Choosing your protection

Every other messenger picks your security for you and hopes you never ask. YGOOW does the opposite: before a conversation starts, you choose how it is protected — and there is no default. If you don’t choose, you don’t chat. That sounds blunt. It is meant to be.

Why there is no default

A default is a decision made for you, by someone who will not be in the room when it matters. Security you didn’t choose is security you don’t understand — and the moment you need it, “I thought it was on” is not an answer. So YGOOW refuses to guess. You set the level when you open a conversation; the app tells you, in plain words, what each one costs and protects.

If none of it matters to you for a given conversation — that is a real, honest answer too. It just means you don’t need this app for that conversation:

You don’t need anything here protecting your metadata and your words? Send an SMS.

That isn’t an insult. It’s the truth, said once, so you can make a real choice.

The five layers a message passes through

Each layer above the one before it is a deliberate choice, never silent:

  1. Transport (TLS). The basic encrypted pipe.
  2. Tor (on by default). The relay never learns your IP or where you are. Turn it off only on purpose — and the app makes you confirm it, because off means you just handed over your address. Underneath, the traffic itself is shaped so the relay learns as little as possible: blocks are padded to a fixed size, the conversation address rotates on a short clock, and a high-risk mode adds cover traffic to hide when you send.
  3. End-to-end channel. A conversation only the two of you can read, bootstrapped from a key you agreed offline.
  4. Locked content (optional). The words themselves, sealed under a separate secret the channel never holds.
  5. Conditions & lifetime (optional). When a message may be opened (only after a date — a time capsule), how many times before it burns, where it opens (only near a place), and when it disappears — all checked on your device, never by the server.

The three levels you choose from

The choice is per conversation, framed by one question: if your phone were taken, what would it reveal?

1 · Private chat

A normal end-to-end conversation with one person. Fast, frictionless, nothing to manage. Messages you have already sent stay sealed even if your keys are later stolen — the key that wrote each one is used once and erased. For people you trust, about things that need privacy but not armour.

2 · Locked conversation

Everything in Private chat, plus: the content is sealed under a separate secret you choose — a password, a file, a link, or a quorum of people. Take the phone and break the channel, and the words are still locked, because their key was never the channel’s key. The level to reach for when the conversation matters more than convenience.

3 · Locked — nothing stored

The strictest. The content secret lives only in your head; nothing that can open the conversation is written to the device. A seized phone reveals nothing to read, past or future — because there is no key on it to find. It is the strongest answer there is to a phone taken and searched later — though not to a live implant on an unlocked one, the endpoint limit that actually felled EncroChat, never its cipher. The cost is honest: you re-enter the secret each time, and there is no recovery. For the conversation you would protect with your silence.

Inside any locked level you can also seal a single message with its own secret or a quorum — so one line is readable to one person and a sealed block to everyone else, with no error and no hint. That is the property we pull apart in “no oracle”.

Any of these can also carry conditions: a message that won’t open before a date, that burns after a set number of reads, or that only opens near a place. They are enforced by your device, not the relay — an honest policy you can lean on with a willing counterpart, not a chain on someone determined to keep a copy. We draw that line on purpose.

If the phone is taken with you

The three levels above answer “a phone found later.” A phone taken while you’re present — and someone demanding you open it — is a different threat, so YGOOW adds tools aimed at it:

These limit what coercion reveals — a credible denial with no proof against it, not invulnerability: a decoy can’t stop a coercer who keeps pressing. What they also can’t hide is that the app is installed at all — we protect what’s inside, not its existence, and we say so in the trust model.

Which level for which situation

If you are… and you want… choose
two colleagues coordinating privacy without ceremony Private chat
a journalist and a source content that survives a seized phone Locked conversation
sharing one sensitive file or instruction a key only a group together can open Locked, per-message quorum
somewhere the device itself may be taken nothing readable left on the phone Locked — nothing stored

None of these is “the secure one” and the rest insecure. They are different answers to different threats — and YGOOW’s job is to make the trade visible, then let you decide.

One secret, measured honestly

The locked levels rest on the secret you pick — so its strength is the whole game. Whatever form it takes, the app measures its real strength, stretches a weak one with a memory-hard function before it is ever used, and never lets the weakest part hide behind the strongest. A public file or a guessable link is not a secret, and the app will say so. More on that in the trust model.

Your key, your rules — everything else is redacted.