Technical overview

How Pigeon works, in detail.

This page is for engineers, security researchers, and anyone who wants more than “it’s encrypted.” It covers the protocols, what our servers can observe, how the Bluetooth mesh routes messages, and where the gaps are today.

Updated 28 September 2026 Closed beta

01Summary

Pigeon is an end-to-end encrypted messenger with two delivery paths: the internet, and a Bluetooth Low Energy mesh between nearby phones. Both paths carry the same ciphertext produced by one message core. Encryption happens above the transport, so neither our servers nor mesh relays ever hold keys that can open a private message.

1:1 messages
Signal Protocol (PQXDH + Double Ratchet)
Groups
Sender Keys, up to 256 members
Media
AES-256-GCM, encrypted on device
Backups
Argon2id → AES-256-GCM
Voice calls
WebRTC DTLS-SRTP, sealed signaling
Offline transport
BLE GATT mesh, up to 7 hops
Server sees
Opaque envelopes and routing metadata
On failure
Fail closed, never “best effort” decrypt

02Architecture

The client is a single Flutter app for Windows, macOS, iOS, and Android. Messages are sealed into an envelope by a shared message service, then handed to whichever transport is available. The envelope keeps a stable ID across both paths, so a message sent over Bluetooth can later sync to the cloud without duplicating.

Nearby messages are held in an outbox. When the device reconnects, they upload by the same envelope ID, and your other devices and the recipient merge them into the same chat.

03Cryptography

We use proven protocols rather than inventing our own. The Signal Protocol implementation is the official libsignal library.

UseConstructionNotes
1:1 chats (cloud and Nearby)Signal PQXDH + Double RatchetPost-quantum key agreement (Kyber prekeys). Forward secrecy and post-compromise recovery.
GroupsSender Keys distributed over pairwise Signal sessionsUp to 256 members. Sender keys persist across restarts.
Public channelsEd25519 signatures on postsPublic by design; signatures prove authorship.
Private channelsShared AES-256-GCM key, admin-controlledKey distributed inside E2EE envelopes.
AttachmentsAES-256-GCM, fresh key and nonce per fileKeys travel inside the message envelope, never to the API.
BackupsArgon2id key derivation → AES-256-GCMPassphrase never leaves the device.
Device identityEd25519 device key + device-bound tokensRevocable per device.
Key storageKeychain, Android Keystore, Windows secure storageKeys leave secure storage only in memory for crypto operations.

Verification

Every conversation has a safety number that both people can compare or scan as a QR code. Before a first Nearby chat, Pigeon requires the two people to verify safety numbers in person. There is no silent trust-on-first-use over the radio.

Failing closed

If a signature doesn’t verify, a session is missing, or an envelope type is unknown, the message is rejected. Release builds contain no switch that disables encryption or falls back to plaintext.

04Server and metadata

Our servers are a delivery service for sealed envelopes. They cannot read messages, and we don’t want them to. They do see some metadata, and we’d rather be clear about it.

DataServer can see?
Message text, media, call audioNo. Ciphertext only.
Encryption keysNo. Public prekeys only.
Who a message is addressed toYes, to route it.
Who sent itYes. We do not use sealed sender yet.
Timestamps and ciphertext sizesYes.
Group membershipYes, to fan out envelopes.
Account identifiersUsername, and phone or email if you add one.
Contact list or address bookNo. We don’t upload it.
  • Push notifications sent through Apple and Google contain only “New message” or “Incoming call.” No text, sender name, or call details.
  • Retention. Undelivered envelopes expire after 30 days on the free plan and 365 days on Plus.
  • Logs record metadata such as IDs and sizes. Message plaintext is never logged, and there is none to log.
  • Transport. TLS everywhere, with certificate pinning in release builds.
  • Blocks are enforced server-side and we never record the reason.

05Media, backups, and calls

Attachments

Photos, files, and voice notes are encrypted on the device with a fresh key. Only the ciphertext is uploaded. The key rides inside the end-to-end encrypted message, so our storage holds unreadable blobs.

Backups

Backups seal your conversations and local message history with a key derived from your passphrase using Argon2id. We store the ciphertext. Without the passphrase, neither you nor we can recover it.

