Private sealed chats
Privacy products often say “encrypted” while still holding keys that let the service operate a cloud inbox. Buzzio’s sealed surfaces aim higher: content keys stay on participant devices.
What is sealed
| Surface | Content vs Buzzio |
|---|---|
| 1-to-1 chat | End-to-end encrypted — staff cannot read bodies |
| Whisper private chat | Session keys on devices |
| E2E groups | Sender-key E2EE — no readable operator transcript |
| Private calls | No server call recording archive |
Shared Feature mode (Communities, Broadcast, open-history groups, Whisper Questions) stores more by design — see Honest.
How sealed delivery works (plain language)
- Your phone encrypts the message before upload.
- Servers briefly relay a locked package.
- Preferred 1-to-1 path uses sealed-sender style envelopes so the outer relay does not need a durable plaintext “from” field.
- After delivery, the relay copy is removed.
- Readable history stays in an encrypted local database on your devices.
Compared with other apps
- Signal / WhatsApp — strong default E2EE for private chats; Buzzio adds phone-free identity and a blind-relay posture for sealed 1:1.
- Telegram cloud chats — default chats are not E2EE like Buzzio sealed 1:1 (Secret Chats are opt-in).
What privacy does not mean
- Network observers can still see that you use Buzzio (not Tor by default).
- A compromised unlocked phone can show decrypted local history.
- Screenshots and second cameras are outside cryptography.
Tips
- Use sealed surfaces when operator-blind content matters most.
- Pair with Zero metadata and Control for device residue.