What we can say
Your messages, attachments, and calls are end-to-end encrypted. Vulpio’s service has no routine technical path to decrypt your content. Participants can still disclose content through reports, recordings, screenshots, or disclosed integrations.
We minimize operational metadata and we publish what remains visible.
What stays on member devices
- Ordinary room messages and replies
- Attachments, including filenames once decrypted
- Direct messages after both people accept
- Voice, video, and screen-share media above the call transport
- Device keys, room keys, and the recovery bundle you choose to keep
The server stores and routes ciphertext. It does not receive ordinary room keys, direct-message keys, attachment plaintext, message plaintext, or media plaintext.
What the service can still see
- Email-backed accounts, handles, and device records
- Which Dens and rooms you belong to
- Invites, roles, and moderation actions
- Message timing, size, and delivery state
- That a call happened, and who joined it
- IP and network metadata at the deployment edge
Email addresses are encrypted at rest so a stolen disk is not an address book. That is not zero-knowledge: the running service can read an email when it must send verification or recovery mail. Passwords are hashed with Argon2id and are not recoverable.
What we will not say
- The operator knows nothing about users
- Zero metadata
- Anonymous accounts
- No government can obtain anything
- Lost devices and a lost recovery key still yield old history
Recovery
A password reset restores the account. It does not, by itself, unlock old encrypted history. History comes back from a trusted device you still have, or from a recovery bundle protected by a recovery key you saved.
If every trusted device and the recovery key are gone, old conversations stay unreadable. The account can continue with a new identity generation after a visible reset. That is the honest failure case, not a staff override.
Reports and safety
There is no proactive scanning of message plaintext. If a member reports abuse, their client can submit a signed evidence bundle of the selected messages. The platform can inspect only that bundle and related service metadata. Community moderators handle Den membership; platform operators handle service accounts and legal obligations.
Early access
The current build is an early-access alpha. It uses a compact device-envelope protocol rather than a reviewed Messaging Layer Security deployment. First contact is trust-on-first-use: compare safety numbers when that matters to you. Do not treat this page as a completed audit.
Questions: hello@vulpio.app. Security issues: security@vulpio.app. Account and signup rules: Terms of Service.