PRIVACY, EXPLAINED

Your space.
Clear boundaries.

Privacy is easier to trust when you understand how it works. Here is what CTalk protects, what is visible, and where you stay in control.

Start with less personal information.

CTalk uses a User ID and password. It doesn't require a phone number, email address, real name, address book or location permission for account access.

Your display name and User ID are still visible to the people you connect with. Choose an alias if you don't want to use your real name. A username-based account is not a guarantee of anonymity: messages, images, documents and voice recordings can reveal identifying information.

Encrypted before upload.

The CTalk app encrypts message content and attachments on your device before sending them to the server. The backend stores encrypted content. HTTPS protects communication between your device and the service.

Account recovery has a trust boundary.

Administrators hold recovery access for accounts they manage. Super admins can hold recovery access for workspaces that enable it. This allows password resets while preserving the account's chat keys and history.

This design is not a promise that content is inaccessible to administrators or people with recovery access. Protect administrator devices and passwords carefully.

CTalk uses a custom encryption design. It has not received an independent cryptographic audit and does not implement the Signal or WhatsApp protocol. It does not provide forward secrecy.

Access follows your connections.

  • A client doesn't get a directory of every other client. Direct conversations connect the client with their admin and, when assigned, a manager.
  • Managers access their assigned client conversations and groups they belong to.
  • Group members can see one another's aliases, User IDs and workspace names. Cross-workspace group connections require an accepted invitation.
  • The server processes account roles, workspace and group relationships, timestamps, delivery/read information, session information and encrypted content sizes.

The super-admin management screen shows workspace and account controls, not a general inbox of everyone else's conversations. Recovery access described above remains a separate consideration.

Saving a file creates another copy.

Downloading or saving media creates a file on your device outside the chat's controlled storage. That copy can remain after logout or message deletion. Opening a document in another application gives that application access to the file.

Delete for me affects your view. Delete for everyone removes the original message content from the chat and denies new downloads of its attachment, but it cannot recall screenshots, saved files, forwarded copies or quoted content in other messages. Offline previews may remain until the device reconnects. Encrypted content may also remain in backups.

Review what your files contain.

Supported images are re-encoded by the app to remove image metadata such as EXIF/GPS. Videos, documents, audio and other files may still include identifying metadata. Faces, names, text and spoken details can identify someone even when metadata is removed.

Private conversations aren't invisible connections.

Your IP address is not shown to other users by CTalk's chat interface. The hosting service, network operator, internet provider and push provider can still observe network information. CTalk does not offer total anonymity or a guarantee that a connection cannot be traced.

The calling design uses an authenticated relay with no direct peer-to-peer fallback. Its purpose is to avoid sharing participants' direct IP addresses with each other. Public audio/video calling is still being enabled for this testing release.

Notifications and device access.

Firebase receives device tokens and message identifiers, not chat text or attachment contents from this integration. The Android app fetches and decrypts notification previews. Android, lock-screen viewers and notification-reading apps you authorize may be able to read those previews.

An unlocked device or approved linked browser can access your account. Review linked devices, sign out when needed, and keep your device secured.

A simple information site.

This CTalk website does not add advertising trackers, analytics scripts, third-party embeds or a contact form. Fonts and assets are served locally or by your browser. Website access logging is disabled in its virtual-host configuration.

Your browser still connects to CTalk's hosting service, which can process connection information. The messaging app has its own authenticated sessions, device storage and service providers.

This is a practical explanation of the current product, updated 15 September 2026. For account and access questions, contact your workspace administrator. Visit the help centre.