How Talklio keeps your chats private

Talklio encrypts every message, photo and voice note on your device with AES-256-GCM before it's sent. The key is stored in your link after the # sign, which browsers never send to servers, so Talklio can't read your chats. Passwords are hashed on your device, and everything is deleted within 24 hours.

A privacy app should be able to explain its security without hand-waving. So here's exactly what happens to your messages, what we can see, what we can't, and where the limits are.

The short version

  • Your messages, photos and voice notes are encrypted on your device before they're sent.
  • The key that unlocks them lives in your link, after the #. Browsers don't send that part to servers, so we never receive it.
  • We store only scrambled data, and we delete it 24 hours after it was sent.
  • Your password is hashed on your device. We never see it in plain text.
  • Calls are encrypted between devices using the same technology video-calling apps rely on.

Where the key lives

When the owner creates a space, their device generates a random 256-bit secret. It gets added to the link like this:

https://talklio.app/s/SPACEID#k=SECRET

The part after # is called the URL fragment. By design, web browsers keep fragments on the device and don't include them in requests to servers. That's a long-standing rule of how the web works, described in the URL standard, not a Talklio promise. So when you open a Talklio link, our servers see the space ID and nothing after it.

Once you've opened the link, your device saves the key locally, so you don't have to keep the full link to hand. It never leaves your device except when you choose to share the link.

How messages are encrypted

Each private chat inside a space gets its own key. Your device derives it from the space secret using HKDF-SHA-256, mixed with the space ID and the chat it belongs to. Messages are then encrypted with AES-256-GCM, a widely used authenticated cipher, with a fresh random value for every single message.

All of this uses the Web Crypto API that's built into every modern browser. There's no home-made cryptography in Talklio.

Photos and voice notes get the same treatment. Your device encrypts the file before uploading, and the other person's device decrypts it after downloading. Our servers handle blobs of noise.

How passwords are protected

When someone types a password, their device runs it through PBKDF2-SHA-256 with 150,000 rounds, salted with the space and their name, before anything is sent. The server then hashes that result again with SHA-256 and stores only that. So we never hold your actual password, and a stolen copy of our data wouldn't reveal it.

To stop guessing, a name gets locked after several wrong attempts, and the lock grows longer if the guessing continues. Logins are also rate-limited per network.

How calls are protected

Voice and video calls use WebRTC, the open standard behind most browser calling. WebRTC encrypts all audio and video with DTLS-SRTP. That's not optional, it's built into the standard. Where possible, the call travels straight between the two devices. If a network blocks that (common on mobile data and office Wi-Fi), the encrypted stream is relayed through Cloudflare's TURN servers, which pass it along without being able to decode it.

What Talklio can see

Being honest about this matters more than sounding impressive. To run the service, our servers handle some information that isn't encrypted:

We can see Why
Display names and chosen avatars So people can pick their name when they join
Who sent a message to whom, and when To deliver it to the right person
Rough message and file sizes Part of storing and sending encrypted data
Emoji reactions and highlight stars They're small settings attached to a message
Whether someone is online, typing or has read a message To show presence and read receipts
Your IP address, while you're connected Unavoidable on the internet. Used briefly for rate limiting and handled by Cloudflare

We cannot see the content of messages, captions, photos or voice notes, or listen to calls.

All of it is short-lived. Messages and their details go after 24 hours. Whole spaces go after 30 days. Rate-limit records expire within two hours, and we don't keep server request logs.

Notifications

Push notifications go through Apple, Google or Mozilla's delivery services. Because we can't read your messages, a notification only ever says something like "Jess: New message" or "Sent a photo". The payload itself is also encrypted for your device.

The honest limits

No app is magic, and you deserve to know where Talklio's protections stop:

  • Screenshots and photos of screens. If someone you're talking to wants to keep a message, they can screenshot it. Talklio can't stop that, and neither can any other app.
  • Your link is the key. Anyone with the full link can try to log in, so the passwords matter. Share them separately from the link.
  • A compromised device. If someone has control of your phone, they can see what you see.
  • Web delivery. Like every web app, Talklio's code is downloaded from our site each time you open it. You're trusting that the code we serve is the code we describe here. We've kept it small, with no third-party scripts inside the app.
  • Metadata. As listed above, we can see who talks to whom inside a space and when, though only for as long as the data lasts.

Reporting a security problem

If you find a vulnerability, please email safety@talklio.app. We'll reply quickly and credit you if you'd like. Our security.txt file has the same details.

Frequently asked questions

Is Talklio end-to-end encrypted?

Yes. Messages, photo captions, photos and voice notes are encrypted on the sender's device with AES-256-GCM and only decrypted on the recipient's device. The key is kept in the link fragment, which never reaches Talklio's servers.

Can Talklio staff read my chats?

No. We don't have the key, so the stored data is unreadable to us. We also delete it 24 hours after each message is sent.

Can police or anyone else get my messages from Talklio?

We can only hand over what we have. That's encrypted data we can't decrypt, plus limited metadata, and all of it is deleted within 24 hours (or 30 days for a space itself). We'd respond to valid legal requests as the law requires, but there isn't much to give.

What encryption does Talklio use?

AES-256-GCM for content, HKDF-SHA-256 to derive a separate key for each private chat, PBKDF2-SHA-256 with 150,000 iterations for passwords, and DTLS-SRTP for calls, all through the browser's built-in Web Crypto and WebRTC.

Sources

  1. URL standard url.spec.whatwg.org