Kryptos

Kryptos

Message encryption using the Kryptos keyboard in your conversations. Incoming ciphertext is decrypted on screen. Messages are visible only to you. Works on top of messaging apps and SMS. Different use cases allow for confidential communication over insecure messaging apps.

Kryptos works natively between iPhone and Android without accounts or servers. Encryption keys are stored on the device.

Download for iOS .ipa file or repository
Through the repository No certificate, just your Apple ID. Updates come on their own.
https://datakeeper.pages.dev/altstore.json
Download for Android .apk file or F-Droid

iOS: the .ipa is unsigned, you sign it on the device. Android: allow installs from unknown sources.

Open source github.com/swisslite/Kryptos Support the project
SHA-256 checksums

.ipa  10ad030b01852130ce829095cd6ff849afb3992d000bd080a9d24196d2edf187
.apk  00c6a3565959498709a4458f30e540df3f9125d63c55ba4706f44e17d854f492

Version history

2.4
2.4 September 21, 2026 Latest
  • IMPORTANT: Installing the new version is recommended. Kryptos 2.4 is not compatible with older versions.

New

  • Brazilian Portuguese
  • The language switch key is now a globe key (you can also switch keyboards by holding the globe key)
  • The iOS app icon is now native
  • Libraries updated to the latest versions
  • Links, email addresses, and phone numbers in decrypted text can now be copied
  • Vibration mode setting
  • Key text size setting
  • Key press enlargement setting
  • The cursor in the keyboard input field can be moved by dragging with your finger
  • Comma key instead of the emoji key; emoji are now available by holding the comma key
  • Chats can now be included in backups
  • Option to disable automatic capitalization
  • Settings are now stored in an encrypted file
  • Third-party keyboards no longer suggest words in Kryptos fields
  • Passwords in “Password” and “Photo” modes must now be at least 6 characters long
  • Code entry is locked after 5 incorrect attempts
  • The keyboard and on-screen decryption are locked 5 minutes after leaving the app
  • When using “Trap Password”, the keyboard is hidden, on-screen decryption is disabled, and access to the camera and microphone is blocked
  • Other changes

Fixes

  • Key flickering when moving the cursor by holding the space bar
  • Disappearing messages were deleted with a delay
  • The lock could be bypassed by setting the clock back
  • The locked keyboard displayed profiles and contacts and allowed switching profiles
  • The “Storage unavailable” screen could erase everything with a single tap without confirmation
  • On-screen decryption displayed text on the locked device
  • Text from disappearing messages remained in the cache
  • The keyboard draft remained visible after locking
  • The keyboard could remember words from encrypted messages
  • File names revealed whether codes had been set
  • Windows and menus were not protected against being overlaid by other apps
  • The app could freeze when handling a large message
  • The mask key is no longer derived from public fingerprints
  • Other fixes
2.3.3 September 3, 2026

What is new

  • Persian language
  • Automatic clipboard clearing is now 1 minute by default
  • The encryption icon on the keyboard has been changed when “Send after encryption” mode is enabled
  • When screen recording or broadcasting, Kryptos hides the conversation and shows a placeholder
  • Before sending decrypted text to another app, Kryptos now asks for confirmation
  • Encryption buttons are disabled in password input fields
  • When decryption is disabled on screen, the service itself is now also disabled; previously, it continued running in the background
  • Voice input has been added to the keyboard
  • The chat header now displays the contact’s key
  • When scrolling up through the conversation, a button to return to the latest message appears
  • Text from Kryptos screens is no longer passed to Android system suggestions
  • “How to use” on the conversation screens is now a link
  • On Android, a “Do not pause the app” option has been added under “Privacy - On screen”
  • Keyboards have been adjusted to the system size. Larger letters, taller keys, wider spacing
  • Double-tapping the period on the keyboard inserts a comma (disabled by default). This can be changed in the keyboard settings in the app
  • App lock has been redesigned

