Enigma X is operated by Martekings OY (Finland), which is the data controller for the processing described here. You can reach us at enigma@ifonly.tech.
1. The short version
- Your account is a cryptographic key pair generated on your device. We never ask for your name, email address or phone number to use the app.
- Your private keys, recovery phrase and encryption keys never leave your device. We cannot read your encrypted messages — not by policy, by design.
- Your typing is processed entirely on your device. The keyboard does not transmit keystrokes anywhere.
- Our servers do store some data to make the product work: your public address and public key, subscription tier, usage counters, reward balances, push tokens, a log of key exchanges between accounts, and anything you write to our support chat. Section 4 lists all of it.
- The apps contain no advertising networks. Two exceptions are named plainly rather than buried: a purchase-attribution service used when you subscribe (section 10), and analytics on this website (section 9).
2. What we can never see
Private keys and recovery phrase. Generated and stored only on your device. They are never transmitted to us, and we have no mechanism to recover them for you.
The content of your messages. Text is encrypted on your device by the Enigma X keyboard before it enters the messenger you are using. The encrypted text travels through that messenger — WhatsApp, Telegram, SMS or any other — not through our servers. We never see your messages in either form, and the messenger sees only ciphertext.
Your keystrokes. The keyboard processes typing locally. Word suggestions and completions come from dictionary files shipped inside the app and are computed on the device. Release builds contain no keystroke logging.
Your address book. We never access the contact list on your phone. Contacts you add inside Enigma X are stored locally on your device.
Your identity. An account is a public address derived from a key pair. Unless you tell us who you are — for example in support chat — we do not know it.
3. Data processed only on your device
Encryption keys, the recovery phrase, your Enigma X contact list, message drafts, privacy mode text, received and decrypted files, and the suggestion dictionaries. You can delete all of this at any time by deleting your account in the app or uninstalling it.
4. Data our servers store
To run the service we operate a backend, hosted on Supabase with media files on Amazon Web Services. It stores the following, keyed to your public address:
Account record
Public address, public key, subscription tier and its expiry date, app version, interface language, last sync time, usage counters such as how many times encryption was used against your plan's limit, reward and token balances, your referral code and — if you signed up through one — the referring account, and in-app quest progress.
Key-exchange log
When you exchange encryption keys with a contact, the key itself is sealed to the recipient's public key and we cannot read it. The record of the exchange — sender address, recipient address and time — is stored in readable form and kept while your account exists. This is what makes account recovery possible: a restored device rebuilds its contact list and regains access to its own history from this log. Stated plainly: we hold metadata about which Enigma X accounts exchanged keys with each other and when. We do not hold the content of any conversation.
Devices and push tokens
A push notification token for your device (see section 8) and a device record used to enforce the one-device-per-account model, including authentication challenges signed by your key.
Encrypted media
Voice messages and media attachments are encrypted on your device and uploaded to cloud storage; recipients fetch them through time-limited links. The storage holds ciphertext, and the decryption key travels inside your encrypted message, which we cannot read.
Support chat
Messages and attachments you send to our in-app support chat are readable by our support team — that is what they are for. They are stored linked to your public address and are not end-to-end encrypted. Please do not include sensitive information you would not want us to see.
Subscription linkage
When you subscribe, we link the store transaction to your public address so that your tier follows your account. We never see your payment details (see section 7).
5. Location sharing
Sending your location is optional and happens only when you tap the location button and grant the operating system's location permission. The app takes a single fix at that moment — there is no background tracking. The coordinates are encrypted on your device into the message like any other text and are not sent to our servers. When a recipient opens a received location, the coordinates are handed to the maps application on their device.
6. The keyboard and "Full Access"
On iOS the system asks you to grant the keyboard "Full Access"; Android shows a similar warning when you enable a third-party keyboard. Enigma X needs this so the keyboard can encrypt and decrypt on the device and exchange data with the main app — not to send your typing anywhere. Keystrokes are processed locally, dictionaries live on the device, and the keyboard uses the network only for the functions described in section 4, such as uploading an encrypted voice message.
7. Payments
Subscriptions are bought through the Apple App Store or Google Play. Payment is processed entirely by Apple or Google under their own privacy policies. We never receive your card number or billing details — only confirmation that a transaction took place, which we link to your account as described in section 4.
8. Push notifications
Delivery uses the platform push services: Apple Push Notification service and Google Firebase Cloud Messaging. These services receive a device token and, as with any network traffic, technical connection data. Notifications are delivery signals; they do not contain decrypted message content. The Firebase SDK in our apps is configured with analytics disabled.
9. This website
This website uses two analytics services to measure how visitors use it: Google Analytics and Yandex Metrica. Yandex Metrica is configured with session replay ("Webvisor"), click maps and link tracking, which means it records page interactions such as mouse movement, scrolling and clicks, and can replay a visit. Yandex processes that data on its own infrastructure, located in Russia.
