Security
Security and encryption
Whyvo is built so the people in a conversation are the only ones who can read it. This page says exactly which surfaces that covers, and which are public by design.
End-to-end encrypted
On these surfaces, content is encrypted on your device and can only be opened by the devices in the conversation. The server stores ciphertext.
- One-to-one chats.
- Group chats.
- Circles, including their announcements.
- Invite-only channels.
- Stories aimed at your contacts or a named list.
- Voice and video call media, one-to-one and group.
- Notification previews, so message text on your lock screen is sealed to your device.
Public by design, and not encrypted
Whyvo does not describe itself as encrypted everywhere, because two surfaces are deliberately public. Saying otherwise would tell people they are private while they are broadcasting.
- Public channels: anyone may follow one, so a key handed to every follower would protect nothing.
- Public stories: a story you choose to make public is visible to anyone who can see it.
Keys and devices
- Keys are generated and held on your devices.
- A new device is brought into your account and receives your history automatically, sealed, without a manual step.
- Backups are encrypted with a key derived on your device.
- Linked devices are listed in the app so you can see what has access.
Account protection
- Sign-up requires verifying the email address you used.
- Two-factor authentication is available.
- Chat Lock gates individual conversations behind your device authentication.
- A background lock revokes decrypted media when Whyvo is not in front of you.
What Whyvo can see
Whyvo operates the service, so it necessarily handles the data needed to deliver a message to the right account and to keep the service working — but not the contents of an encrypted conversation. The Privacy Policy sets out the detail.