Messages are encrypted on YOUR device with X25519 + AES-256-GCM. The server stores and delivers only ciphertext — it cannot read a single word.
Register your identity first, then send an encrypted message to another registered user (e.g. david).
The ciphertext stored on the server is base64 of the AES-GCM blob. The plaintext never exists server-side — it is created in your browser, encrypted, and only the recipient (who has the shared secret) can decrypt it. You can inspect the raw stored message at /secure-api/api/secure/inbox/<user> — it will be unreadable.
🏴 Darren Houston Limited · S·OS · 🏳️🌈 Everyone welcome · Love is love · No one left behind