Guillotine CC
Back to gchat

Security

Updated 14 August 2026

What protects your account, and what does not. Written to be checked.

In transit

Every connection between the app and our server runs over TLS — the WebSocket the app holds open, the HTTP endpoints that move files, and the website you are reading. There is no plaintext fallback.

At rest — the honest part

Message content stored on our server is not end-to-end encrypted. It is technically readable by the server, and therefore by us. We state this rather than implying otherwise, because "encrypted" is a word that is used loosely and it should not be.

End-to-end encryption is a design goal, and when it ships it will be a published protocol — Signal or MLS — rather than something we invented. This page will change on the day that is true and not before.

Passwords

Passwords are hashed with Argon2 and never stored or logged in any recoverable form. We cannot tell you your password because we do not have it. Sign-in can also go through Google, in which case we never see a password at all.

Sessions

A signed-in device holds a session token with an expiry. The session record keeps the sign-in time and IP address for 180 days so that a stolen account can be recognised, and is then deleted along with the address.

Calls

Audio and video travel directly between the two devices over WebRTC, which is encrypted between the endpoints by the protocol itself. When a direct route is impossible — a strict NAT, a mobile network — the encrypted stream is relayed by our TURN server, which forwards packets it cannot read. Calls are never recorded.

Files

Uploads move over HTTPS and a download is authorised by membership of the chat the file was sent to. Media is held in object storage; the same authorisation applies whether a file sits on our disk or in the bucket.

Who else gets anything

One party: Google, which receives a push token so your phone can ring when the app is closed. There is no analytics SDK in the app, no advertising network, no third-party tracker, and no data sold to anyone.

Privacy

Reporting a vulnerability

Write to us. Tell us what you found and how to reproduce it, and give us a reasonable window to fix it before publishing. We will answer.

What this page does not claim

No end-to-end encryption today. No formal third-party security audit. No bug-bounty programme. Those are absences, not secrets, and naming them is the point of the page.