No account. No phone number. No traces. ZKRYPT uses military-grade encryption so only you and your contact can read your messages — ever.
Every design decision was made to protect you — not collect you.
Messages are encrypted on your device before they leave. The server only ever sees ciphertext — unreadable gibberish without your private key.
Drag your finger to generate a unique cryptographic identity. No name, no email, no phone number — completely anonymous by design.
All messages vanish from our servers after 12 hours. You can also delete any message instantly with a single tap — permanently.
Your private key never leaves your device. We mathematically cannot read your messages. Not now, not ever, not even if compelled.
Share your 8-character ZKRYPT ID via QR code or text. Your real identity stays completely separate from your encrypted conversations.
Zero analytics SDKs. Zero advertising IDs. Zero data brokers. ZKRYPT earns nothing from your data because it has no access to it.
Drag your finger across the entropy canvas. A unique X25519 key pair is generated from your random movement.
Choose a 4-digit PIN to lock the app. Your keys stay on-device, protected by your PIN at all times.
Show your contact your 8-character ZKRYPT ID or QR code. They add you — no servers involved in this step.
Send encrypted messages. ECDH key exchange happens automatically. Nobody else can ever decrypt your conversation.
The same algorithms trusted by governments, banks, and security researchers worldwide.
Elliptic-curve Diffie-Hellman key exchange — fast, secure, and resistant to quantum pre-image attacks.
Cryptographic key derivation function used to derive the symmetric encryption key from the shared secret.
256-bit authenticated encryption. Every message uses a unique nonce — no two ciphertexts are ever alike.
All crypto operations run inside the browser's native WebCrypto sandbox — keys never touch JavaScript memory as plain text.