Last updated: 27 July 2026 · HK Managed Services Provider Limited (hkmsp.com)
The short version: your conversations are locked on your phone with keys we never have, so protecting your data does not depend on trusting us — the system is built so we cannot read it, even if we wanted to or were ordered to.
Every message, picture, voice note, file, and call is encrypted on your device and can only be decrypted on your contact's device. We use vetted, unmodified cryptography (X25519 key agreement, ML-KEM-768, HKDF-SHA-256, and XChaCha20-Poly1305 authenticated encryption). There is no plaintext mode and no way to switch encryption off.
Conversations run on a double ratchet: the keys move forward with every single message and are destroyed once used. Two things follow. If your phone is compromised today, yesterday's messages cannot be recovered from it (forward secrecy), and once the intruder is out, the conversation heals itself and they are locked back out (post-compromise security).
Encrypted traffic can be recorded now and attacked years later, when a quantum computer could break the elliptic-curve maths that protects most of today's internet. So every key agreement in TalkRidge is hybrid: classical X25519 and post-quantum ML-KEM-768 together, and an attacker has to break both. Unusually, this applies not only to the initial handshake but to every ratchet step for the life of the conversation.
A message on our server carries no sender: it is addressed to an anonymous mailbox and routed by an opaque session number that means nothing to us. Your phone works out who sent it, after decrypting it. Message lengths are padded to fixed size classes too, so the size of a delivery does not reveal the size of what you wrote.
Your private identity keys are generated on your phone the first time you open the app and are kept in its hardware-backed secure storage (iOS Keychain / Android Keystore). They are never uploaded, and there is no key-escrow or master key on our side. The medium-term keys that start a conversation are rotated regularly and the old ones deleted, so even your long-term identity key cannot unlock a conversation after the fact.
Encryption in transit is not much use if the phone hands everything over. Your message history and contacts are stored encrypted at rest under a key held in the device's secure hardware and pinned to that one device, so it cannot ride an iCloud or iTunes backup off the phone. You can also require Face ID, Touch ID or your passcode to open the app, which additionally keeps your conversations out of the app switcher. A further setting blocks screen recording and mirroring (on Android, screenshots too — no iOS app can prevent those, and we will not pretend otherwise).
The server only accepts and hands back opaque ciphertext addressed to an anonymous mailbox id. It holds no keys, no phone numbers, no email addresses, and no contact list — so a breach of our server would expose ciphertext, not your conversations. Access to a mailbox is proven with a cryptographic signature, not a password that could be stolen or reset.
A delivered message is wiped from the server the moment your phone confirms receipt. Anything never collected is purged automatically after 7 days.
By default you are not discoverable by anyone — you add contacts by scanning each other's QR code in person and confirming a matching security fingerprint. If you want to be reachable, you can publish an opt-in username (like @you): it maps only to your public keys, never to a phone number, email, or your address book, and you can remove it at any time, which erases it from our directory. We never scan or upload your contacts.
If you enable alerts, the banner is content-free — "New message", "Incoming call", or "Someone added you as a contact", with no sender name and no text. The actual content is only ever decrypted on your phone.
Contact backup is optional. When on, your contacts are stored on our server sealed with a key that only your phone holds — unreadable to us — and your identity key is saved to your own iCloud Keychain or Google Block Store, not to us. When off, nothing but your sealed messages ever leaves your phone.
The app contains no ads, no analytics or tracking SDKs, and no cross-app tracking. We have no advertising business and nothing to profile.
Because delivery goes through our relay, it can observe unavoidable metadata such as roughly how much traffic a mailbox receives, when, and which mailbox is being polled; we minimise this and do not sell it. Calls connect your two phones directly, which is what keeps the audio out of our hands, but it also means the other party's device can see your IP address, as on any direct call. We recommend verifying a contact's security fingerprint, which the app shows on both phones. TalkRidge has not yet been through an external security audit. And no app can protect a phone that is itself compromised — keep your device updated and screen-locked.
At any time you can choose Settings → "Delete my identity & data", which erases your identity from the device and wipes your mailbox, push token, and backup from our servers. For the full details of what little we store and why, see our Privacy Policy.
HK Managed Services Provider Limited — support@talkridge.com · hkmsp.com.