Dmessenger 隱私政策
生效日期:2026-09-10 · 最後修訂:2026-09-10
Dmessenger 是一款端對端加密的即時通訊 app,由 Nadrix(下稱「我們」)開發並營運。這份政策說明 app 會處理哪些資料、放在哪裡、誰看得到。我們的做法可以用一句話概括:能不收的就不收;收了的,我們自己也讀不到。
1. 不需要帳號
使用 Dmessenger 不需要註冊,也不需要提供手機號碼、電子郵件或任何個人資料。你的身分在你的裝置上產生:一組私鑰與一個由公鑰導出的地址(dm1… 開頭)。這個地址就是你的聊天 ID,我們無法把它對應到任何真實身分。
2. 留在你裝置上的資料
以下資料只存在你的手機裡,不會上傳:
- 私鑰與 12 個字的助記詞。助記詞是唯一的恢復途徑;我們沒有備份,忘記密碼也無法幫你救回(見第 8 節)。
- 訊息、附件(照片、語音、檔案)與加密會話。這些用你的密碼派生出的金鑰(Argon2id)加密後存放,沒有密碼打不開。
- 聯絡人、群組與你幫聯絡人取的暱稱。同樣加密存放。
- 本機偏好:你自己的顯示名與頭像、主題、桌布、通知開關。⚠️ 這一類偏好在裝置上是未加密的,解鎖 app 之前就讀得到(身分清單上顯示的名字就是這樣來的)。訊息內容、助記詞與加密會話不在此列,它們始終是加密的。
- Face ID/Touch ID 解鎖(可選):開啟後,解鎖 vault 的金鑰會存進 iOS 鑰匙圈,受生物辨識保護、只在這台裝置、不進 iCloud。密碼本身從不儲存。
刪除身分(設定 → 切換身分 → 刪除)會把以上資料全部從裝置上清除。
3. 伺服器看得到什麼
訊息經由我們營運的中繼伺服器(relay,位於新加坡)轉送。中繼只搬運密文,看不到訊息內容、附件內容,也看不到寄件者是誰(寄件者身分藏在加密層裡)。
中繼會處理與短暫保存以下資料:
| 資料 | 為什麼 | 留多久 |
|---|
| 你的公鑰包(公鑰與一次性預鑰) | 讓別人能對你發起加密通道 | 只要你還在使用就會留在伺服器上;目前沒有從伺服器移除公鑰包的功能 |
| 加密後的信封:收件地址、密文、大小、時間 | 轉送給收件者 | 收件者取走後即刪除;沒人取走的信封最多保留 7 天,之後刪除 |
| 推播 token(只在你開啟通知時) | 讓 Apple 能叫醒你的手機 | 你關閉通知或登出時刪除 |
中繼因此看得到的元資料是:哪個地址在什麼時候收到多大的一封信。它看不到是誰寄的、寫了什麼。我們目前沒有隱藏寄件者(sealed sender)或洋蔥路由這類流量分析防護;這是現階段刻意的取捨,寫在這裡讓你知道。
連線紀錄:中繼的資料庫不記錄 IP 位址。任何網路伺服器在連線期間都會知道你的 IP,我們不把它與你的地址關聯、也不用它做任何分析。
4. 推播通知
通知預設關閉。開啟後,伺服器會把一個由 Apple 發給這台裝置的推播 token 綁到你的地址。有新東西時,伺服器透過 Apple 推播服務送一則通知;通知只包含種類(「你有新訊息」「你有新的好友請求」「你有新的群組邀請」),不包含內容,也不包含寄件者。Apple 因此只知道「這台裝置收到了一則 Dmessenger 通知」。
關掉通知會把 token 從伺服器移除。
5. 你的顯示名
你在個人資料裡設定的顯示名,會放在加密訊息裡送給你的聯絡人與同群成員,讓他們知道怎麼稱呼你;伺服器看不到。對方如果已經幫你取了暱稱,看到的會是他取的那個。陌生人送來好友請求時,你不會看到他的顯示名,只會看到地址與留言。
6. 裝置權限
- 相簿與相機:只在你挑照片或拍照的那一刻使用;只有你選中的那一張會被讀取,和訊息一樣加密後送出。
- 麥克風:只在你按下麥克風到按停止之間錄音;錄下的語音和訊息一樣加密後送出。
- Face ID/Touch ID:只用來解鎖你的身分(第 2 節)。
以上內容都不會以任何未加密的形式離開你的裝置。
7. 我們不做的事
- 沒有分析、沒有廣告、沒有第三方追蹤或崩潰回報 SDK。app 裡唯一會連線的對象是我們的中繼伺服器與 Apple 推播服務。
- 不販售、不分享任何資料——我們手上也沒有可分享的東西。
- 不保存已送達的訊息;沒有雲端備份、沒有跨裝置的聊天記錄同步。換手機用助記詞恢復身分時,聊天記錄不會跟過去,這是設計使然。
8. 忘記密碼
密碼從不離開你的裝置,我們沒有重設機制,也沒有後門。忘記密碼時,唯一的辦法是用 12 個字的助記詞重設;重設後身分與聯絡人保留,但這台裝置上的聊天記錄會清空(舊記錄是用舊密碼派生的金鑰鎖著的,沒有任何人能打開)。
9. 訊息過期與刪除
- 你可以為每個對話設定訊息計時器,到期的訊息會在雙方裝置上刪除。
- 「對所有人刪除」會請對方裝置刪掉那則訊息(送出後 24 小時內);這是對對方 app 的請求,我們無法保證對方裝置一定執行。
- 伺服器上沒有可以刪除的訊息副本——送達的當下就刪了。
10. 兒童
Dmessenger 不是為 13 歲以下的兒童設計的,我們也無從得知使用者的年齡(我們不收年齡,也不收任何個人資料)。
11. 政策變更
政策若有變更會更新這一頁與頂端的修訂日期。涉及資料處理方式的重大變更會在 app 的更新說明裡提到。
12. 聯絡我們
請注意:因為我們讀不到任何訊息內容,處理檢舉時只能依據你提供的說明與截圖。
Dmessenger Privacy Policy
Effective date: 2026-09-10 · Last revised: 2026-09-10
Dmessenger is an end-to-end encrypted messaging app developed and operated by Nadrix ("we", "us"). This policy explains what data the app handles, where it lives and who can see it. Our approach in one sentence: we collect as little as possible, and what we do handle, we cannot read.
1. No account
Dmessenger has no sign-up. You never give us a phone number, an email address or any other personal information. Your identity is generated on your device: a private key and an address derived from the public key (starting with dm1…). That address is your chat ID. We have no way to link it to a real person.
