Legal
Security & Data Notice
How FLUX protects messages with end-to-end encryption, local encryption and peer-to-peer connections — and where that protection ends.
Last updated
This page explains how FLUX is designed to protect your communication, how far along each part is, and — just as important — what no messenger can protect against. We would rather tell you the limits than promise what nobody can guarantee.
FLUX does not promise absolute anonymity, and no software is impossible to break. FLUX is in development. Each capability below is marked with its real state, as everywhere on this site: Implemented, Experimental, Research or Planned.
End-to-end encryption — Implemented#
Messages are encrypted on the sender's device and decrypted only on the recipient's device. Anything in between — networks, servers, relays — carries only encrypted data and cannot read the content.
End-to-end encryption protects what you write. It does not by itself hide:
- that two devices communicate, when, how often, and how much data they exchange (metadata);
- your network address from the networks your messages cross;
- what happens on the devices themselves: a recipient can copy, forward or screenshot a message, and malware or someone with access to an unlocked device can read it.
Keys held by you — Planned#
FLUX is designed so that your identity keys are generated and kept on your device, not issued by a server. Whoever has your keys can read your messages; if you lose them, nobody — including us — can recover your messages.
Encrypted local storage — Planned#
Conversation history is designed to be stored only on your device, encrypted at rest. This protects it from someone who copies the device's storage, but not from someone who can use your unlocked device. A strong device passcode remains essential.
Peer-to-peer connections — Experimental#
Over the internet, FLUX connects devices to each other directly where it can, rather than routing everything through one central service. A direct connection means the devices learn each other's IP addresses, which can reveal an approximate location. Where a direct connection is not possible, connections may need help from intermediate servers, which see that a connection exists but not its content.
Bluetooth mesh — Research#
We are researching offline, device-to-device messaging over Bluetooth Low Energy, where nearby devices relay encrypted messages. This is research, not a working feature. If it ships, people nearby could still detect that devices are communicating, even though they cannot read the messages.
What this website knows#
This website is separate from your conversations. It never receives private keys, session keys, message content or other cryptographic material — requests containing such fields are refused. What it does collect (for the waitlist and the newsletter) is described in the Privacy Policy.
Independent review#
The FLUX client code is being opened for public review (see Licenses & Open Source). Until an independent security audit is published on this site, treat FLUX as software in development and do not rely on it where a security failure could put someone in danger.
Reporting a vulnerability#
If you find a security issue in FLUX or this website, please write to Support@bash-soft.com with "Security" in the subject. Include what you found and how to reproduce it. We confirm receipt, keep you informed, and credit you when we publish the fix, if you wish.
Please give us reasonable time to fix the issue before disclosing it, do not access or change other people's data, and do not degrade the service for others (no denial-of-service testing). Research that follows these rules in good faith is welcome. Fixed issues are published as security advisories.