The relay cannot read your messages
Content is sealed on your device with X25519 key agreement and XSalsa20-Poly1305 authenticated encryption before it is sent. The server holds no key that opens it.
About
That is the design, not a slogan. Everything Benda protects, it protects by making the relay technically incapable of helping — rather than by promising it will not.
Content is sealed on your device with X25519 key agreement and XSalsa20-Poly1305 authenticated encryption before it is sent. The server holds no key that opens it.
No phone number, no email, no profile. You are a randomly generated identifier and a six-digit PIN.
The keypair is sealed with PBKDF2-HMAC-SHA256 at 200,000 iterations and AES-256-GCM. It is never transmitted, and there is nothing to reset.
Deletion is immediate once every device acknowledges delivery, and nothing outlives the room’s time-to-live regardless.
Most messengers ask you to trust a company. Benda is built so that trust is not needed: encryption happens on your device with keys the relay never receives, so there is no readable copy of your messages to hand over, sell, or leak.
Benda is not open source, and that is fair to hold against us — you cannot audit the client yourself. What we offer instead is a design that fails safe, and behaviour you can check: no ads, no trackers, no account, nothing to sell.
Benda is a non-profit project. Voluntary donations cover the relay; there are no ads, no subscriptions, and no data to sell.
Security reports to TODO@TODO.