1. Absolute Zero Data Collection
We do not collect, process, store, or transmit any identifying information about you or your contacts. Specifically, Entangl never asks for or logs:
- Phone numbers or SIM card identifiers (IMSI / IMEI)
- Email addresses or real names
- IP addresses (communications route over Tor hidden services or local LAN)
- Address book or phone contact lists
- Device diagnostics, crash analytics, or usage telemetry
2. Cryptographic Local Identity
Your identity in Entangl is generated exclusively inside your Android device's hardware security chip (Android Keystore / StrongBox). Your private keys never leave your phone. Your public identity key is shared strictly out-of-band when you choose to physically present your screen for a peer to scan.
3. Direct Peer-to-Peer Routing
There are no central relays or cloud mailboxes. Messages are routed directly between your device and your contact's device. Traffic is protected by two layers of encryption: post-quantum Double Ratchet encryption (ML-KEM-768 Kyber + X25519) and onion routing transport encryption.
4. Hardware-Secured Local Storage
All message records, session states, and contact identities reside in a local SQLCipher encrypted database. The encryption key is protected by the device hardware keystore. If your device is seized while locked, the database remains encrypted with AES-256.
5. 100% Free & Open Source Verification
Entangl is free software licensed under the GNU Affero General Public License v3.0 (AGPLv3). Our source code is public and fully auditable by third-party security researchers and independent privacy advocates.