01Your words stay yours
Each participant controls their own message history. Deleting your local conversation does not erase another participant’s copy. Once the server accepts an encrypted message, it can deliver it when the recipient reconnects, even if the sender is then offline. Data not yet uploaded remains on the sender’s phone.
Mnelo does not analyze or generate conversations with AI, send their contents to an AI provider or use them to train a model. The app does process and encrypt data on participant devices. ‘No AI’ does not mean ‘no processing’ or ‘no encryption’.
02What makes the connection possible
Phone registration uses Infobip to send and verify a code. Mnelo processes the number and retains a keyed phone-number index, public device identity, discoverability choice and verification time, plus aggregate SMS usage counters. It also retains Apple/Google push-routing tokens and revocable notification permissions.
Infobip, Hetzner, Apple, Google and the website host Vercel operate under their own policies and may retain operational metadata. Network services can observe IP addresses, connection timing and traffic volume. We do not claim these providers retain nothing.
Push providers receive generic events and delivery metadata. Message alerts may wait for a reconnect within their expiry; incoming-call alerts have a short expiry. The iPhone can resolve a contact name and decrypt a preview locally after receiving the event. Push acceptance is not proof of message delivery.
03Protection, with honest limits
The local database uses SQLCipher, with its key in operating-system secure storage. Messages use the Signal protocol through libsignal; attachments are encrypted on the sender’s device with their keys carried inside encrypted messages. Calls use authenticated WebRTC encryption. This integration has not been independently security-audited.
Verifying a phone number alone does not independently verify a contact’s encryption identity. Compare the contact code with the person. Device compromise and stolen keys can expose information on a participant’s device.
04A personal introduction, chosen by you
Your photo and optional profile details are stored locally and exchanged with contacts over an authenticated encrypted connection. Recipients can keep their copies.
A QR invitation contains a shared name and public Mnelo identity, never a private key, phone number, email, photo or message history. The browser reads this from the URL fragment, which is not included in the HTTP request. Anyone holding the link can read its contents.
05Your copies, your responsibility
Encrypted backup exports use a user-held key. Chat ZIP exports are different: they contain readable history and files, so anyone with the ZIP can read them. Choose the storage destination carefully. Automatic cloud synchronization and restoring the current encrypted messaging identity are not available; an export does not recover a lost identity.
Deleting local history does not delete other participants’ copies or exported backups. Account & data explains local erase, registration unlinking and the current lost-key limitation.
06A quieter website, too
This messenger website has no analytics, advertising, registration form or application database connection. Invitations are processed in the browser. The host still handles HTTP requests and may keep network metadata.
Contact g.devd1@gmail.com for Mnelo support and privacy requests, or use TestFlight’s Send Beta Feedback. Do not include OTPs, recovery keys, passwords or private messages. Final public-release legal notices are still being prepared.