Transparency
A privacy promise is only worth what the person making it is willing to say about their own weak points. Here are ours.
What we cannot do, even if asked#
- We cannot read your messages. They are encrypted on your device with keys we never hold. What reaches the server is bytes without meaning.
- We cannot tell who talks to whom. The server never learns the composition of a group.
- We cannot restore your data. If the key on your device is gone, the data is gone. There is no backup on our side, and there never was.
- We cannot identify you. There is no registration, no phone number, no email address, no profile.
What we can see#
- That something was delivered to a given mailbox, when, and how big it was.
- The technical envelope of a connection to the server, as any operator of any server can see it.
- Diagnostic logs, if you allowed them and once that channel starts working — the contents of which are listed on the Privacy page.
What the server stores, and for how long#
| What | How long | Note |
|---|---|---|
| A sealed parcel waiting for its addressee | Until it is collected | Deleted the moment the addressee confirms receipt |
| A parcel that nobody collected | 14 days by default | Then deleted automatically |
| A file in transit | Until collected, within a fixed storage quota | Encrypted; the server cannot open it |
| Access records of the web server | A short period | Ordinary operational records |
Where it runs#
Development, hosting and distribution are inside the European Union. The server used for the beta stands in Helsinki, Finland.
Known weak points#
These are true today. They are written here so that nobody has to discover them the hard way.
- The application is not signed with paid certificates. Windows and macOS will warn about an unknown developer. See How to install.
- There has been no independent security audit. The cryptography rests on a published standard — MLS, RFC 9420 — and on well-known libraries, but no outside party has yet reviewed how EMAPKA uses them.
- Protection of the secure area on a device is emulated in software. Where hardware protection exists, EMAPKA does not yet use it.
- On some Linux desktops the application cannot block screen capture. In that case it says so on screen rather than pretending otherwise.
- On a phone, nothing can stop a photograph of the screen. Nor can any application anywhere.
- Someone you invited is someone you trusted. No encryption protects you from a participant who chooses to pass on what they read.
Reporting a vulnerability#
If you have found a weakness, write to security@emapka.app and tell us what you found. Give us time to fix it before making it public. We will not take legal action against anyone who reports a problem in good faith and does not damage other people's data while doing so.
Page updated: