Security & Privacy

How Island.chat protects your communications

Core Principles

Island.chat uses OPAQUE password authentication and client-side end-to-end encryption. During honest operation, password and decrypted private-key material remain in your browser, while the service stores ciphertext and the metadata needed to operate.

Why Web-Only Matters

Island.chat is web-only by design. There is no native app to install, no push-notification token to register with Apple or Google, and no persistent local message database on your device.

  • No app installation: No app icon, no app store install record, and no native app container on the device
  • No push infrastructure: No APNs or FCM token registration for message delivery
  • No persistent local message store: Chat data may exist temporarily in browser memory during active use, but not in a native on-device message database
✓ Used in Private/Incognito mode, this can reduce device traces compared with native messaging apps.

No Personal Details Required

We don't ask for your real name, phone number, or any personally identifying information.

How It Works:

  • Auto-generated handle: We create a random identifier for you (e.g., "brave-fox-1234")
  • Handle-only signup: Register with just a password and your generated handle
  • No phone verification: No SMS, no phone numbers
✓ No name, email address, or phone number is required to create an account.

End-to-End Encryption

During honest operation, every message you send is encrypted on your device before it leaves. The stored ciphertext can be decrypted by the conversation participants, not by the application backend.

Technical Implementation:

  • X25519 Key Exchange: Secure key agreement protocol
  • HKDF-SHA256: Derives separate v2 keys for text, media metadata, media blobs, and contact aliases
  • XChaCha20-Poly1305: Authenticated encryption with canonical context for encrypted fields
  • Per-message IDs and nonces: Each message carries explicit v2 versioning and fresh encryption parameters
✓ The backend stores encrypted message content plus delivery metadata; it does not receive message plaintext or the keys needed to verify message AEAD tags during the honest protocol flow.

What We Can See vs. What We Cannot See

Transparency is critical. Here are the main kinds of data we can see and what remains private. The complete list, with how long each is kept, is in our Privacy Policy.

We CAN See

  • Your auto-generated handle (e.g., "brave-fox-1234")
  • Who you're messaging (sender and recipient IDs, your connections and invitations)
  • When messages are sent (timestamps, delivered and read state, edit and deletion markers)
  • Encrypted file details (the size and type of files you send, not their content or names)
  • Your settings (such as message retention and activity sharing)
  • IP addresses (in server logs kept for 14 days, in rate-limit counters kept at most 24 hours, and in the encrypted record of a safety report; we also look up your IP's country to block regions where we don't offer the service)
  • Passkey details (the credential ID and public key, if you set up Face ID or Touch ID)
  • Payment records (amount, status, refunds and refund requests, and the payment processor's references — never your card number)

Not Visible During Honest Operation

  • Your password (processed by the OPAQUE client)
  • Your message content (end-to-end encrypted before upload)
  • Your decrypted private encryption key (the backend stores an encrypted envelope)
  • Message history plaintext (the backend stores ciphertext)
✓ A passive theft of stored ciphertext does not include your decrypted private key.
Note: Encryption keys are exchanged through our server. We do not currently offer out-of-band key verification (safety numbers), forward secrecy, signatures, or metadata hiding. A malicious operator, replaced site JavaScript, compromised endpoint, or fully compromised server could substitute keys, capture future plaintext, or impersonate a participant.

Safety Reports

Island.chat is private by design, but it is not a safe harbor for abuse. Island.chat cannot view ordinary end-to-end encrypted conversations. Users may report specific messages or files. When a report is submitted, selected content is sent to Island.chat for safety/legal review. Island.chat may preserve, restrict, remove, suspend, or report content and account information where required or permitted by law, including for child sexual abuse material, grooming, sextortion, trafficking, threats, malware, non-consensual intimate imagery, or other illegal use.

✓ Report submission is initiated by a user and is limited to the items selected for the report.
Report Illegal Content

OPAQUE Password Authentication

In the honest OPAQUE protocol flow, your password stays on your device. The server stores an OPAQUE registration record rather than a password hash.

How It Works:

  • Password stays local: Your password is only used on your device
  • No password hashes: The database stores OPAQUE registration records instead
  • Narrow breach protection: A database or backup leak without the OPAQUE server setup cannot test password guesses through your private-key envelope
✓ There is no password-recovery path; losing the password means losing account access.

