TalkRidge Privacy Policy
Last updated: 27 July 2026 · HK Managed Services Provider Limited (hkmsp.com)
TalkRidge is engineered so that we collect as little as is technically possible — and so that even we, the operator, cannot read your communications. This is not a promise to behave; it is a property of how the app is built.
Why this design is the safest
- End-to-end encryption by default. Every message, picture, voice note, file, and call is encrypted on your device and only decrypted on your contact's device, using vetted, unmodified cryptography (X25519 and post-quantum ML-KEM-768 key agreement, HKDF-SHA-256, and XChaCha20-Poly1305 authenticated encryption) on a double ratchet that gives every message its own key. There is no "off" switch and no plaintext mode. See how we protect your data.
- Your keys never leave your phone. Your private identity keys are generated on first launch and held in the device's hardware-backed secure storage (iOS Keychain / Android Keystore). We never see them, and there is no key-escrow.
- A "blind mailbox" server. Our server is a dumb letterbox: it only accepts and hands back opaque ciphertext addressed to an anonymous mailbox id. It holds no keys and can decrypt nothing. Access to a mailbox is proven by a cryptographic signature, not a password we could lose.
- No phone number, no email, no address-book upload. By default you are not discoverable at all — contacts are added by physically scanning each other's QR code and confirming a matching security fingerprint. If you want, you can publish an opt-in username (like @you) that maps only to your public keys — never a phone number, email, or your contact list — and remove it at any time. We never scan or upload your address book.
- Messages self-destruct. A delivered message is deleted from our server the moment your device confirms receipt; anything never collected is purged automatically after 7 days.
- No trackers, no ads, no profiling. The app contains no advertising, no analytics or tracking SDKs, and no cross-app tracking. There is no IDFA and nothing to sell.
What we cannot see
The content and meaning of your messages and calls, your contact names (these live only on your phone), and who your contacts are. We could not disclose your message content to anyone — including in response to a legal demand — because we do not possess it in readable form.
The little we do store, and why
- Encrypted mailbox contents — opaque ciphertext only, deleted on delivery and after 7 days at the latest.
- A push-notification token, only if you enable alerts, so we can send a content-free "New message" / "Incoming call" / "Someone added you as a contact" banner. It names no sender and no content. Deleted when you turn alerts off or delete your account.
- An encrypted contact backup ("vault"), only if you turn on backup — sealed with a key only your phone holds, so it is unreadable to us and exists solely to restore your own contacts to a new phone.
- Abuse reports you choose to file, which contain only what you decided to include (the reported user's public key, a reason, and any text or excerpt you added). We keep these to act on abuse, and they outlive your account because they are a record about someone else.
- Ordinary, transient server logs needed to run and protect the service; they never contain message content.
Honest limits
Because delivery goes through our relay, the relay can observe unavoidable metadata such as message sizes and timing and which mailbox is being polled. We minimise and do not sell this. Each delivery also carries a one-word public hint — "call", "contact add", or "housekeeping" — so your phone can show the right banner and stay silent for housekeeping traffic such as delivery receipts. The hint names the kind of delivery only: never the sender, never the content. We recommend confirming a contact's security fingerprint, which the app shows on both phones.
Your controls
You can block or report any user in-app, turn notifications and backup on or off, and — at any time — choose Settings → "Delete my identity & data", which erases your identity from the device and wipes your mailbox, push token, and vault from our servers.
Children
TalkRidge is not directed at children under 13 and we do not knowingly collect data from them.
Contact
HK Managed Services Provider Limited — support@talkridge.com · hkmsp.com.