Privacy
Beta notes · last updated 19 August 2026
What is always protected
- Message content is end-to-end encrypted by default. Texts, photos, files, voice messages and calls are encrypted on your device and decrypted only on your recipients' devices. The server stores and forwards ciphertext it cannot read.
- Your phone number is not shown to other users. Your account ID is a keyed hash derived from your number — people you chat with see your display name and that opaque ID, never the number itself. QR codes and NFC invites share the same opaque ID.
- No ads, no trackers, no selling of data. The apps contain no advertising or analytics SDKs. Optional crash reporting sends technical error details only.
What the server necessarily handles
Like every messaging service, delivering your messages requires the server to process some metadata:
- Which accounts talk to each other, and when messages were sent (not what they say).
- Your phone number at sign-up, to send the verification SMS. It is stored as a salted hash rather than in plain text.
- Push tokens, so your device can be woken up for notifications. Notification payloads do not contain message text.
Contact discovery
To find which of your contacts already use Weke Chat, the app sends salted hashes of the numbers in your address book — never the numbers themselves. Lookups require a signed-in account and are strictly rate-limited, and this path never writes numbers or hashes to server logs.
The honest caveat: the hashing salt is public by necessity, and the phone-number space is small, so a determined party who obtained the server database could reverse those hashes. Hashing here protects against accidental leaks and casual scraping — it does not hide from the server operator which numbers use the service. A breach would reveal that a number uses Weke Chat; it would not reveal any messages.
PIN recovery
Your recovery PIN restores your encrypted history on a new phone. The PIN wraps your encryption keys using Matrix's standard secret storage. Because a 4–6 digit PIN is short, someone holding the server's encrypted blobs could in principle brute-force it — a stronger, hardware-backed vault is on the roadmap. Choose a PIN that isn't your birth year.
Disappearing messages
When a chat has a timer, messages are removed for every participant after they're read: each device deletes its local copy and the original is deleted server-side as well. Two honest limits: a participant using a non-Weke Matrix client may not honor the timer, and nothing prevents anyone from photographing their own screen.
What we don't do
- No reading, scanning or moderating of message content — we can't; it's encrypted.
- No sharing or selling of any data to third parties.
- No shadow profiles: the service stores nothing about people who haven't signed up beyond the hashed-lookup mechanics above.
Deleting your data
Deactivating your account removes your profile, devices, and the server-side ciphertext of your messages. During the beta, contact support@wekedev.com and the deactivation is processed manually within a few days.