is Withdraw this invitation. Use it if you sent the link to the wrong place. Withdrawing only stops the link being redeemed — if someone already used it, you are already talking, and leaving that chat is a separate thing. Once you press Done the link no longer appears anywhere in the app, so withdraw before you close the screen if you have doubts. You can have up to 20 live invitation links at a time.
Invite by email
Type the person's address into New chat. When the hint under the field reads Not on Private.Ki, the button becomes Send invitation. Press it and Private.Ki emails them a message titled "
123
123What the invitee sees
Whichever way the link reached them, the person opens it in a web browser and:
- Sees Setting up your account... with your name: "Ada invited you to a private conversation on Private.Ki. We're creating your encrypted mailbox and the keys for it here on this device — nowhere else." Their key pair is generated in their browser.
- Lands on a short Welcome to Private.Ki screen, then the chat with you opens — empty, encrypted, ready.
What the other person sees: their account and keys are made in their browser, then a short welcome.Web & desktop 
What the other person sees: their account and keys are made in their browser, then a short welcome.iPhone 
What the other person sees: their account and keys are made in their browser, then a short welcome.Android - Gets a Private.Ki identity without filling anything in. From a link or QR code that is a guest: Guest NNNN, with an address like
guest_NNNN@…on our domain and no password. From an emailed invitation the address is derived from their own —[email protected]becomessam@…on our domain — and their email address stays attached to the account, so they can sign back in with a code sent to it.
On your side a new conversation appears. For a link it is with Guest NNNN and opens with a system message: "Chat started by someone who opened your invitation link. Verify their identity by asking something only they would know." Do that — the link proves someone had the link, not who they are. For an emailed invitation the chat is with the address you invited.
Someone who arrived by link is told, above their first messages: the account exists only in that browser or on that phone, with no password and no email address. If they clear the browser or lose the phone, the chat goes with it. They can press Set a password to keep it — and until they do they cannot email people outside Private.Ki. Emailed invitees see a milder version of the same prompt: their messages are temporary until they set a password.
The invitee has to open the link in a browser, not in the installed app: phones do not pass the part after the # to apps, and without it the invitation cannot be read. If they tap the link and the app opens instead, they see Open this invitation in a browser with instructions. Once the account exists they can sign in to the app normally.
If the link does not work for them
The page tells them plainly which case it is: This invitation has expired, This invitation has already been used (someone else with the link got there first — worth knowing), This invitation was withdrawn, We don't recognise this invitation or This link is incomplete (the #… part was cut off, often by an app shortening the link). In every case the fix is the same: send a fresh link, by a channel only they can read.
What our server sees
Cannot see
- The key inside the link — the part after
#k=stays in the two browsers - The content of the conversation that follows
Can see
- That you created an invitation, how long it is valid for, and when it was redeemed
- For an emailed invitation, the address you sent it to