This concerns visitors to this website only. It is entirely separate from the apps: website analytics have no connection to your Enigma X account, your keys or your messages, and nothing in the apps reports to these services.
You can opt out using your browser's tracking controls or an ad/tracker blocker, the Google Analytics opt-out browser add-on, and the opt-out offered by Yandex Metrica.
Standard web server logs — IP address, browser user agent and pages requested — may be kept briefly for security and operations.
If you subscribe to updates with your email address, or write to us through the contact form on this site, what you submit is stored in the same backend described in section 4. We use a subscription address only to send those updates, and every message includes an unsubscribe link; a contact form submission is used only to answer you. Neither is linked to an Enigma X account, because the website does not know your public address.
10. Service providers
We use a small set of providers to run Enigma X: Supabase (database and server functions), Amazon Web Services (encrypted media storage), Google Firebase (push notification delivery), Apple and Google (app distribution and payments), GoMarketMe (purchase attribution: it receives store transaction confirmations and device information so that affiliate partners can be credited for subscription purchases, and never receives your messages, keys or account contents), and Netlify (hosting for this website).
They process data on our behalf under their own security and data-processing terms. We do not sell or rent any data to anyone, and we share data with no one else, except as required by law (see section 13). Some providers process data outside the EU and EEA; where that happens, transfers rely on the safeguards those providers offer, such as the EU standard contractual clauses.
11. Retention and deletion
- On your device: delete data at any time in the app, or by uninstalling it.
- On our servers: the records in section 4 are kept while your account exists, because they are what makes the account work and recoverable. Uninstalling the app does not by itself delete server records.
- Deletion on request: write to us from the app's support chat or email us with your public address, and we will delete your account record, push tokens, support history, stored media and key-exchange log. After that, account recovery is impossible — we cannot restore what we no longer have.
12. Security
All message encryption and decryption happens on your device, using AES symmetric encryption with public-key cryptography for key exchange. Keys are stored in the platform's secure storage and are never transmitted to us. Connections to our backend use TLS, and stored media is ciphertext. No system is perfectly secure and we do not promise otherwise — but we have designed the service so that the most sensitive data never reaches us at all.
13. What we could disclose if legally compelled
Because of the design above, the complete list of what we could produce in response to a lawful request is the server-side data in section 4: account records, the key-exchange metadata log, push tokens, support chat history, and encrypted media we cannot decrypt. We cannot produce message content, keys or your identity, because we do not have them.
The same holds for proposals such as EU Chat Control. Because encryption happens in the keyboard on your device, we cannot comply with a request to hand over readable messages — there is no point in our infrastructure where your unencrypted communications exist.
14. Children
Enigma X is not directed at children under 13, and we do not knowingly collect data from them. If your jurisdiction sets a higher minimum age for consenting to data processing, that age applies. If you are a parent and believe your child has provided us with personal information, please contact us.
15. Your rights
If you are in the EU or EEA, or another jurisdiction granting data-protection rights, you may request access to, correction of or deletion of the data we hold about you, restriction of or objection to its processing, and a portable copy. Contact us at enigma@ifonly.tech; we will need your public address to locate the data. You also have the right to complain to a supervisory authority — in Finland, the Office of the Data Protection Ombudsman (tietosuoja.fi), or the authority in your own country.
Where a legal basis is required: we process the section 4 data to perform our contract with you, namely providing the service; server logs and security processing rest on our legitimate interest in keeping the service running and safe; website analytics and the newsletter rest on your consent, which you can withdraw at any time.
16. Open source and acknowledgements
Enigma X builds on open-source software. In particular:
- Russian word frequencies: FrequencyWords by Hermit Dave, licensed CC BY-SA 4.0. The adapted word list ships inside the app and is likewise available under CC BY-SA 4.0. The dictionary is used entirely on your device.
- The Android app is built on FlorisBoard, licensed Apache 2.0. Its license and copyright notices are preserved, and the app's About screen includes the project license and a full list of third-party licenses.
- The iOS app uses open-source components under their respective licenses, including web3swift, CryptoSwift, swift-sodium, secp256k1.swift, BigInt, Lottie, Hero, MultipartFormData, and the Supabase, Firebase and Apple Swift libraries.
17. Changes to this policy
We will post updates on this page with a new "last updated" date, and announce material changes in the app. Your continued use after a change takes effect constitutes acceptance of the updated policy.
18. Contact
- Martekings OY
- Email: enigma@ifonly.tech
- Contact Form, or the support chat inside the app
Remember
With Enigma X, your privacy isn't just a policy — it's built into the architecture. We can't read your messages even if we wanted to, and this page is written to tell you exactly where that guarantee ends.