Tech insider

How theSHFT works, in detail.

The homepage keeps it simple. This page is for people who want the specifics: the protocols, the limits, and what our servers can and can't see.

Describes theSHFT 9.4, the version on the App Store today

What's end to end encrypted, and what isn't

End to end means only the phones in the conversation hold the keys. Some parts of theSHFT are built that way and some aren't, so here's the full list.

FeatureEnd to endHow
Direct messagesYesX3DH, the Double Ratchet and NaCl box, plus ML-KEM-768 when the other phone supports it
Group chatsYesSender Keys over X25519
Voice and video callsYesAES-256-GCM through Agora, with a per-call key the phones agree on over X25519
Photos, videos and voice notes in those chatsYesEncrypted with the chat's key on your phone before upload
StoriesNoThe media is encrypted at rest, but our server holds its key so it can show the Story to your contacts
Community postsNoReadable by any signed in account, by design

The protocols

Direct messages

A new chat starts with X3DH key agreement, using identity keys, signed prekeys and one time prekeys, so it works even when the other phone is offline. From then on the Double Ratchet gives every direct message its own key, so one leaked key doesn't open earlier or later messages. The cipher is NaCl box: Curve25519, XSalsa20 and Poly1305.

X3DHDouble RatchetXSalsa20-Poly1305

Post quantum layer

Direct messages are wrapped in both Curve25519 and post-quantum ML-KEM-768 (NIST FIPS 203) whenever the recipient's device has published a post-quantum key; an attacker then has to break both. A device without one gets a classical Curve25519 session. Group chats and calls don't have this layer.

The ML-KEM-768 code is the PQClean reference C library, compiled natively on iOS.

ML-KEM-768PQClean

Group chats

Groups use the Sender Key protocol over X25519. When someone joins or leaves, each member moves to a new sender key before their next message.

Sender Keys

Calls

Voice and video calls are end to end encrypted with AES-256-GCM through Agora. The two phones agree on the call key over X25519. Calls use classical cryptography only.

AES-256-GCMX25519

Padding

Before encryption, message text is padded with random bytes up to a multiple of 256 bytes, so the size of a message gives less away.

On your phone

Local storage

What theSHFT saves on your phone is encrypted again, field by field, with XSalsa20-Poly1305 (NaCl secretbox). The key is 256 random bits made on the phone, kept in the iOS Keychain and marked this device only. If iOS includes theSHFT's files in the phone's own backup, only this same phone can open your messages.

Your PIN

The PIN is hashed with PBKDF2 at 600,000 iterations. Checking your PIN takes the same time whether you type your real PIN, your Duress PIN or a wrong one, so timing gives nothing away.

Your 12 words

The recovery phrase is 12 words from the standard BIP39 list, generated on your phone. To find your account on a new phone, the app sends a one way hash of the phrase, never the words.

Duress PIN (Pro)

Typing the Duress PIN deletes your account on our server and wipes theSHFT's data on the phone, then shows the welcome screen like a fresh install. There's no undo.

Screenshots, precisely

From the moment it starts, theSHFT draws its screens through a protected layer, so on iPhone a screenshot, a screen recording or AirPlay mirroring of the app captures a black image. This rests on how iOS renders protected content, not on a supported Apple API, so treat it as a strong deterrent rather than a guarantee.

iOS tells apps after a screenshot has been taken. When that happens in a chat, theSHFT writes a small system event into the conversation and the other person sees that you took a screenshot. iOS gives apps no signal when a recording starts, so recordings are blacked out but never reported. A camera pointed at the screen gets around all of it.

Timers, precisely

When the countdown starts

A timed message starts its countdown when it is read, on your phone and on theirs. Our server stamps the expiry when it sees the read. In a group, each member's copy counts down from when that member reads it.

Timer lengths

New chats start at 10 seconds. Free accounts can pick Off, 10 seconds or 30 seconds. Pro adds everything from 5 seconds up to 24 hours. Either person can change a chat's timer and the other side follows.

Messages nobody opens

If a timed message is never opened, your copy leaves your phone 72 hours after you send it, and in a group an unread timed message is removed 72 hours after it was sent. An unopened direct message waits on our server, still encrypted, for up to a year before cleanup removes it.

Legal holds

When valid legal process requires us to preserve specific messages, cleanup skips them. That's rare. Direct messages and group chats stay encrypted either way, and we don't have the keys to them.

What our servers see

Routing data

To deliver messages, our servers see who a message is from and who it's to, when it was sent and how big it is. They can't read your direct messages, group chats or calls. Your contact list lives on our servers too, so it comes back when you restore your account.

Notifications

Message notifications carry generic text, like "New notification", on your lock screen. Each push also carries a small routing payload that reaches Apple and our delivery provider. For calls, group adds, mentions and reactions that payload includes a username or group name. Message content is never in it.

Crash reports

Crash and stability reports go to Sentry after keys, tokens and account IDs are scrubbed out. They include your device model, iOS version, app version, session start and end, app hangs, and for a sampled 10 percent of sessions the names of the screens you opened. You can turn them off in Settings, under Privacy, with Send crash reports.

What the app never asks for

There are no advertising or product analytics SDKs in the app. theSHFT never asks for your address book or your location.

Link previews

A link preview is made on the sender's phone before encryption and travels inside the message, so the recipient's phone never contacts the linked site.

Code and audits

theSHFT's encryption module (X3DH, Double Ratchet, Sender Key and the ML-KEM-768 hybrid) is published at github.com/wma1101/theshft-crypto. The public copy is behind the app today; starting with the 9.4.0 republish it will be mirrored from the app at every App Store release, with the hash of the shipped file in the repo.

The app, server and rules are not open source and no external audit has been commissioned. Found a vulnerability? Email support@theshft.app.

SHFT, theSHFT's mascot, giving a thumbs up

Seen enough?

theSHFT is free on iPhone. Android is coming soon.

Download on the App Store