Messy privacy policy
Last updated: 28 September 2026
Messy is a private messaging app run by one person for a small circle of friends. There is no company behind it, no advertising and no analytics. This page says what the app and its server keep, for how long, and who can see it.
What is encrypted
Messages, photos and captions are encrypted on your phone before they are sent, using a key that only the phones in the conversation hold. The server stores and forwards the encrypted copy and cannot read it. The same is true of:
- Messages you schedule to send later, the words of an auto-reply, and a duress alert. Each is encrypted on your phone before the server holds it.
- The new words of a message you edit.
- A YouTube link preview: the link, the video’s title and its thumbnail travel inside the message, encrypted like a photo.
- Which picture a chat uses as its background.
- A poll’s question and choices, and every vote on it: which choices each person picked. Everyone in the chat can see who picked what, as the poll says before it is sent.
- A screenshot notice, the line a chat shows when someone takes a screenshot there or tries to: whether it was of the chat or of one photo, which photo, and whether their phone stopped it. The app sends one from the version after 0.2.4 (see On your phone).
- A voice note: its sound, how long it is, and the shape of its sound that its bubble draws.
- The optional “spoons” energy status: the level, any note and any tags are encrypted for the people you chose, and the server keeps only the latest encrypted copy.
Before a photo or GIF is encrypted, the app takes out the details its file can carry besides the picture, such as where and when it was taken and on which phone. It keeps only what the picture needs to be shown as it looks: its colours, its frames and which way up it goes. A picture the app cannot do this for is not sent.
What the server can see
The server necessarily knows some things in order to deliver messages:
- Your display name and your short handle (the code friends use to add you). Use whatever name you want to be called. It doesn’t have to be your legal name.
- Every display name your account has had: the name it was created with, and each change since, with the name before and after it, when it was made, and whether you made it or the person running the server did. It is kept so that the person running the server still knows who you are after you change your name. Only they can see it, in the server’s admin tools; it is never sent to your phone or anyone else’s. Your friends’ phones are told only the new name, and show where it changed in their chat with you, with the name you had before, which they already knew. A phone that knows two people by the same name, or by names that look alike, says so beside each of them, with their code.
- To keep one person from passing for another, the server compares a new name with the names of your friends and of the people your friends know, and refuses one that is the same or looks the same. So a friend of one of your friends who tries to take your name is refused. They are not told whose name it is, and each such try uses up one of the five changes they may make that day, so names cannot be tried one after another to find out whom your friends know. Someone you have blocked cannot find out a name you took since by trying it.
- Which conversations exist and who is in them. The names given to group conversations, and the name each member goes by in a group, are not encrypted. Members of a group who are not already your friends see you only by the name you chose for it, not by your usual name or your code.
- Group invitations: who invited whom to which group, and when, while the invitation waits for an answer; and, if you decline one, that you declined that person’s invitation to that group.
- Who has blocked whom, and since when.
- How long each chat’s messages last after everyone has read them, and who last changed that and when.
- Which chats you have muted, and until when; not when you muted them, or from which phone.
- When messages are sent, their size, who they are addressed to, whether one carries a photo and the photo’s file type, which earlier message a reply answers, and which messages are auto-replies or duress alerts. It can tell that a message carries a YouTube link preview, because it has both words and a picture, but not which video: the picture is padded to one of two fixed sizes before it is encrypted.
- Which messages have been edited, when each was last edited, and the size of the new words; not what a message said before or after.
- That a message is a poll, a vote on one, or the poll’s creator closing it, and which poll a vote or a close is about: so who voted on which poll, and when, but not the question, the choices, or what anyone picked. Each is padded to one of a few fixed sizes before it is encrypted, so its size says nothing finer.
- That a message is a screenshot notice, and so who sent one in which chat and when, but not whether it was of the chat or of a photo, which photo, or whether the screenshot was taken or stopped. Every notice is padded to the same size before it is encrypted.
- That a message is a voice note, and the size of its sound, which is padded to one of a few sizes before it is encrypted, so that it says roughly how long the note is, to within about a quarter, and nothing finer. Not a word of it.
- How far each person has received and read in each conversation, and that someone is typing (passed on as it happens and never kept).
- Emoji reactions: which emoji, who reacted, and to which message. Reactions are not encrypted.
