Security · Scenarios and limits

Protecting a conversation also means explaining its limits

Security changes with the conversation, the device, and the person who has physical access.

Reporting channel

Local report builder

Report preparation: 0/4
Open secure email

Everything is prepared in this browser. SmileChatSocial receives or stores none of this content until you send the email.

Subject: [SECURITY] Short summary

Affected page or feature:
Description:
Minimal steps to reproduce:
Observed impact, without accessing other people’s data:
Browser and device:
Strictly necessary evidence:

What we aim to protect

The model considers content reading during delivery, contact impersonation, device loss, and unwanted physical access.

It does not assume a healthy device. An unlocked screen, malicious software, an external capture, or another person’s decision can overcome application controls.

Conversation and identity

End-to-end encrypted private 1:1 chatsConfirmedContacts, invites, and checkingConfirmedSecret Chat v2ConfirmedTemporary messagesWeb BetaOne-use linksPlannedLive Typing with presence controlIn developmentEncrypted calls between peoplePlanned

1:1 encryption, contact checking, and Secret Chat are confirmed. Temporary messages can be explored locally on the website.

One-use links and encrypted calls are planned. Live Typing remains in development when it involves shared presence.

Device protections

Local identityConfirmedAccess PINPlannedBiometric accessPlannedProtected local dataIn developmentLocal clearingWeb BetaDuress PINVisionDecoy profilesVision

Local identity is confirmed. A PIN and biometrics are planned, while local-data protection remains in development.

Web Beta clearing acts only on its local view. A duress PIN and decoy profiles are Vision and do not guarantee forensic protection.

Recovery without hiding risk

Encrypted backup and recoveryConfirmed

Encrypted-backup recovery is confirmed. Its security also depends on the credential, the device, and custody of recovery material.

Final documentation must explain device changes, lost credentials, partial failure, and actions that cannot be undone.

Limits that always matter

No feature is presented as invulnerable, absolutely anonymous, or able to erase every trace across all systems.

Controls reduce specific risks. They do not replace device updates, screen locking, care with links, or checking sensitive identities.

Responsible reporting

Email smilechatsocial@gmail.com with [SECURITY] at the start of the subject. Include a summary, affected page, minimal steps, impact, and only the evidence needed.

Do not perform volume testing, social engineering, persistent access, data alteration, or attempts involving other people’s accounts. No reward or response time is guaranteed.

SmileChat newsletter

Follow SmileChat's development

Leave your email to request SmileChat updates when delivery becomes active.

You are in controlYou can withdraw your request at any time from this same block. The controller’s legal identity is pending confirmation.

Withdraw a request