Chats, calls, files and an AI assistant. Below is the list of what stays on the server and what never reaches it. No “military-grade encryption”, and none of the other words that mean nothing.
Direct chats, groups, channels, folders, replies, forwarding, pinned messages, and search across your whole history.
Voice and video, one to one and in groups. Works where UDP is blocked, too: there is TURN over TLS.
Photos, video, documents, video notes, and voice messages with transcription. Large files are encrypted chunk by chunk and never held whole in memory.
Answers questions, summarises what you missed, and pulls meetings and tasks out of a conversation. Off by default: for it to read your chats, you have to say yes.
A group call is not end-to-end encrypted. It runs through our media server, where the stream is decrypted so it can be fanned out to everyone on the call. One-to-one goes directly. We do not write “calls are end-to-end encrypted” without that qualification, and we will not.
Metadata is not hidden. The server knows who writes to whom, and when. If your threat model is hiding the fact of the conversation itself, you need a different tool.
The web client is weaker than the app. In a browser, security depends on the code the server hands you on every load. A guarantee against a dishonest server exists only in an app you installed once.
The full account, including the wording we are bound to keep, is in the security model and the privacy policy.