- Which devices belong to your account, the name each device was given (such as “Kim’s iPhone”), and for each one: a public key, whether it is an iPhone or an Android phone, its notification address, when it last connected, which version of the app and which optional features it has, when its sign-in token was last replaced with a new one, whether and when the person running the server checked it, and, once it is cut off, whether they were the one who cut it off.
- If you schedule a message: which chat it is for, which of your phones scheduled it, when, and when it will be sent, but not what it says.
- If you turn on auto-reply: that it is on, until when, and which of your 1-on-1 chats it answers, but not what it says.
- If you set a duress alert: that the phone has one, which chats it goes to, and when you last saved it, but not what it says. If it is ever sent, the server knows from that that the phone’s duress PIN was used.
- That a chat has a background, and who changed it and when, but not which picture.
- In games, who starts and joins a game, and each player’s move once the round reveals it. Games are held in the server’s memory and never written to its database.
- If you turn on the spoons status: who you chose to share it with, when you updated it, and your daily reset time, but not the level or note.
- Your IP address while the app is connected, as with any internet service.
What is kept, and for how long
- Encrypted messages and photos are deleted from the server three days after everyone in the conversation has read them (or one day, or one hour, if someone in the chat chose that before they were sent), and after 30 days if someone never reads them. Each phone is sent the deadline when it is set, and told when the server deletes the message; a phone that is not connected at the time is told the next time it connects. For that, and so that a phone sending the message again, because it never heard that it arrived, cannot bring it back, the server keeps a deleted message’s id, its place in the chat and when it was deleted until 30 days after the message was sent, and nothing else about it. Each phone deletes its own copy at the deadline it was given, or, if it was never given one, 30 days after the message was sent, even if it never connects again. A phone whose app has not taken the update of 27 September 2026 is not told of a deadline or a deletion it missed, and does not delete a message it was never given a deadline for, so it keeps such a copy until the app is unpaired or deleted.
- Messages you unsend are deleted from the server at once, and from other phones at once or the next time each one connects, as long as that is within 30 days of when the message was sent. Until then the server keeps only the message’s id and its place in the chat, so that it can tell them, and does not take the message again if a phone sends it again; not who unsent it, and not what it said.
- When you edit a message, the server puts the new encrypted words in place of the old ones at once and keeps nothing of the old ones, and every phone in the chat does the same with its copy, at once or the next time it connects. Your own phone keeps the old words only until the server has taken the new ones. With the message, the server keeps when it was last edited and an id your phone gave that edit, so that the edit sent again changes nothing; they are deleted with the message.
- A poll, each vote on it and its closing are kept and deleted like messages, on the disappearing-messages setting the poll was sent under, and a poll that is unsent or deleted takes every vote on it with it. When someone changes their vote, the server deletes their earlier one at once, keeping only its id and its place in the chat, as for a deleted message.
- A screenshot notice is kept and deleted like a message, on the chat’s disappearing-messages setting.
- A voice note is kept and deleted like a message with a photo: its sound is deleted from the server with it, and is not in the backup (below).
- A scheduled message is kept for at most 7 days, until it is sent or cancelled. It is sent at its time even if the phone that scheduled it has been unpaired, cut off by the person running the server, or wiped with a duress PIN. Only Cancel, from any of your paired phones, stops it, or removing or blocking the person it is for, or leaving the group it is for, which take it with everything else you sent there. Once sent, it is an ordinary message.
- An auto-reply is kept until the time you chose or until you turn it off. Unpairing the phone that turned it on turns it off too.
- A duress alert is kept until it is sent, and deleted as it is sent. Turning it off, removing the duress PIN, turning off the PIN lock, unpairing the phone, or the phone being cut off by the person running the server deletes it unsent.
- A block is kept until you unblock. What a person you blocked sends you in your 1-on-1 chat is kept but never delivered: it is deleted when you unblock them, or after 30 days like any message nobody reads. A change they make there to how long its messages last is kept too, and never takes effect: only their own phones show it, until you unblock them, when it is deleted. So is an emoji reaction they add there meanwhile: only their own phones show it, and it is deleted when you unblock them. If you change your name while the block lasts, the name you had when you blocked them is kept with the block, and is the one they go on seeing, until you unblock them, when it is deleted and they are sent the name you have then.
- The note that your display name changed, and when, is kept for a day, which is what the limit of five changes a day counts, and is then deleted. So is the note that you tried a name and were refused because someone your friends know has it: when, never the name. The record of every name your account has had (above) is kept for as long as your account is, and is deleted with it.