Fixes

  • If you switch to another app immediately after pressing “Encrypt”, the text is no longer inserted into it
  • The public key is no longer automatically removed from the clipboard
  • Large photos no longer cause the app to close when extracting a message from them
  • A message decrypted by the keyboard no longer disappears from the conversation
  • App lock immediately revokes the keyboard’s access to encryption; previously, access remained for several more minutes
  • The delay after entering an incorrect code can no longer be reset by restarting the app
  • Automatic clipboard clearing no longer deletes data copied in other apps
  • The “Copy” button in the on-screen decryption panel now correctly copies the text
  • The keyboard no longer suggests or remembers words in fields for secret phrases and one-time codes
  • The keyboard no longer reports that steganography is unavailable if the message was actually hidden
  • Turning the clock back no longer allows decrypted text to remain in memory longer than intended
  • On-screen decryption no longer lags on screens with a large amount of text
  • Interrupted panic wipe no longer leaves the app on the recovery screen
  • A deleted PGP key no longer reappears after restarting the app
  • The keyboard no longer lags in long conversations
  • When launching Kryptos, it no longer contacts Google services to load the emoji font
  • The emoji panel opens correctly again after switching between light and dark themes
  • Re-adding a contact with the same saved key no longer permanently breaks the conversation in one direction
  • When decryption fails, the app now states the reason if the key has already been used or has expired, instead of displaying a message about an incorrect contact
  • An error in a background task no longer crashes the app together with the keyboard
  • Other fixes
2.3.2 August 17, 2026

What is new

  • Chinese.
  • Profanity, insults and potentially dangerous words are out of all three text steganography modes, in English, Russian and German.
  • 197 such words were removed from the dictionaries and the same number of neutral ones added, so each language still holds 4,096 words.
  • The smart-sentence grammar had 11 words replaced.
  • In the random-letter mode the text is now picked so that no forbidden letter combination appears in it.
  • The Paste and Clear buttons in the keyboard message field are bigger and sit in one row under the field.
  • The size of the keyboard message field is adjustable: small, medium or large.
  • The Kryptos badge on the keyboard can be hidden, and the space it frees goes to the profile and contact labels.
  • Send after encrypting now works in messengers that send with their own button, VK for one.
  • That kind of sending needs the Kryptos on-screen decryption service switched on. Android turns the service off when the app is updated, so switch it on again.
  • A profile can be renamed, any one from the list and not only the current one.
  • A contact can be renamed from the chat list and from the chat menu.
  • A long press on a message in a chat opens a menu with copy and delete.
  • A deleted message is wiped completely: its text no longer shows up in on-screen decryption or in the keyboard.
  • If the storage of one profile cannot be read, the app opens on a working profile and says which profile is unavailable.
  • A failed attempt to open a profile no longer offers to erase all data.
  • Other changes.
  • Covers made by the ordinary-words and smart-sentences modes cannot be read by versions before 2.3.2, so both sides have to update.

Fixes

  • Send after encrypting did not send the message in messengers with their own send button: the text was encrypted and pasted but stayed in the field.
  • The keyboard closed after an encrypted message was sent and had to be called up again.
  • The Paste button did nothing with an empty clipboard and said nothing about it.
  • The area under the keyboard was filled with black instead of the keyboard colour.
  • Switching to a profile with damaged storage closed the app, after which it would only open on the erase-everything screen, even though the keys and the chats were intact.
  • Switching to such a profile from the keyboard silently substituted the contacts and chats of the previous profile and wrote them into the storage of the new one.
  • Storage failures while creating, deleting or renaming a profile, regenerating its key or working with PGP keys closed the app instead of reporting an error.
  • The app could create a new encryption key over existing data and make it unreadable for good.
  • The password stayed in memory after the key had been derived.
  • A copied message was marked as shown even when the keyboard could not open it because of the lock screen, and after unlocking it never appeared.
  • Send after encrypting could press the send button while the app was locked.
  • Words learned by the keyboard were lost for good if they could not be saved.
  • The first send of a message hidden in text froze the interface for about 0.1 seconds.
  • The emoji panel read from storage as it opened and could stutter.
  • Hiding a message in a photo used 80 MB more memory than it needs.
  • Saving a photo with a hidden message could silently do nothing.
  • Settings could open straight on the panic-password screen after the app was restarted.
  • Regenerating a key did not show which profile it was being done for.
  • Other changes.
2.3.1 August 9, 2026

