support · encrypted · ephemeral

Redacted Support

End-to-end encrypted messaging that self-destructs.

For all support, abuse reports, security issues, or general enquiries:

support@redactedapp.com

We aim to respond within 48 hours.

Frequently Asked Questions

Getting started

How do I create an account?

Download Redacted from the App Store or Google Play, then choose a username and passphrase. No phone number, email address, or real name required.

What is a passphrase, and why does it matter?

Your passphrase is what generates your encryption keys. Choose a strong passphrase you'll remember — we cannot recover it if you forget. If you lose your passphrase, you lose access to your account permanently.

Can I use Redacted on multiple devices?

Currently, Redacted is a single-device app per account. Multi-device support is on our roadmap.

Privacy and encryption

Can Redacted read my messages?

No. Your messages are encrypted end-to-end using NaCl cryptography. Your encryption keys are derived from your passphrase and stored only on your device. The Redacted servers only see encrypted ciphertext that we cannot decrypt — even if compelled by court order.

What data does Redacted collect?

We collect the minimum required to operate the service: your username, hashed password, push notification token, and encrypted message metadata (delivery timing, sender/recipient IDs). We do not collect phone numbers, email addresses, real names, location data, contact lists, or analytics tracking.

Where is my data stored?

All Redacted servers are hosted in Sydney, Australia. Your encrypted messages are stored only until delivered and opened. Once a message's destruction timer expires, the encrypted ciphertext is permanently deleted from our servers.

What happens to my data if I delete my account?

Your account and all associated data are permanently deleted within 30 days of account deletion. Encrypted messages you sent to others may still exist on their devices until those messages expire per the destruction timer.

Self-destructing messages

How do destruction timers work?

When you send a message, you choose how long it should exist before being permanently destroyed. Once the timer expires, the message is removed from your device, the recipient's device, and Redacted's servers.

What timer options are available?

Free users can choose: 30 seconds, 2 minutes, 5 minutes, 1 hour. Redacted Premium users can choose: 24 hours, 7 days, 30 days, or never destroys.

Can the recipient save my messages?

The recipient can screenshot your message before it expires. Redacted notifies the sender when a screenshot is taken (on iOS). On Android, Redacted blocks screenshots entirely while in chat. However, no app can fully prevent someone from photographing their screen with another device.

Premium

What does Redacted Premium include?

Extended destruction timers (24h, 7d, 30d, never), priority support, premium badge on your profile, and access to upcoming Premium features.

How much does Premium cost?

A$4.99 per month, A$39.99 per year (33% off monthly), or A$129 once for lifetime access.

How do I cancel my subscription?

On iOS: Settings → Apple ID → Subscriptions → Redacted → Cancel.
On Android: Google Play Store → Subscriptions → Redacted → Cancel.
Cancellation takes effect at the end of your current billing period.

How do I get a refund?

Refunds are handled by Apple and Google, not by Redacted. Contact Apple Support or Google Play Support directly for refund requests within their respective policies.

Security features

What is biometric lock?

Optional Face ID or fingerprint requirement to unlock Redacted. The app locks automatically after 30 seconds in the background.

What is decoy mode?

An optional feature where you can set a second passphrase that opens an empty version of Redacted. If someone forces you to unlock the app, you can enter your decoy passphrase to show a safe, empty version while your real conversations remain hidden.

How do I report abuse or illegal content?

Email support@redactedapp.com with details. We take abuse reports seriously and will investigate within 48 hours. Note: due to end-to-end encryption, we cannot see message content, but we can take action on accounts based on verified reports.

Technical

What encryption does Redacted use?

NaCl (Networking and Cryptography Library) with X25519 elliptic curve Diffie-Hellman key exchange, XSalsa20 stream cipher for symmetric encryption, and Poly1305 message authentication codes. These are well-tested, open cryptographic standards.

Is Redacted open source?

Not currently. We may open-source the client in future.

Has Redacted been independently audited?

Not yet. We are a small Australian indie product. An independent security audit is on our roadmap as we grow.

What if I find a security vulnerability?

Please email support@redactedapp.com with details. We will acknowledge within 48 hours and work with you to address the issue. We do not currently offer a paid bug bounty but credit researchers publicly for responsible disclosure (with their permission).

Legal


About

Redacted is an Australian-made encrypted messaging app.

Built in Australia. Hosted in Sydney.
Answerable to Australian privacy law.