Private Key Protection

Your private key is encrypted with a key derived from the OPAQUE export key after successful authentication.

Envelope Encryption:

  • OPAQUE export key: Produced in your browser after peer authentication and never sent to our application server
  • HKDF-SHA256: Derives a separate envelope key with a fresh random salt and fixed domain separation
  • XChaCha20-Poly1305: Authenticated encryption binds the envelope to your public key
  • Keys in app memory: Island.chat does not intentionally write decrypted keys to persistent browser storage
✓ During honest operation, your private key is decrypted in browser memory for the active session, not by the application backend.

Session-Only Storage

Island.chat does not intentionally store decrypted message or media content, decrypted private keys, drafts, decrypted caches, or pending encrypted sends in localStorage, sessionStorage, IndexedDB, Cache Storage, service workers, filesystem APIs, or a native app database. During active use, decrypted data may exist temporarily in browser memory, and browsers or devices may still retain traces through history, cache, password managers, screenshots, or operating-system behavior.

What Gets Cleared:

  • Decrypted private keys: Cleared on logout and otherwise lost when the tab or page lifecycle ends
  • Session data: Automatically expires after 30 minutes of inactivity
  • Message, media, draft, and retry state: Runtime memory only; reload or tab close loses this app-managed state
✓ Closing your browser tab is designed to clear decrypted keys and session-only chat state from app memory, but device and browser traces may still remain.

Minimal Metadata

We only store the metadata the service needs to function. Our Privacy Policy lists all of it, with retention periods.

What We Store:

  • Encrypted message content: The application backend does not receive the plaintext
  • Sender and recipient IDs: Required for message delivery
  • Timestamps and delivery state: For message ordering, delivered and read state, and edit and deletion markers
  • Encrypted file size and type: Required to store and deliver files; the content and file names stay encrypted
  • Account data: Your handle, connections, invitations, settings, and passkey credential ID if you set one up
  • Security logs: IP addresses appear in server logs outside the database, kept for 14 days, and in rate-limit counters that expire within 24 hours
  • Payment records: Amount, status, and the payment processor's references, until you delete your account. Refund requests are kept until resolved and then for 90 days, even if you delete your account while a refund is being handled

What We Don't Store:

  • IP addresses in the database, except inside the encrypted record of a safety report
  • Device fingerprints
  • Browsing history or tracking data
  • Message content in readable form
✓ We can see limited account metadata needed to operate the service, including which Island.chat handles are connected and when messages are sent. That means we can infer a pseudonymous account-level communication graph, but we cannot read message content, and we do not require real names, phone numbers, or email addresses to create an account.

Message Lifespan and Deletion

Privacy is not just about encryption. It also depends on where messages are stored and how deletion works.

Single Server-Side Conversation State:

Unlike apps that keep separate copies on each device, Island.chat is designed to avoid persistent local message storage and maintain a canonical encrypted server-side conversation state. During an active session, your browser temporarily holds decrypted messages and media in memory so the chat can function.

Conversation Deletion:

When a connection is removed, messages between both participants are removed from the active conversation and, under normal operation, permanently deleted from server-side application storage. There is no user-facing recovery period or archive. Deletion applies to both sides of the conversation, except where information has already been preserved for a user-submitted abuse report, legal hold, required safety process, or lawful request. Older encrypted copies may remain temporarily in bounded disaster-recovery backups until those backups expire.

Configurable Auto-Deletion:

You control how long your messages are stored on the server:

  • 1 hour: Messages auto-delete quickly
  • 8 hours: Messages deleted within a work day
  • 1 day: Daily cleanup
  • 7 days: Messages auto-delete after one week
  • 30 days: Monthly cleanup (default)
  • 90 days: Quarterly retention
  • 365 days: Annual deletion
  • Forever: Manual deletion only

Shared Retention:

In any conversation, the shorter retention period between you and your connection applies to both sides. For example, if you set 30 days and your connection sets 1 hour, all messages in that conversation will be deleted after 1 hour for both of you.

✓ Deleting a message removes its encrypted content at once, leaving only a marker that it was deleted; an attached file's encrypted data is queued for removal from storage. Retention expiry, conversation removal, and account deletion are designed to permanently remove the relevant live application records, subject to backup aging and safety or legal preservation exceptions.