What is new

  • The app is fully translated into German.
  • Keyboard: a QWERTZ layout with ä ö ü ß and its own dictionaries (40,000 frequent words, 177,000 word forms, 640 bigrams), with suggestions and autocorrect at the same level as Russian and English. Nouns are suggested capitalised, the case taken from a corpus that preserves it.
  • Steganography in all three modes: a 4,096-word list, smart-sentence grammar with German word order and cases, and the random-letter mode.
  • The suggestion engine went from two languages to an arbitrary number.
  • The keyboard declares three layouts in the system input-language switcher, and picking one there switches the layout inside the keyboard.
  • Length masking now works in steganography too, in all three modes and all languages. Before this the switch did nothing once steganography was on, and the length of the text could be read straight off the length of the cover.
  • A new keyboard mode on Android: the padlock encrypts the message and sends it in the messenger right away, and a paper-plane badge appears on the padlock. Off by default, switched on in Settings → Keyboard.
  • Other changes.

Fixes

  • Confirmation popups ("Erase all" and ten more dialogs) no longer appear off to one side, they are anchored to the button that opened them.
  • On-screen stego decryption: a sender name that matched a dictionary word (Weber, Richter, Koch) broke parsing and the message would not decrypt. A second bug: a stray word at the end of the node (a timestamp, "Heute") threw away a message that had already been parsed. Added limited resynchronisation and anchoring on the sentence boundary. Affects every language, not only German.
  • The key preview was not covered by the screenshot block and showed even in password fields: on a screen recording of a "protected" keyboard the typed text could be read character by character.
  • An oversized photo or an oversized backup file crashed the app out of memory instead of returning a clear error.
  • The app stalled on launch once every two days, which is when the Signal keys were being rotated.
  • Opening the app with a long text in the clipboard made the interface lag.
  • Holding backspace with two fingers did not stop the deletion.
  • Switching a PGP key and deleting a recipient froze the screen.
  • The illustrated guide loaded every image at once, now they load as you scroll.
  • The keyboard held twice the memory it needed while loading dictionaries.
  • After a profile switch the keyboard showed the decryption from the previous profile.
  • A corrupted backup file wiped the working PGP keys instead of being rejected.
  • Length masking ate up to half the capacity of a photo while hiding nothing: the size of the shot does not depend on the length of the message. It has been removed from photos.
  • App launch waited for the whole message history to be parsed.
  • The message history was re-encrypted and written again on every launch, even when nothing had changed.
  • Picking a photo decoded the whole shot just for a thumbnail, and hiding and extracting ran on the main thread.
  • Key export and import and PGP operations froze with no progress indicator.
  • Regenerating a PGP key took the algorithm from the new-key form.
  • Deleting a PGP recipient happened without confirmation.
  • The pressed-key highlight disappeared from under the finger after the very first letter.
  • A message you had already read stopped opening again after the next 64 arrived.
  • The wording about being offline in the help was made precise: the app opens no network connections.
  • The green clipboard dot on the decrypt button in the keyboard could swallow the tap instead of the button.
  • Other changes.
  • The stego format has changed: messages with length masking on will not open in older builds.
2.3 August 4, 2026

What is new

  • Panic password. A second password that, instead of unlocking Kryptos, wipes everything for good: profiles and private keys, chats, contact keys, PGP keys, the words the keyboard has learned, caches and settings. Afterwards the app opens empty, as if freshly installed. Set it in Privacy. It replaces the old panic PIN and can now be any password, not only digits.
  • App passcode. An ordinary code to unlock the app when you would rather not use biometrics. Both codes are typed into the same field, so the field itself tells nobody whether a panic password exists.
  • Key backup. Your own keys, your contacts' keys and your PGP keys go into a single password protected file that restores on another phone. The file is encrypted with Argon2id and AES-256-GCM and looks like random data from the outside. Chats are not included.
  • A button on the keyboard itself turns the compose field on and off. It sits on the left of the bar, well away from the encrypt button, stays in sync with Settings both ways and can be hidden.
  • About now has a Source code section linking to the repository, and the contacts moved into a separate Developer section.

