The short version
Every one-to-one chat on TalkEx is end-to-end encrypted. That means the message is scrambled on your device and can only be unscrambled on your contact’s device — the servers in between only ever see ciphertext. We can route it, store it and deliver it, but we can never read it.
The handshake
When two people start chatting, their devices perform an Elliptic-Curve Diffie-Hellman (ECDH) key agreement on the P-256 curve. Each side keeps a private key that never leaves the device and shares only a public key. From those, both sides independently derive the exact same shared secret — without that secret ever crossing the network.
That shared secret becomes the key for AES-256-GCM, the same authenticated cipher trusted by banks and governments. GCM doesn’t just encrypt — it also verifies integrity, so a message that was tampered with in transit is rejected instead of shown.
What we can and can’t see
We can see that a message was sent, roughly when, and to whom, because we have to deliver it. We cannot see the text, the photo, the voice note, or the call audio. Even if someone compromised our database, they’d find only encrypted blobs.
Your part
Turn on App Lock and Two-Step Verification in Settings, and review your Linked Devices regularly. Encryption protects data in transit and at rest — device security is the last mile, and it’s in your hands.