- A mute is kept until the time you chose or until you turn the chat’s notifications back on, and is deleted when you leave that chat.
- A group invitation is kept until it is answered, or withdrawn because the member who sent it left, a block came between the two of you, or the group ended. A decline is kept, with no time, until you join that group or it ends. The name you go by in a group is kept until you leave it.
- A spoons status is deleted at your chosen daily reset time.
- Your account (your name, handle and devices, with their keys and notification addresses) is kept until you delete it, in Settings → Delete account, or the person running the server does, which you can ask them to at any time. Deleting it unsends everything you sent: from phones that are online at once, and from the rest the next time each one connects, as long as that is within 30 days of when the message was sent, as for any unsend. The one exception is a duress alert you already sent, which stays with the friend it went to: if it has not reached them yet, your devices are signed out at once, and the rest of your account is deleted once it has, or once it has expired as any message does. Your polls take everyone’s votes on them with them, as when you unsend a poll. You leave every group, and your 1-on-1 chats stay on your friends’ phones, under the name they knew you by, with only what they sent, closed; an app that has not taken the update of 27 September 2026 removes such a chat instead. Along with your account the server deletes your group memberships and the names you went by, invitations to and from you and your declines, blocks by and of you, your mutes, the notes that your name changed and the record of every name you had, anything waiting to be sent (scheduled messages, an auto-reply, and a duress alert, which is not sent), the backgrounds you chose and the photos you sent, and what it noted about your devices and the old sign-in tokens it kept for them. Your reactions to other people’s messages are taken back from phones online at the time, and by your friends’ phones when they next connect; another group member’s phone that was away keeps one until the message it is on goes. The server keeps only the random number that stood for your account and when it was deleted, so that it stays deleted (see The backup). Its log records the same, for 14 days. So does the record the person running the server keeps of what they do with its admin tools, which names that number, never your name, beside anything they did for your account before, such as making you an invite code, for as long as they keep it.
- Your phone’s notification address, and the key its notification codes are made with (below), are deleted from the server when the phone is unpaired or cut off.
- If the server sees one of your devices connected twice at the same time, which one phone cannot do, it keeps the IP addresses the two connections came from with that device, so the person running the server can look into it. They are deleted from the device’s record once that person has, and are never in the backup. The server’s log notes them too, and keeps them for 14 days (below).
- If the server sees a sign that something other than your phone is using one of your devices’ sign-in (connected twice at once, a new encryption key, a second revoke token asked for, or an old sign-in token tried), it notes with that device what it saw and when, shows it to the person running the server, and tells all your paired phones, which show it until that person has looked into it. The note is kept with the device’s record.
- When a phone replaces its sign-in token with a new one, which every phone does once, the server keeps a one-way hash of the old token with that device, so that it can recognise the old one if anything tries it again. It is deleted when the device is unpaired or cut off, or your account is deleted.
- The server’s log, which stays on that computer, records the IP address a phone is paired from, with your name and the name given to the phone, and the IP addresses of refused, failed or suspicious connections. Each day’s log is deleted 14 days later.
- The relay server, which passes the encrypted connection between your phone and the server without being able to read it, logs the IP address of every connection, when it was made, how long it lasted and how much data went each way. That includes the check for app updates the app makes each time it starts. That log is also deleted after 14 days.
The backup
The server keeps everything in one file on one computer, so a copy of it is encrypted and sent to off-site storage every night. It is encrypted before it leaves that computer, with a key the storage provider does not have. Copies are kept for about a month; a few of the most recent are always kept whatever their age, so there is never a stretch with nothing to restore from.
A backup holds no messages at all. Not the ones everyone has read, not the ones nobody has read, and not the ones you unsend. Every message is taken out before the copy is made, so no message you write is ever in off-site storage, for any length of time. Nor are reactions, scheduled messages, auto-replies, duress alerts, spoons statuses, which chats people have muted, who changed their name that day or tried to, when anyone’s name changed or who changed it, the ids kept of deleted and unsent messages, the IP addresses of a device seen connected twice, or the keys notification codes are made with.
Everything else is in it, chiefly: account details (names, the name each account was created with and every name it has had since, in order, handles, and each device’s name, public key, notification address, iPhone or Android, app version, when it last connected, and one-way hashes of its sign-in token and of any it replaced), invite codes not yet used, which conversations exist, what group conversations are called, who is in them and the name each member goes by, group invitations still waiting and declines, how long each chat’s messages last and who last changed that and when, how far each person has read in each conversation, who has blocked whom and any change a blocked person made meanwhile to how long their chat’s messages last (and, where a blocker has changed their name since, the name they blocked with), and chat backgrounds, still encrypted. These are the things that could not be rebuilt if the computer were destroyed.