Cryptography

  • A password is turned into a key with Argon2id (64 MiB, t=3, p=1, the RFC 9106 profile). PBKDF2 is gone from the project entirely. This covers password mode, photo steganography and the lock screen codes.
  • The two Argon2id implementations, the PHC reference library on iOS and BouncyCastle on Android, are checked against all seven official test vectors and give byte-identical results, so a message crosses between the platforms unchanged.
  • Messages encrypted with a password by an older version can no longer be opened: the password token format has changed.

Steganography in photos

  • The container no longer carries a visible signature or the length at fixed positions. Without the password there is nothing in the photo to test against.
  • Bits go only into textured parts of the picture, roughly its noisiest quarter, and nudge brightness by one instead of replacing the lowest bit. That breaks the classic statistical attacks on LSB.
  • Positions are spread by a keyed stream and the length is masked. A wrong password and a photo with nothing in it are now indistinguishable.
  • Photos made by older versions can no longer be opened: the container format has changed completely.

On-screen decryption and the keyboard

  • The main fix: in real messengers on-screen decryption often found no messages at all, because their text is marked as unimportant for screen readers. It finds them now.
  • The decrypted text appears exactly where the ciphertext is, centred on it and as wide as it. It used to be a small window pinned to the top left corner.
  • The panel no longer flickers or rebuilds itself in a loop, it disappears a fraction of a second after you leave a chat, and it does not show up for a message that has scrolled off the screen.
  • The expand button was redone and now appears when the text is really cut off rather than when it is long, so a long message can no longer be trimmed silently.
  • The decryption window on the keyboard was rebuilt: the contact's name in the title, even padding and corners, and long text scrolls inside the window without closing it.

Security

  • Erasing data and the panic password really do clear the settings now. The settings file used to survive untouched.
  • Code hashes live in encrypted storage and are destroyed by the wipe itself, so nothing is left to show that a code was ever set.
  • Checking a code on the lock screen takes the same time whatever codes exist, so the response time cannot reveal whether a panic password is set. After a few wrong tries the delay grows to 30 seconds.
  • The wipe destroys the storage key first, so a wipe interrupted halfway leaves data that nothing can decrypt any more.
  • The clipboard now clears itself in the background. It used to work only while the app was open, which is not when it is needed.
  • Key backup refuses to export at all if any part of the keys cannot be read, instead of quietly writing an incomplete file, and identifiers from an imported file are validated before they become names in storage.
  • The app signature check now fails closed, and strict biometrics is requested where the system supports it.

Fixes and performance

  • Critical: after a screen lock was removed the app could fail to start at all, because the system destroys the hardware key. It now shows a recovery screen with an explanation and a reset button.
  • Disappearing messages: the chosen interval showed up only after reopening the chat, and messages did not vanish while you watched. There is a live timer now, and expired messages are cleared from the keyboard and on-screen caches too.
  • Fixed a memory leak in the screen scanner and a race during the wipe, and a hardware storage failure during a wipe no longer crashes the app.
  • Typing no longer redraws the whole chat screen, the background stopped allocating memory on every frame, and the device integrity check moved off the main thread.
  • On-screen decryption got lighter: cards are reused and invisible areas are skipped.
  • The design has not changed, verified with screenshots.
2.1.1 July 17, 2026

Fixes

  • On-screen decryption (Android) works again. After the move to the new ciphertext format the detector only recognized a message when it was the only content of a screen element — timestamps, read marks or a sender name glued on by the messenger broke recognition. The token is now found inside any surrounding text.
  • Hidden text (steganography) is more robust on screen and when pasting: stray words next to the message ("edited", "PM", a sender name) no longer break decoding — the decoder ignores them, and integrity is still protected by the checksum.
  • The Back button in a chat now closes the chat instead of the whole app (Android).

Performance

  • The screen scanner is heavily optimized: no extra allocations or repeated pattern compilation in the hot path, dictionaries warm up in the background — less load on the phone and battery while you scroll.
  • Clipboard scanning is capped at a sensible size — a giant copied text can no longer freeze the interface (both platforms).

