Device security
Security check required
Start something secure
New conversation
Create group
Find people you know
ChtCr can privately check which of your contacts already use ChtCr. Only email addresses and phone numbers from contacts you select are normalized and checked; names stay on this device during discovery. When you choose to invite someone, their name and chosen email or phone are saved with your invitation. Your contacts will not be messaged or invited without your approval.
Enter secure invitation
Choose contacts to add or invite
People
New chat
Add a contact
Invite someone by email or phone, or exchange a QR contact code in person.
Messages
Chats
Search ChtCr
Message text is searched only after decryption on this device.
Your inbox
Recent messages and updates
Action needed
Important security updates
Recent contacts
Active groups
Recent activity firstReceived
Latest messages
Newest received activity first. Message text appears only where local decryption and privacy settings permit it.
Content
Your groups, channels, and communities
Create or join
Create a private group, channel, or community, or use an invitation you trust.
Groups and channels
Communities
Groups and channels
Group details
Members
Requests to join
Moderation history
This log contains actions, reasons, and message identifiers—not decrypted message content.
Create an event
Communities
Community
Community details
Groups and announcement channels
Member directory
Encrypted collaboration
Stories use per-device key envelopes. Task, note, event, and payment memo text is encrypted with the conversation key before it leaves this device. ChtCr never requests or stores card or bank credentials.
Private on-device AI
Only locally decrypted text is processed. Translation requires an installed on-device language model and fails closed when unavailable.
Profile and privacy
Images are resized locally to 512 × 512 and metadata is removed.
Off by default. ChtCr matches only identifiers you have verified and never shows your email address or phone number in discovery results.
Notifications
Security
Contacts and chat calls use bearer tokens plus per-device HMAC signatures. Device secrets are stored with the platform secure-storage adapter.
Your data
Selected email addresses and phone numbers are normalized and checked for matches. ChtCr does not automatically invite anyone. Turn this off to withdraw future access; device permission can also be removed in system settings.
The production database is configured in AWS Ireland. ChtCr does not claim every backup, log, delivery provider, support system, or subprocessor remains in the EU or EEA. Review hosting, transfer, data-rights, and business DPA information.
Key backups never contain login sessions, device credentials, or plaintext messages. Keep the backup password separately—ChtCr cannot recover it.
Documents are hashed locally and are not uploaded for signing. The receipt proves that this verified device signed the exact SHA-256 hash.
Organisation and compliance
eDiscovery exports preserve encrypted evidence and integrity hashes. ChtCr cannot decrypt message contents without participant-held keys.
Administration
A webhook signing secret is displayed once, as is each bot token. Store them in a secret manager. Marketplace plugins are declarative and receive only explicitly approved permissions.
Help and safety
Using ChtCr safely
Start conversations from Chats, find or invite people from the new-conversation menu, and manage devices, two-factor authentication, passkeys, and recovery codes under Security.
On the web, use Ctrl/⌘ K to search, Ctrl/⌘ N for a new chat, and Ctrl/⌘ Enter to send. Keyboard users can use the skip link, arrow through the bottom navigation, and press Escape to close menus and dialogs.
For account access problems, use Forgot password? on the sign-in screen. ChtCr staff should never ask for your password, MFA or recovery code, device secret, backup password, or encryption keys.
Read the privacy, hosting, data-rights, and business DPA information.