So a backup restored after a failure brings everybody’s account and every phone back, and brings the conversations back empty. That is the same thing that happens to a message at most three days after everyone reads it; the backup simply does not keep one for longer than the server does. Anything scheduled, any auto-reply, any duress alert and any mute would have to be set again.
Besides the nightly backup, the person running the server can take a copy by hand, on that same computer, before changing something. It is not encrypted and goes nowhere else. It holds everything, messages included, but not spoons statuses, scheduled messages, auto-replies, duress alerts or mutes, and it is kept until they delete it.
A deleted account, with the record of every name it had, stays in the copies made before it was deleted until those are deleted: about a month for the nightly off-site ones, which never held its messages, and for as long as the person running the server keeps a copy taken by hand, which may. So that putting one of them back does not bring anyone back, the server keeps a list of the accounts deleted, with only each one’s random number and when. The list is in every copy made after a deletion, and also in a file beside the database, which putting a copy back does not replace; as it starts, before any phone can connect, the server deletes again any account on the list that a copy brought back. Only a copy from before a deletion, put back on a new computer with no later list beside it, would bring that account back, until the person running the server deletes it again.
On your phone
From the version of the app after 0.2.4:
- Screenshots and screen recording. On Android, the app cannot be screenshotted or recorded, and it is blank in the list of recent apps. An iPhone lets no app stop a screenshot, so there the whole app goes black whenever the screen is being recorded or shown on another screen in any way, whether a screen recording, AirPlay to a TV or a Mac, or iPhone Mirroring; it shows one plain colour in the app switcher instead of your chats, and closes the keyboard first, so neither the keyboard nor the words it suggests from what you are typing show there (it closes it whenever the app stops being the one in use, even when you only pull down Notification Center or Control Center; what you typed stays in the box); and photos are left out of screenshots as far as the iPhone allows it; the words of a chat are not. When someone takes a screenshot in a chat on an iPhone, or tries to on an Android phone that tells the app about it, the chat is sent a screenshot notice (above). The phone’s system only tells the app that a screenshot happened; the app never sees the picture. On Android 12 and older, if you let the app see your photos so you can send one, it checks the name of each new picture saved while it is open to see whether it is a screenshot; the name is not kept or sent anywhere.
- Backups of your phone. On an iPhone, what the app keeps on the phone (your messages, who you talk to, your chats and when anything was sent) is left out of iCloud and computer backups. On Android the app is left out of Google backups altogether. A backup made before this version still holds what it held until it is replaced or deleted.
- Keyboards. On Android, the app asks your keyboard not to learn what you type in a message, a poll, an auto-reply or a duress alert, a search or a spoons note. A keyboard can ignore that request. An iPhone offers apps no such request.
Notifications
The app asks for permission to show notifications once, right after you pair it, and after that only when you tap Background notifications in Settings. (On Android 12 and older, apps may show notifications unless you turn them off in the phone’s settings, so there it does not need to ask.) Once it may, the phone gets a notification address from Apple or Google, has Expo’s push service turn it into one the server can use, and gives that to the server. Expo sees your IP address when the phone asks it, which it does again only when something has changed.
The server sends each notification through Expo’s push service, which passes it on to Apple or Google. Expo, Apple and Google see your phone’s notification address, when each notification was sent, and a short code that only your phone can turn back into the conversation it is about. Your phone’s code for a conversation is different from anyone else’s, so the codes do not tell them which phones share a conversation; they can tell that two notifications to your phone with the same code are about the same one of your conversations. The notification itself never contains a message, a name, or a spoons level; it only says that something new is waiting.
A chat you mute is sent no notification at all until the mute ends: the server wakes none of your phones for it, so Expo, Apple and Google see nothing about it either. The one exception is a duress alert, which wakes your phones with the same notification as any message, because it is meant to reach you at once. Its messages still arrive whenever the app connects, and still count as unread.
A screenshot notice wakes no phone at all, muted or not, and is not counted as unread: it is in the chat the next time the app connects.
