Security & Privacy

Private by construction,
not by promise.

On most networks, privacy is a policy the operator asks you to trust. On Pixelmine it is a property of the mathematics: your private content is sealed on your own device before it ever leaves, and no node — and not the company — holds the keys to open it.

Operator-blind

The people running the service
cannot read what you share.

Direct messages, group chats, and followers-only posts are encrypted on your device and can only be opened by the people you intend. Everything that stores or relays that content — the nodes, the coordination service — only ever handles sealed data it cannot decrypt. There is no master key and no back door for anyone to abuse, leak, or be compelled to hand over.

Sealed on your device

Content is encrypted before it is sent. Plaintext never leaves your phone.

Stored blind

Nodes hold only ciphertext and wrapped keys — meaningless without your key.

Only you hold the keys

Decryption happens solely on the devices of the people you chose to share with.

The encryption

Future-proof by default.

Pixelmine’s encryption is built on standards designed to remain secure even against the quantum computers of the future. Each message and post is sealed with a fresh key, and that key is wrapped individually for every recipient — so reaching many people stays cheap, and no shared secret is ever exposed. What is sealed today stays sealed against tomorrow’s decryption.

  • A future-proof key exchange establishes a shared secret only you and your contact can derive — never the network in between.
  • Every message and post is encrypted with its own single-use key, so one compromise can never unlock the rest.
  • That key is wrapped separately for each recipient, so nodes only ever see sealed blobs they cannot open.
Sealing to an audience

Only the right people can open it.

A followers-only post is sealed with a single key, and a copy of that key is wrapped individually for each accepted follower — so exactly those people can read it, however far the post travels. Group chats work the same way, sharing one key among their members.

  • Accepting a follower runs a one-time key exchange with them — done once, then reused for every future post.
  • Each post carries a small manifest: its key, wrapped separately per follower. Nodes store the manifest but can open none of it.
  • When someone leaves or is removed from a group, the key is rotated — they keep what they already saw, but cannot read anything new.
Integrity

Verifiable, not just private.

Because the network is made of independently run nodes, authenticity cannot rest on trusting the machine that hands you data. Instead every action carries a signature and every record proves its own authorship — so a node can safely accept data from strangers precisely because it never has to trust them.

  • Every post, follow, and reaction is signed with a key only you hold, and checked before any node will store it.
  • Your identity is the fingerprint of your own key, so no one can bind your name to a key they control — impersonation fails the math.
  • Tampering is self-defeating: alter a record and its signature stops verifying, and the network drops it.
Your identity

You are a key you hold,
not an account we keep.

Your identity is derived from a cryptographic key generated on your own device and never handed to anyone. It works across every node with no login and no password to phish or leak. The company cannot reset it, lock you out of it, or impersonate you — because it never holds it in the first place.

Recovery & control

Yours to keep, yours to take.

Owning your identity means owning its recovery too. Your keys export as a single encrypted file, locked with a passcode, and restore on any device — the company is never in that loop. The keys that unlock your conversations are themselves stored sealed to you, so you can recover them across devices without ever exposing them to a node.

Portable backup

An encrypted key file, secured by your passcode, restores your account anywhere.

No back door

There is no reset button we can press and no key we can produce under pressure.

Your data, portable

Your content lives across many nodes, not locked inside one company’s servers.

What we can and can’t see

Drawing the line, honestly.

End-to-end encryption is a strong guarantee, but an honest one is worth more than an overstated one. Here is exactly where the line falls.

What stays private

  • The content of your messages, group chats, and followers-only posts.
  • Your keys and your account settings.
  • Private media — stored encrypted, meaningless without the key.

What isn’t hidden

  • Public posts are public by design, so they can be discovered and shared.
  • That communication happened — encryption hides content, not the fact of it.
  • The timing of activity and the broad shape of the network remain observable.
The honest limits

What encryption can’t do.

Strong privacy is worth stating precisely. Encryption protects the contents of your communication — it does not erase the fact that communication took place, and it is not a cloak of total anonymity.

  • Metadata is not hidden: that two people share a conversation, when they are active, and the broad shape of the network remain observable.
  • One-to-one content uses a long-lived shared key for efficiency, so it does not offer forward secrecy — a rare key compromise would expose that relationship’s history. Group chats gain forward secrecy for future messages through rotation.
  • Anyone you shared something with can screenshot or keep it; encryption controls who can open a thing, not what they do with it afterward.
The building blocks

Standards, not homegrown crypto.

Pixelmine does not invent its own cryptography. It uses published, standardized algorithms — the same ones being adopted to resist future quantum computers.

Key exchange

A post-quantum key-encapsulation standard (ML-KEM-768, FIPS 203) establishes shared secrets.

Signatures

A post-quantum signature standard (ML-DSA-65, FIPS 204) authenticates identity and every record.

Content encryption

AES-256 seals the actual messages, posts, and files.

In short

Your privacy doesn’t depend
on trusting us.

It rests on keys only you hold and encryption no operator can undo. That is the difference between a promise and a guarantee.