Design (Android)

  • New floating bottom bar: the active tab expands into a labeled pill, with smooth color transitions.
  • Animated chat open and close with an iOS-style parallax.
  • Live touch feedback: buttons, cards and tabs respond with a springy press.
  • Smooth appearance of messages and banners, animated tab switching.
2.1 July 16, 2026

Security & audit

  • Full security audit of both platforms: crypto core, key storage, keyboards, on-screen decryption, PGP, untrusted input handling.
  • Legacy message formats removed (KX1:, BEGIN KRYPTOS MESSAGE and the old password format). Only the new compact format is read and sent — update Kryptos on both sides, messages from older versions can no longer be read.
  • Less code — smaller attack surface: all dead legacy code stripped, no traces of the old formats left in the binaries.

New ciphertext format

  • Ciphertext is now a single line with no predictable prefixes, indistinguishable from random noise: AES-256-CTR whitening over the real Signal cipher, different output every time, even the message type is hidden.
  • DEFLATE compression before encryption — long messages get noticeably shorter.
  • Password mode: compact token without BEGIN/END, the PBKDF2 iteration count is no longer stored in the ciphertext.
  • Messages are detected by token shape instead of a prefix — everywhere: auto-decrypt, chat, keyboards, on-screen decryption.

Length masking — new

  • A toggle in Settings → Privacy → Metadata (off by default): the ciphertext is padded to fixed buckets (64/128/256…), so its length no longer reveals the size of the message. Works for chat and password mode.
  • The format is self-describing — the recipient strips the padding regardless of their own settings; the token length is exactly the bucket size, and the handshake is masked too.

Reliability

  • Fixed a rare decompression mismatch between iOS and Android; full cross-platform compatibility verified byte-for-byte with test vectors.
  • Bounds checks when stripping padding and decompressing — protection against hangs and corrupted data; minor fixes on both platforms.
  • Expanded test suites: 39 iOS + 47 Android + 10 built-in self-checks — all passing.
2.0 July 15, 2026

What's new

  • Smart text steganography: the hidden message is woven into real, grammatically coherent sentences (EN/RU) instead of a run of words. Enabled with a separate toggle in Settings → Steganography and works alongside the regular mode.
  • The sample output right in Settings now updates to match the selected mode and language.

Security & reliability

  • iOS: the profile index and PGP store are no longer overwritten when the keychain is temporarily unavailable — protects profiles and keys if the app launches before the device is unlocked.
  • Android: data that decrypts but fails to parse now raises an error instead of silently regenerating keys — protects identity, metadata, indexes and PGP.
  • Android: closed a tapjacking vector in the on-screen decryption window — the copy and close buttons are now protected from overlay attacks.
  • Internal cleanup: dead code removed, a hidden defect fixed in the Android keyboard source, faster steganography settings handling.
1.1.1 July 13, 2026

Android

  • Fixed a crash on launch on Android 12 when the device has no screen lock (PIN, pattern or password).
  • The master key protection level is now picked automatically: on devices with a screen lock the key still requires the device to be unlocked, on devices without one the app works instead of crashing.
1.1 July 13, 2026

Android

  • Screenshot blocking for on-screen decryption is now a separate toggle in Settings, off by default — it used to block screenshots system-wide while the service was running.

Keyboard (Android & iOS)

  • Autocorrect and suggestions rebuilt from scratch: up to 2–3 typos per word are fixed as you type, accounting for near-key misses, swapped and doubled letters.
  • The correction dictionary grew from ~8,000 words to the full lexicon — about 360,000 word forms for Russian and 110,000 for English; autocomplete now suggests word forms too.
  • Common misspellings removed from the dictionaries — they used to count as real words and block correction; real words, slang and learned words are still never touched.

Text steganography (Android & iOS)

  • New encoding format — hidden text is ~30–36% shorter for the same message.
  • New dictionaries of 4,096 short natural words replace the recognizable BIP39 list; every message now looks different — random masking and sentences of varying length with real punctuation.
  • Added a checksum: plain text and damaged or truncated copies are no longer mistaken for a hidden message. Dictionaries cleaned of crude words.
  • The old steganography format is removed: messages created in version 1.0 cannot be read by 1.1 — make sure everyone you write to updates.

