Skip to content

Limitations

What PrivaMesh does not protect you from

Every privacy tool has edges. Ours are listed here rather than left for you to discover, because a product that only publishes its strengths is asking to be taken on faith.

The short version: ciphertext on a public chain is permanent, transaction timing is visible unless you turn cover traffic on, the RPC provider sees your IP, and message history can never be restored.

Ciphertext stays on a public chain forever

Every message is written to Solana as padded ciphertext and never expires. It is unreadable without keys that were destroyed after use, but an adversary can record it today and keep it indefinitely. If a future break in the cryptography arrives, what was recorded is still there.

The fact and timing of a transaction are public

Stealth addresses hide who a message is for, and padding hides how long it was. Neither hides that a transaction happened at a particular moment. With cover traffic off, your activity pattern is visible to anyone reading the chain.

Padding reveals a bucket, not nothing

Plaintext is padded to 32, 64, 128, 256 or 512 bytes. An observer learns which bucket a message fell into - so a one-word reply and a 500-byte message are still distinguishable from each other, just not from anything else in the same bucket.

Cover traffic is off by default

The decoy mode that hides timing spends from your message allowance, so it ships disabled. Until you turn it on, timing correlation is available to anyone watching the chain. That is a deliberate trade rather than an oversight, but it means the default configuration is weaker than the maximum one.

The RPC endpoint sees your IP

Submitting a transaction means talking to an RPC provider, which sees your address and the timing of your requests. It is swappable and self-hostable, but out of the box you are trusting a third party with network-level metadata. Pair it with a VPN or Tor if that matters to you.

Delivery depends on Solana, the RPC and our fee worker

If any of the three is down or blocked in your country, sending stops. Your identity, contacts and history are unaffected because they live on your device, but PrivaMesh is not censorship-proof in the sense of always getting through.

Message history cannot be recovered

Forward secrecy destroys each message key after use, and ratchet state never leaves the device. Your recovery phrase restores your identity and contacts on a new device, never your conversations. Reinstalling the app on the same phone has the same effect.

No way to verify you added the right person

Prekey bundles are signed, so a registry cannot substitute a key for an account. Nothing in the app checks the step before that: whether the account is the person you intended. There is no safety number, no fingerprint comparison and no out-of-band verification flow. If an attacker persuades you to add their account, the cryptography works perfectly and protects the wrong conversation.

If you publish a handle, the chain shows who you start conversations with

The discovery registry ties your handle to your public key, and the first message of a conversation carries that same key in the clear - it has to, because that is how the other side derives the shared secret. It is also sent to the recipient’s ordinary address, because no shared address exists yet. So anyone reading the chain can match the two and see that you began a conversation with a particular person, and when. Not what was said: the content stays encrypted, and later messages move to one-time addresses. If you never publish a handle, the same opening message names nobody. Reported externally in August 2026; fixing it properly means changing the message format, which older installs could not read.

A stolen phrase opens every message sent before the first reply

Your identity key, signed prekey and post-quantum prekey are all derived from the recovery phrase, and no one-time prekeys are published. The envelope that opens a conversation stays on the public chain forever and carries the sender’s ephemeral public key, so anyone holding your phrase can recompute the X3DH root. It does not stop at that one message: until the sender processes a reply from you, every message they send continues the same chain, one step apart, and the same secret also locates those messages on the chain. Someone who wrote three times while you were offline exposed all three. Once you reply and they receive it, a random device-local key enters the ratchet and the phrase stops being enough. ML-KEM-768 does not change this, because its seed is derived from the phrase too. Reported externally in August 2026; we previously described this as the opening message only.

Losing the recovery phrase loses the account

There is no reset, no support override and no backup we hold. Twelve words are the account. That is the direct cost of there being no account database.

Three platforms, two of them barely tested

The iPhone app requires iOS 26.5 or later: post-quantum X-Wing needs iOS 26, and rather than quietly fall back to the classical handshake the app does not run on older systems at all. It is the only platform with real use behind it. The Windows installer carries no code-signing certificate, so every download raises a publisher warning. The Android APK is version 0.1, checked on an emulator rather than a real device, and no Android or Windows build has yet sent a message on mainnet. Paid tiers work on iPhone only. There is no web client.

Features a mainstream messenger has and this does not

No group chats, no file or media transfer, no voice or video calls, no multi-device sync, no message search across devices. PrivaMesh is a focused one-to-one text messenger.

Anonymity is not guaranteed

PrivaMesh removes the identifiers it controls. It cannot stop you from revealing who you are in a message, reusing a handle from another context, or being identified by your network provider. Anonymity is a practice the architecture supports, not a switch it flips.

Why this page exists

Absolute claims are easy to write and impossible to verify, and in a privacy product they cost more trust than they buy. Anyone technical enough to matter will find the gaps, and finding them unlisted is worse than reading them here.

If something on this page is wrong or out of date, that is a bug - tell us at the security page. For the component-by-component view of who can observe what, see the architecture page.

Frequently asked questions

Can my messages be decrypted in the future?

The ciphertext is on a public chain permanently, so it can be recorded and kept. Forward secrecy destroys each message key after use, and on iOS 26 the handshake mixes in ML-KEM-768 against future quantum attacks. Neither makes recorded ciphertext disappear.

Why is cover traffic disabled by default?

Decoy transactions spend from your message allowance, so leaving it on would quietly cost you messages. It is a setting rather than a default, which means the shipped configuration is weaker on timing than the strongest one available.

If someone steals my recovery phrase, can they read my old messages?

Everything sent before your first reply reached the sender, yes. Those envelopes are on the public chain permanently, every key needed to open them is derived from the phrase because no one-time prekeys are published, and the messages after the opener continue the same chain. From your first processed reply onward the conversation is protected by ratchet keys that were random and never left the device.

Is PrivaMesh anonymous?

It removes the identifiers we would otherwise hold - no phone number, no email, no account. It does not hide your IP from your network provider, and it cannot stop you identifying yourself in a conversation.

Keep reading