Skip to content
ashlonk
Why Ashlonk Voice Security Blog Support
العربية Get Ashlonk
Security

Locked on your phone. Opened on theirs. Nowhere else.

This page explains, without the legal language, how Ashlonk protects what you say. If you only read one line: every personal message and call is end-to-end encrypted, and the keys never leave your devices.

On this page
  1. End-to-end encryption, in one minute
  2. What our servers can see
  3. Verifying who you are talking to
  4. Your device is the front door
  5. Contact discovery without uploading your life
  6. How we run the service
  7. Report a vulnerability
  8. What we will never do

01End-to-end encryption, in one minute

When you open a chat with someone, your phones agree on a shared secret using public-key cryptography — the same family of maths that secures online banking. Each of you keeps a private key that never leaves the device; only the matching public keys travel through our servers.

Every message, voice note, photo and file is encrypted on your phone with that secret before it is sent. Our servers see a sealed envelope with an address on it — who it is for and roughly how big it is — and pass it along. They cannot open it, and neither can we.

Calls work the same way: audio and video are encrypted end-to-end between the two phones. When the connection cannot go directly between devices, our relay servers forward encrypted packets they cannot decode.

02What our servers can see

We are honest about the metadata a messenger needs to route traffic:

  • Your phone number and account profile (name, photo and "about" if you set them).
  • Which accounts you exchange messages with, and when — needed to deliver them.
  • Group membership, so group messages reach every member.
  • Device and connection basics: app version, OS, connection type and a transient IP address.

What our servers cannot see: the content of any message, voice note, file or call. Undelivered messages wait encrypted for up to 30 days and are then deleted; delivered messages are removed immediately.

03Verifying who you are talking to

Every chat has a safety code — a number you and your contact can compare in person or over a call. If the codes match, no one is sitting between you. Ashlonk warns you if a contact’s safety code changes, which normally means they reinstalled the app or changed phones.

04Your device is the front door

Encryption protects messages in transit. Once a message is on a phone it is only as safe as the phone. We recommend:

  • A screen lock, and Ashlonk’s own app lock (Settings → Privacy → App lock).
  • Keeping Android or iOS up to date; we support the two most recent major versions.
  • Never sharing your SMS verification code — we will never ask for it.
  • Turning on two-step verification (Settings → Account → Two-step verification) so a stolen SIM alone cannot take over your account.

05Contact discovery without uploading your life

If you allow contacts access, phone numbers from your address book are hashed on your device and matched against hashed numbers on our servers to show you who already uses Ashlonk. The results are used only for matching and are not stored beyond the match.

06How we run the service

  • All traffic between the app and our servers is protected by TLS in addition to end-to-end encryption.
  • Data at rest on our servers is encrypted; access is on a least-privilege basis and logged.
  • The website is fully static with a strict Content Security Policy — no scripts, no cookies, no trackers.
  • Every person who works on Ashlonk is bound by confidentiality obligations.

07Report a vulnerability

If you have found a weakness in the app, our servers or this website, please tell us privately at security@ashlonk.com before publishing anything. Include steps to reproduce and the app version. We acknowledge reports within 48 hours, keep you informed while we fix the issue, and credit you (if you wish) when it is resolved. We will never take legal action against good-faith researchers who respect user privacy and give us reasonable time to fix a problem.

We thank everyone who reports responsibly — by name, or anonymously if they prefer — on our Security Hall of Fame.

Our machine-readable policy lives at /.well-known/security.txt.

08What we will never do

  • Build a backdoor, key escrow or "lawful intercept" capability into Ashlonk.
  • Weaken encryption for any government, company or advertiser.
  • Read, scan or analyse the content of your conversations.

These commitments are backed by Article 40 of the Iraqi Constitution and spelled out in our Privacy Policy and Transparency report.

ashlonkأشلونك؟ Made in Baghdad, for everywhere.
العربية
© 2026 ashlonk · +964
Explore Voice notes Groups Calls Security Get the app
Company About Blog Marketing & Press Transparency report Security Hall of Fame
Help Support Community guidelines Delete your account Accessibility
Legal Privacy Policy Terms and Conditions Copyright