How it works

1

Type a message

Enter a message in Kryptos or using the built-in Kryptos keyboard while in a messaging app. Tap the “”, and the text is encrypted in the message field.

2

Send through any messenger

Send the encrypted text through Telegram, WhatsApp, SMS, or any other messaging app. To a third-party observer, the ciphertext looks like an ordinary string of characters, with no way to recover the contents of the original message.

3

Decrypt on screen

Kryptos decrypts the received ciphertext in the messaging app and displays the original message on screen. The message can also be decrypted through the keyboard or in the app from the clipboard.

Features

Signal Protocol

The same encryption as Signal, using the libsignal library: a new key for each message (Double Ratchet) and protection against future attacks using quantum computers (PQXDH and SPQR). It is also possible to pad message lengths to fixed values to make ciphertext analysis by third-party observers more difficult.

Fully Offline

No internet connection. The app contains no network code, and encryption keys, settings, and chat history are stored locally.

iPhone and Android

A native app for both platforms with full compatibility. Messages, keys, and ciphertext hidden inside images or text work between both sides.

On-Screen Decryption

On Android, Kryptos works over other apps: it detects ciphertext and displays the decrypted text over the ciphertext in the chat. There is no need to copy the ciphertext separately. On iPhone, copied ciphertext can be decrypted by the keyboard from the clipboard or by “” above the keys, or in the Kryptos app, also from the clipboard.

Kryptos Keyboard

The Kryptos keyboard is installed as a system keyboard and is available in any app where text input is used. Enter a message, tap “”, and the ciphertext remains in the input field, ready to send. The keyboard can also decrypt incoming ciphertext above the keys. Suggestions and autocorrection are supported for multiple languages, as well as emoji. The key text size and vibration level can be configured. Other settings are also available. The keyboard works offline.

Steganography

Hide a message inside an image or disguise it as an ordinary set of words instead of obvious ciphertext.

Password and PGP

Use a shared password: agree on a password with another person and exchange information using symmetric encryption. PGP is also supported.

Lock and Clipboard

Biometrics, hiding content in the app switcher, screenshot blocking, and automatic clipboard clearing.

Panic PIN

A separate PIN code that, instead of unlocking the app, deletes all keys, chats, and contacts.

Questions and answers

Do I have to switch to Kryptos to write or read a message?

No. You stay in your own messenger: type the message, tap the lock on the Kryptos keyboard, and only the ciphertext is left in the field. An incoming message is shown decrypted right over the ciphertext on Android, and read by that same keyboard on iPhone. You open the app itself only to add a contact or change a setting.

How does the Kryptos keyboard work?

You enable it once in the system list of keyboards, and it is then available in any app. Pick a contact, type, tap the lock: the plain text in the field turns into ciphertext. Incoming messages are read in the same place: you copy the message and the keyboard shows the decrypted text above the keys with the sender's name. You can also type in a field inside the keyboard itself, and then the messenger never sees the plain text at all. The rest of the time it is an ordinary keyboard, with suggestions and autocorrect for Russian, English, German, Persian and Brazilian Portuguese, pinyin input for Chinese, fully offline.

What is on-screen decryption?

It is an Android feature. You switch the Kryptos service on once in the accessibility settings, and the app then finds its own ciphertext on screen and lays the decrypted text over it while you scroll the conversation. Nothing to copy, nothing to open. The service reads only text that is already on the screen, works only for your contacts, and never while Kryptos is locked. A separate switch blocks screenshots while it runs. The iPhone gives no app that kind of access to the screen, so there the keyboard does the reading.

What do I set up once?

Enable the Kryptos keyboard in the system list of keyboards: on iPhone you also allow it full access, without which it cannot reach the keys. On Android, if you want on-screen decryption, switch the service on in the accessibility settings. And exchange keys with your contact: let them scan your QR code, or just copy your key as text and send it any way you like, through that same messenger if you want. Their key is pasted as text in the same way, no camera needed. That key is the public one and it is safe to show; the private key never leaves the device. After that there is nothing to configure and nowhere to register.

