Security & privacy, in plain English
What protects you today
- Your password is the key. Cinder turns it into an encryption key using PBKDF2-HMAC-SHA-256 with 600,000 rounds. That makes guessing slow and expensive.
- Everything is encrypted on the device. Your messages, keys and vault are stored encrypted with AES-256-GCM. Locking the app clears the key from memory.
- No servers. No internet. Cinder doesn't request Android's internet permission, so it can't connect to the internet at all. Your messages never touch our servers, because there aren't any.
- No screenshots, no backups. Cinder blocks screenshots and screen recording, and it's excluded from cloud backup.
- No location. Cinder refuses location access, and snaps are re-encoded so location tags are removed.
- Camera only when you ask. Cinder asks for camera permission only when you tap Snap.
- Wrong guesses slow down. Every wrong password adds a longer delay.
Installed app only
Cinder runs only as an installed app (Android and Amazon Fire now, iPhone coming). There is no web version, because browsers can't block screenshots, may wipe stored data, and load fresh code from a server on every visit.
Honest limits
- Cinder is currently a single-device demo. Both sides of a conversation live on the same phone. Messages don't yet travel between two phones, so Cinder does not yet offer end-to-end encryption between two people.
- If you forget your password, your data can't be recovered.
- Nothing protects a phone that's already been compromised by malware or unlocked by someone else.
- Cinder hasn't had an independent security audit yet.
Coming soon: true end-to-end encryption
Real two-phone messaging, with keys made only on each person's own phone and safety numbers you can compare in person. Messages will still never be stored on a server. Details will be published here when it ships.
