Security / privacy

What Shum protects

What Shum protects, where your data lives and what it does not hide yet.

01

Keys on your device

Your profile is created on the device. No sign-up, no phone number.

02

Content is encrypted

Only the recipient can read a message. It stays encrypted in transit.

03

Relays deliver data

Nostr relays carry sealed envelopes over the internet. If a relay is down, delivery is delayed.

Where your data lives

DataStoredWhat to know
Profile keysOn your deviceWithout the keys a profile cannot be restored. Make a backup.
Chat historyLocal app storageYour chats are only as safe as your device.
Encrypted messagesDevices and relay transportEach relay decides how long to keep envelopes. Future versions will let you run your own relay, link relays into a network for your people, or host a complete server yourself.
Connection metadataNetwork infrastructureEncryption hides the text, not the fact that a connection happened. Future versions will let you connect over Tor if you choose: relays will not see your IP address, and your provider will not see which relays you use.
NotificationsShum push server and AppleThe server sees who sent a notification to whom. Apple sees the sender's name in the title. Message text is never sent.
Limits of protection

What to
keep in mind

Your device must be protected

Whoever holds your unlocked phone can read your chats. Use a screen lock and keep your system updated.

Deleting does not recall delivered messages

Deleting wipes the profile on your device. Copies with your contacts and envelopes on relays may remain.

Check who you add

Anyone can use any name and avatar. Compare the safety code in person or over a channel you trust.

Technical details

Key formats, signatures and message-handling rules are described in the specification.