Does my contact need Kryptos too?

Yes, nothing but Kryptos can decrypt the message. Which phone each of you carries does not matter though: the iPhone and Android versions are fully compatible, and keys and messages work in both directions.

Does it need an internet connection?

No. Kryptos has no servers and no accounts, and there is not a single line of networking code in the app. On Android it does not even ask for permission to reach the network. Encryption happens entirely on the device, and delivery is handled by whatever messenger you already use.

Can the messenger read my messages?

No, it only ever gets text that is already encrypted. It does still see that you sent something, to whom, and roughly how much. That is metadata, and Kryptos does not hide it, but you can at least mask the length in Settings → Privacy.

How strong is the encryption?

Chats use Signal's own libsignal library, the same protocol as Signal itself, with post-quantum protection on every message, not just the handshake. Password mode and photos use Argon2id and AES-256-GCM. Kryptos contains no home-made cryptography.

Why is the first message so long?

It carries the post-quantum handshake (PQXDH with Kyber), which is about two kilobytes. It is sent once: as soon as your contact replies, messages become many times shorter.

Why will a message not decrypt a second time?

That is not a fault but forward secrecy: the key for each message is destroyed the moment it is read, so old correspondence cannot be recovered even by someone who takes your phone. Messages you have already opened remain in the chat history.

It says it could not decrypt. What now?

Usually the wrong contact or the wrong profile is selected. If every new message from one person fails, the session has gone out of sync: send them your key again and have them add you a second time.

What is the safety number for?

It is a fingerprint of the key. Compare it with your contact over some other channel, read it out loud for instance. If the numbers match, there is definitely nobody in the middle.

What are profiles for?

A profile is a separate identity with its own key and its own contacts. You can keep several and switch between them, to keep work and private life apart for example.

Can I use one key on two phones?

No. A conversation runs from one device: its key chain cannot advance in two places at once. Move your keys to the new phone with a key backup and then use only that phone.

What happens if I delete the app or lose my phone?

The keys live on the device and nowhere else, so deleting the app destroys them for good and there is nothing left to decrypt with. The only insurance is to make a key backup in Settings beforehand. The flip side of the same property: whoever finds the phone gets nothing either.

Does the key backup restore my messages too?

Only if “Back up chats” was on when the file was made. Otherwise the file carries only your keys, your contacts and your PGP keys.

I forgot the password to my key backup

There is no way to recover it. The file is encrypted with that password and Kryptos keeps no copy of it anywhere. Make a fresh backup with a password you will not forget.

What do disappearing messages actually do?

They erase the conversation inside Kryptos after the time you pick, on your device, and on your contact's if they set the same thing themselves. What they cannot touch is the ciphertext already sitting in the messenger: only the messenger itself can remove that.

Can I send a photo or a file through Kryptos?

No, Kryptos encrypts text only. The Photo tab does something different: it hides a text message inside a picture, rather than sending the picture itself securely.

I hid a message in a photo and it will not open

The photo has to be sent as a file (a document). Sent as an ordinary picture it is recompressed by the messenger, and recompression destroys the hidden data.

What is the panic password?

It is a second password for the lock screen. Type it instead of your normal passcode and the app silently and irreversibly destroys every key, message and setting, then opens as if it had just been installed. You set it up in Settings → Privacy.

Why does the app ask for the camera?

Only to scan a contact key from a QR code. The camera is used nowhere else, and refusing access breaks nothing: you can always paste the key as text instead.

Do my keys and messages end up in the phone's cloud backup?

No. On iPhone the keys sit in the Keychain marked as this-device-only, so they never go into an iCloud or computer backup. On Android the app is excluded from cloud backup and from device-to-device transfer entirely. Everything else is encrypted with exactly those keys, so a stray copy would be unreadable anywhere else.

Requirements

iOS

iOS 17 and later. An unsigned .ipa file is used and signed on the device.

Android

Android 8.0 and later. Signed .apk. Installation requires allowing apps from unknown sources.

Network

Not used. The app runs locally and does not use a network connection.

Languages

Russian, English, German, Chinese, Persian, and Brazilian Portuguese. The interface language is determined by the system language settings.