Face ID & Touch ID (Optional)

On supported devices (iOS Safari, macOS Safari), you can enable Face ID or Touch ID to quickly fill in your handle when logging in.

How It Works:

  • WebAuthn standard: Industry-standard passkey authentication
  • Platform-managed credentials: Passkeys are protected by your device or synced credential provider
  • iCloud Keychain sync: Passkeys sync across your Apple devices (iOS 16+)
  • Password still required: Face ID fills your handle, but you still enter your password to decrypt your keys
✓ Biometric templates stay with the platform authenticator. Island.chat stores WebAuthn credential identifiers and public-key material, not biometric data.

Session Security

Sessions are designed to minimize exposure if you walk away from your device.

Session Limits:

  • 30-minute inactivity timeout: Auto-logout after idle period
  • 8-hour absolute timeout: Maximum session duration
  • Secure session cookies: HTTP-only, Secure, SameSite=Strict
  • Server-side sessions: Stored in Redis, not in browser
  • CSRF protection: Authenticated state-changing requests in our session-based API require a valid token
  • Fresh password confirmation: Account deletion and connection removal require a fresh, single-use, action-bound OPAQUE password proof
✓ Sessions are protected with HTTP-only, Secure, SameSite=Strict cookies, server-side storage, session ID regeneration, automatic timeouts, and fresh password confirmation for destructive actions. As with any web session, protecting your device and browser still matters.

Transparent & Auditable

Security through transparency. Our approach is based on well-established cryptographic protocols and open standards.

Standards We Use:

  • OPAQUE: Password-authenticated key exchange; the implementation is compatibility-pinned and tested
  • libsodium: Industry-standard cryptographic library
  • HKDF-SHA256: Domain-separated envelope and message/media/alias v2 key derivation
✓ The cryptographic design is documented and its compatibility-sensitive parameters are pinned and tested.

What We Don't Do

Sell your data

Show you ads

Track your activity

Share your data for advertising

Scan your messages

Store your password

Because we cannot scan encrypted message content, abuse and safety reviews rely on user-submitted reports, available metadata, payment records, security logs, and lawful process. If a participant chooses to report abuse, they may voluntarily provide decrypted messages or media for review.

Device Traces Warning

Island.chat is web-only by design, built to minimize data exposure and avoid storing conversation data on your device. However, certain optional features and browser behaviors may leave traces on your device:

Features That Leave Device Traces:
  • Browser Password Manager: If you allow your browser to save your handle and password, these credentials will be stored in your browser's password manager (e.g., Chrome Passwords, Safari Keychain, Firefox Passwords).
  • Face ID / Touch ID (Passkeys): If you set up Face ID or Touch ID, a passkey credential linking your handle to this site will be stored in your device's keychain and may sync to iCloud Keychain on Apple devices.
To Minimize Device Traces: Decline browser password save prompts, don't set up Face ID/Touch ID, use Private/Incognito mode, and manually enter your credentials each time.

Maximize Your Privacy

While Island.chat provides strong security, here are additional steps you can take:

Use Private/Incognito Mode: Reduces persistent browser history, cache, and credential traces
Decline Password Save Prompts: Don't let your browser remember your credentials
Skip Face ID / Touch ID: Don't set up passkeys to reduce device traces
Use a VPN: Adds an additional layer of network security
Create a Strong Password: Use a unique, long password (12+ characters recommended)
Log Out When Done: Clear session data by logging out and closing the tab

Our Threat Model

Island.chat is designed to protect against:

  • Passive access to stored message and media ciphertext
  • Database or backup leaks that do not include the OPAQUE server setup
  • Passive network observers reading message plaintext from protocol traffic
  • Persistent app-managed device storage of decrypted keys, conversations, drafts, caches, or pending sends
Important Limitations:

Island.chat cannot protect against compromised devices, keyloggers, or physical access to your unlocked device. Keep your devices secure and updated.

We do not currently offer out-of-band key verification, such as safety numbers. Because encryption keys are exchanged through our server, a malicious operator, replaced frontend JavaScript, or full server compromise could substitute keys or capture future messages. Those threats are outside the guarantee described here.

Message/media/alias v2 does not add forward secrecy, post-compromise security, signatures, metadata hiding, protection from compromised endpoints, server public-key substitution, long-term-key compromise, or participant forgery.