Questions & answers.

The honest versions — including the answers other messengers put in the fine print.

Can you read my messages?

No. Messages are encrypted on your device with MLS (RFC 9420) before they leave it, and decrypted only on the recipient’s device. Our relay stores and forwards ciphertext it cannot open, and deletes it after delivery (or after 30 days if never delivered).

We label the encryption “beta, unaudited”because our integration hasn’t had its third-party review yet — the underlying protocol library has. The security brief tracks exactly where that stands.

What data do you actually have about me?

The server knows: a random user ID, your device’s public keys, and encrypted blobs in transit. Your profile — name, phone, email, photo — stays on your device. Verification emails are stored only as hashes. There are no ads, no analytics, and no trackers, in the app or on this site.

What happens if I lose my phone?

Honestly: today, the account is gone. Your identity is a key held only by your device — no password, nothing on our servers to restore. That’s a real trade-off we chose over server-side recovery, which would mean a copy of your keys existing somewhere we could be forced to hand over.

Multi-device support and an encrypted backup you unlock with a recovery code (that we never see) are designed and on the roadmap.

Why is Whist paid?

Because you’re the customer, not the product. Free messengers are paid for somehow — usually with data. One person in a circle pays (Duo, Circle, or Team, through the App Store); everyone they invite uses Whist free. No ads ever.

How do I know I'm talking to the right person?

Every chat has a safety number— 60 digits that you and your contact both see. Compare them in person or over a call; if they match, no one is sitting between you. Mark the chat verified and Whist will warn you by removing the badge if your contact’s key ever changes.

Do disappearing messages really disappear?

On your device and ours: yes, genuinely deleted, not hidden — the database rows are purged and vacuumed. On your contact’s device: their app deletes them too, but we won’t pretend deletion can defeat a screenshot or a modified client. No messenger can, and the ones that imply otherwise are selling you something.

Why did the code come by email and not SMS?

Because SMS verification isn’t built yet, and the app says so instead of pretending. (SMS is also the weaker channel — SIM-swap attacks are real — so email went first on purpose.)

How is this different from WhatsApp or Signal?

Signal is excellent and audited — if you need proven, maximum-assurance privacy today, use Signal. Whist is for private circles: one person pays, their people join free, no phone-number-book scraping, profile data never uploaded, and a strict rule that the product never claims more than it does. We’re earning the audit receipt Signal already has, and we say so out loud.

Where are your servers?

The relay runs in the European Union (Cloudflare, Eastern Europe region). Since it only ever holds ciphertext and delivery metadata with short retention, the honest answer to “where is my data?” is mostly: on your device.

Android? iPad? Desktop?

iPhone first. Multi-device is a security design problem we’re solving properly (see the roadmap in the security brief) — other platforms come after that foundation, not before.

I found a security issue. Who do I tell?

[email protected] — we read every report, respond honestly, and credit researchers who want credit.