Voice calls

One-to-one voice calls use WebRTC with DTLS-SRTP. Call setup (SDP and ICE) is sent as a sealed Signal message, not in the clear. When a direct connection isn’t possible, audio relays through our own TURN server, which sees encrypted packets only. Noise suppression runs on the device, with no cloud processing.

06Nearby mesh in detail

Nearby delivers already-encrypted envelopes over Bluetooth Low Energy when there is no internet. It is opportunistic: it works best in dense groups of people who have Pigeon and have Nearby turned on.

Transport

iOS, macOS, and Android run dual-role GATT, advertising and scanning at the same time. Windows runs as a central only, so it can connect to phones and Macs but can’t be discovered by other Windows PCs. Frames are fragmented to fit the negotiated ATT MTU.

Discovery and first contact

A signed-in device broadcasts a single-hop identity beacon so nearby contacts can find it. Before a first Nearby chat, both people verify safety numbers in person. After that, Nearby messages use the same Signal session as cloud messages. A Noise XX handshake for radio-only first contact is designed but not yet shipped.

What a relay sees

A relay handles a mesh frame containing the Signal ciphertext plus routing metadata: a message ID, TTL and hop count, and conversation and sender routing fields. It can forward, delay, or drop a frame. It cannot read or alter the message without detection.

Routing

  • TTL: 7 at origin, clamped at 8, and reduced in dense areas to limit flooding.
  • Relay jitter: random 10–220 ms delay before forwarding, to reduce collisions.
  • Fanout: relays forward to a subset of neighbours rather than everyone.
  • Dedupe: message IDs are remembered for about five minutes, so loops die out.
  • Sync: when the internet returns, envelopes upload by ID and merge with the cloud copy.

Range

ScenarioRealistic reach
Single hopAbout 10 m, roughly a large room. Less through walls and bodies.
Festival or stadium crowdAcross a section of the grounds, if enough people nearby have Nearby on.
Park or trail groupWithin your group and anyone in between.
Across townNo. Nearby isn’t a city-wide network.

Platform status

PlatformRoleStatus
AndroidDual-role GATTWorking
iOSDual-role GATTForeground best
macOSDual-role GATTWorking
WindowsCentral onlyScan and connect

Limits we want you to know about. Nearby is not a replacement for emergency services. Delivery isn’t guaranteed. Store-and-forward couriering, where a phone carries a message until it meets the recipient later, isn’t built yet. iOS restricts Bluetooth in the background, so Nearby works best with Pigeon open. People nearby can observe that Bluetooth traffic exists, along with its timing and size.

07Threat model

What we design against, and what an attacker in each position could still learn.

AdversaryCanCannot
Network eavesdropperSee that you connect to Pigeon, and traffic volumeRead messages or learn who you talk to from packet contents
Malicious or compelled serverRead the database, logs, and storage: routing metadata and ciphertextDecrypt messages, media, backups, or calls
Compromised mesh relaySee, delay, or drop frames and their routing fieldsRead or undetectably modify messages
Local radio observerSee Bluetooth adverts, identity beacons, timing, sizes, and proximityRead message contents
Device thiefAccess an unlocked, unprotected deviceOpen Pigeon if app lock is on; open backups without the passphrase

Out of scope today

  • Anonymity from our server. Pigeon is not a mixnet.
  • Sealed sender, so the server does see who sent an envelope.
  • A compromised device, such as malware that reads the screen after decryption.
  • Guaranteed Bluetooth delivery, or resistance to deliberate radio jamming.

08Status and known gaps

Pigeon is in closed beta. We would rather list what’s missing than let you assume it’s there.

AreaStatus
E2EE 1:1 and group messagingWorking
Encrypted media and backupsWorking
1:1 encrypted voice callsWorking
Nearby mesh: multi-hop, TTL, jitter, dedupeLanded
Nearby ↔ cloud sync by envelope IDLanded
Radio-only first contact (Noise XX)Planned
Store-and-forward courierPlanned
Sealed senderPlanned
Video and group callsPlanned
Independent security auditBefore public launch

09Reporting a vulnerability

If you find a security problem, email [email protected] with Security in the subject. Include steps to reproduce and the app version. Please give us a reasonable chance to fix it before disclosing publicly. We’ll reply, keep you updated, and credit you if you’d like.

For the plain-language version of this page, see Security. For what we collect and why, see the privacy policy.