How TalkRidge protects your data

Last updated: 27 July 2026 · HK Managed Services Provider Limited (hkmsp.com)

The short version: your conversations are locked on your phone with keys we never have, so protecting your data does not depend on trusting us — the system is built so we cannot read it, even if we wanted to or were ordered to.

Everything is encrypted end-to-end

Every message, picture, voice note, file, and call is encrypted on your device and can only be decrypted on your contact's device. We use vetted, unmodified cryptography (X25519 key agreement, ML-KEM-768, HKDF-SHA-256, and XChaCha20-Poly1305 authenticated encryption). There is no plaintext mode and no way to switch encryption off.

Every message gets its own key

Conversations run on a double ratchet: the keys move forward with every single message and are destroyed once used. Two things follow. If your phone is compromised today, yesterday's messages cannot be recovered from it (forward secrecy), and once the intruder is out, the conversation heals itself and they are locked back out (post-compromise security).

Built for the day quantum computers arrive

Encrypted traffic can be recorded now and attacked years later, when a quantum computer could break the elliptic-curve maths that protects most of today's internet. So every key agreement in TalkRidge is hybrid: classical X25519 and post-quantum ML-KEM-768 together, and an attacker has to break both. Unusually, this applies not only to the initial handshake but to every ratchet step for the life of the conversation.

The relay does not know who is talking to whom

A message on our server carries no sender: it is addressed to an anonymous mailbox and routed by an opaque session number that means nothing to us. Your phone works out who sent it, after decrypting it. Message lengths are padded to fixed size classes too, so the size of a delivery does not reveal the size of what you wrote.

Your keys stay on your phone

Your private identity keys are generated on your phone the first time you open the app and are kept in its hardware-backed secure storage (iOS Keychain / Android Keystore). They are never uploaded, and there is no key-escrow or master key on our side. The medium-term keys that start a conversation are rotated regularly and the old ones deleted, so even your long-term identity key cannot unlock a conversation after the fact.

Locked down on the device too

Encryption in transit is not much use if the phone hands everything over. Your message history and contacts are stored encrypted at rest under a key held in the device's secure hardware and pinned to that one device, so it cannot ride an iCloud or iTunes backup off the phone. You can also require Face ID, Touch ID or your passcode to open the app, which additionally keeps your conversations out of the app switcher. A further setting blocks screen recording and mirroring (on Android, screenshots too — no iOS app can prevent those, and we will not pretend otherwise).

Our server is a blind letterbox

The server only accepts and hands back opaque ciphertext addressed to an anonymous mailbox id. It holds no keys, no phone numbers, no email addresses, and no contact list — so a breach of our server would expose ciphertext, not your conversations. Access to a mailbox is proven with a cryptographic signature, not a password that could be stolen or reset.

Messages don't linger

A delivered message is wiped from the server the moment your phone confirms receipt. Anything never collected is purged automatically after 7 days.

You choose whether to be found

By default you are not discoverable by anyone — you add contacts by scanning each other's QR code in person and confirming a matching security fingerprint. If you want to be reachable, you can publish an opt-in username (like @you): it maps only to your public keys, never to a phone number, email, or your address book, and you can remove it at any time, which erases it from our directory. We never scan or upload your contacts.

Notifications reveal nothing

If you enable alerts, the banner is content-free — "New message", "Incoming call", or "Someone added you as a contact", with no sender name and no text. The actual content is only ever decrypted on your phone.

Backups you control

Contact backup is optional. When on, your contacts are stored on our server sealed with a key that only your phone holds — unreadable to us — and your identity key is saved to your own iCloud Keychain or Google Block Store, not to us. When off, nothing but your sealed messages ever leaves your phone.

No trackers, nothing to sell

The app contains no ads, no analytics or tracking SDKs, and no cross-app tracking. We have no advertising business and nothing to profile.

Honest limits

Because delivery goes through our relay, it can observe unavoidable metadata such as roughly how much traffic a mailbox receives, when, and which mailbox is being polled; we minimise this and do not sell it. Calls connect your two phones directly, which is what keeps the audio out of our hands, but it also means the other party's device can see your IP address, as on any direct call. We recommend verifying a contact's security fingerprint, which the app shows on both phones. TalkRidge has not yet been through an external security audit. And no app can protect a phone that is itself compromised — keep your device updated and screen-locked.

You stay in control

At any time you can choose Settings → "Delete my identity & data", which erases your identity from the device and wipes your mailbox, push token, and backup from our servers. For the full details of what little we store and why, see our Privacy Policy.

Contact

HK Managed Services Provider Limited — support@talkridge.com · hkmsp.com.