Privacy
Privacy by design
EKIP is built so that private conversation content stays private.
What we store
EKIP stores account identity (username and a blind index of your email), public device keys, and encrypted ciphertext. Conversation content is encrypted on your device before it reaches the server.
What we cannot read
Private conversation content is encrypted on your device. EKIP infrastructure is designed so it cannot decrypt private conversation content.
Private keys
Private keys remain client-side. In the browser they are wrapped with a non-extractable AES-GCM key held in IndexedDB and are never written to localStorage, sessionStorage or cookies.
No third-party trackers
EKIP does not include third-party analytics, advertising pixels or tracking scripts.