The microphone
The app asks to use your phone’s microphone the first time you record a voice note, and not before. It uses it only while you are recording one: from when you press the mic until you let go, send it or discard it, for at most two minutes; at two minutes the recording stops for good. It never records in the background: leaving the app or the chat, or the app locking, stops a recording and throws it away, and so does a call, or anything else on the phone that takes the microphone while you record.
While you record, your phone keeps the sound in a temporary file in the app’s own storage, which is how the phone’s recorder works. When you finish, the app reads it into memory, deletes the file at once, and encrypts the sound before anything leaves the phone. A recording you cancel or discard is deleted without being read.
To play a voice note, the app fetches it encrypted, decrypts it in memory, and writes it to a temporary file for the phone’s player, since the player plays only from a file. That file is deleted as soon as the note stops, finishes or another starts, and when the app goes to the background or locks. The last few voice notes you played stay decrypted in the app’s memory, so that playing one again needs nothing fetched, until the app locks, is unpaired or is closed. None of these files is in your phone’s backups.
You can turn the microphone off for Messy in your phone’s settings at any time; everything else in the app works without it. The app asks for no other permission to do with sound.
YouTube link previews
Off unless you turn them on, in Settings, on each phone. When they are on and you send a link to a YouTube video, your phone asks YouTube for that video’s thumbnail and title and sends them with the link, encrypted. YouTube sees your phone’s IP address, which video, and when; no cookies are sent or kept. If that takes more than a few seconds, the link goes without a preview. Nobody else’s phone contacts YouTube to show the preview you sent; tapping it opens the video in YouTube’s app or your browser.
Invite links
An invite code can be sent as a link, https://chat.tlbmiss.com/i followed by “#” and the code. The code is the part after the “#”, which browsers and phones never send to any server, so opening the link does not give the code to the server or to the relay. A phone that opens the link without the app is shown a short page by the server, the same for everyone, which cannot show the code because it is never sent it; the server keeps no record of that, and the relay logs the connection as it logs every connection (see above). The code reaches the server only when you pair with it, as a typed code does. On a phone with the app, the link fills the code in and pairs only when you tap to pair.
For links to open in the app rather than the browser, phones check that the server allows it: an Android phone checks when the app is installed or updated, itself or through Google, and iPhones ask Apple, whose servers fetch the answer from the server. What they fetch names the app and nothing about you.
Screen lock
The app asks your phone whether it has a screen lock (a passcode, PIN, pattern or password), so that Settings can warn you if it has none. It learns only yes or no, never the lock itself, and the answer stays on your phone: it is not sent to the server or anyone else. On Android, asking needs the permissions to use biometric and fingerprint hardware, which the app uses for that question only; it never asks for your fingerprint or your face.
Who else is involved
Almost nobody. There are no third-party services other than Apple’s and Google’s notification systems and Expo’s push service, described above; YouTube, only if you turn on link previews, described above; Apple and Google checking that the app may open invite links, described above; the company hosting the relay server; and Cloudflare, which stores the encrypted nightly backup and cannot read any of it. No data is sold, or given to anyone for their own use.
Your choices
- You can unpair a phone from Settings at any time; this deletes the local copy of your messages from that phone. Messages you scheduled still go at their time; cancel them first if you do not want them sent.
- You can delete your account, in Settings → Delete account, or ask the person running the server to. The app asks for your PIN first, if you set one, and for you to type “delete my account”. The server does not take it from a phone it has flagged as having a login something else may hold. Once the person running the server has checked one of your phones, or while the server has flagged one, it takes it only from a phone they have checked, even if the one they checked has been flagged or unpaired since: only they can change that. The app says so when it refuses, and to delete from another phone or ask them.
- The spoons status is off unless you turn it on, and you can turn it off or clear it at any time.
- YouTube link previews are off unless you turn them on.
- The microphone is used only if you record a voice note, and you can turn it off for Messy in your phone’s settings.
- You can cancel a scheduled message from any of your paired phones, and turn off an auto-reply or a duress alert at any time.
- You can block someone. They are not told, though they may work it out: their messages to you stay at one tick, and your code no longer works for them.
- You can mute a chat for an hour, 8 hours, a week or until you turn it back on. Nobody else is told.
- You can change the name your friends see you by, in Settings → Your name, up to five times a day. Use whatever name you want to be called; it does not have to be your legal name. Your friends are told, in their chat with you; groups keep the name you chose for each. The person running the server can see every name you have had, until your account is deleted.
Contact
Contact the person who invited you, who runs the server, or email support@tlbmiss.com.