End-to-end encrypted
A message is encrypted on your phone and only becomes readable again on your recipient’s. In between, whether it travels through nearby phones or over the internet, it is nothing but a string of unreadable characters.
Droplet uses the Signal Protocol, the same principle as the major encrypted messaging apps: every message has its own key, and the key changes with every exchange. Even if a key were stolen one day, it would unlock neither earlier messages nor later ones.
Encryption relies on proven algorithms: X25519 to agree on a key, AES‑256‑GCM to encrypt, HMAC-SHA256 to advance the keys.
Groups
In a group, each member has their own sending key, shared with the other members through messages that are themselves encrypted. It moves forward with every message. When an admin removes someone from the group, the keys are renewed: the removed person cannot read what is written afterward.
An identity without a number
Your identity is a key pair created on your phone. There is no phone number, no email address and no account password to steal from a server.
To be sure you’re talking to the right person, compare your safety code with theirs, or scan their QR code: if the two match, no one has slipped in between you.
Blind relays
Phones that relay a message carry a sealed envelope. They know where it comes from and where it’s going, not what it contains. The details of what they see are in the Privacy Policy.
To also hide who is talking to whom on the internet, Droplet can go through Tor: our servers then no longer see your IP address.
Calls
Audio and video calls are end-to-end encrypted and go directly from one phone to the other whenever possible. When that’s not possible, a relay passes along the encrypted audio and video, without being able to listen in.
On your phone
- Locked chats: a chat can be hidden behind your fingerprint or your face.
- Disappearing messages: they delete themselves, on both sides, after the time you choose.
- View once: a photo or video that can only be opened once.
- Encrypted backups: protected by your password (PBKDF2, 300,000 iterations, then AES‑GCM). Without it, no one can open them, not even us.
- Keys kept safe: your identity key is stored in Android’s key vault.
What Droplet can’t protect
Being honest about security also means stating its limits:
- Someone holding your unlocked phone can read your chats that aren’t locked. Protect it with a passcode.
- The person you’re talking to can take a screenshot or photograph their screen.
- The metadata needed for delivery (who is writing to whom, and when) remains visible to relays and to our servers, unless Tor is on for the internet part.
- Public statuses and emergency signals are meant to be read by everyone in range.
- The online assistant and translation send text to third-party services. They are off by default.
Report a vulnerability
Found a security vulnerability? Write to us at contact@dropletmesh.app before making it public, with what we need to reproduce it. We respond to every report and keep you updated on the fix.