Security / privacy
What Shum protects
What Shum protects, where your data lives and what it does not hide yet.
01
Keys on your device
Your profile is created on the device. No sign-up, no phone number.
02
Content is encrypted
Only the recipient can read a message. It stays encrypted in transit.
03
Relays deliver data
Nostr relays carry sealed envelopes over the internet. If a relay is down, delivery is delayed.
Where your data lives
| Data | Stored | What to know |
|---|---|---|
| Profile keys | On your device | Without the keys a profile cannot be restored. Make a backup. |
| Chat history | Local app storage | Your chats are only as safe as your device. |
| Encrypted messages | Devices and relay transport | Each relay decides how long to keep envelopes. Future versions will let you run your own relay, link relays into a network for your people, or host a complete server yourself. |
| Connection metadata | Network infrastructure | Encryption hides the text, not the fact that a connection happened. Future versions will let you connect over Tor if you choose: relays will not see your IP address, and your provider will not see which relays you use. |
| Notifications | Shum push server and Apple | The server sees who sent a notification to whom. Apple sees the sender's name in the title. Message text is never sent. |
Limits of protectionWhat to
What to
keep in mind
Your device must be protected
Whoever holds your unlocked phone can read your chats. Use a screen lock and keep your system updated.
Deleting does not recall delivered messages
Deleting wipes the profile on your device. Copies with your contacts and envelopes on relays may remain.
Check who you add
Anyone can use any name and avatar. Compare the safety code in person or over a channel you trust.
Technical details
Key formats, signatures and message-handling rules are described in the specification.