2. Data that stays on your device
The following exists only on your phone and is never uploaded:
- Your private key and 12-word recovery phrase. The recovery phrase is the only way back in. We keep no copy and cannot restore access if you lose it (see section 8).
- Messages, attachments (photos, voice messages, files) and encryption sessions. These are stored encrypted with a key derived from your password (Argon2id). Without the password they cannot be opened.
- Contacts, groups and the nicknames you give your contacts. Stored encrypted as well.
- Local preferences: your own display name and avatar, theme, wallpaper, notification switch. ⚠️ These preferences are stored unencrypted on the device and can be read before the app is unlocked (that is how the identity list shows your name). Message content, the recovery phrase and encryption sessions are not in this category; they are always encrypted.
- Face ID / Touch ID unlock (optional): when enabled, the key that unlocks your vault is stored in the iOS Keychain, protected by biometrics, on this device only, never in iCloud. Your password itself is never stored.
Deleting an identity (Settings → Switch identity → Delete) removes all of the above from the device.
3. What the server can see
Messages travel through a relay server we operate (located in Singapore). The relay only carries ciphertext. It cannot see message content, attachment content, or who the sender is (the sender's identity is inside the encrypted layer).
The relay processes and briefly stores:
| Data | Why | For how long |
|---|
| Your public key bundle (public keys and one-time prekeys) | So others can open an encrypted channel to you | Kept while you use the service; there is currently no way to remove a key bundle from the server |
| Encrypted envelopes: recipient address, ciphertext, size, timestamp | To deliver them to the recipient | Deleted as soon as the recipient fetches them; unfetched envelopes are kept for at most 7 days, then deleted |
| Push token (only if you turn notifications on) | So Apple can wake your phone | Removed when you turn notifications off or log out |
The metadata the relay can therefore see is: which address received an envelope of what size at what time. It cannot see who sent it or what it says. We do not currently have sealed-sender or onion-routing style protection against traffic analysis; this is a deliberate trade-off at this stage and we state it here so you know.
Connection records: the relay's database does not store IP addresses. Any server on the internet knows your IP address for the duration of a connection; we do not associate it with your address and do not use it for any analysis.
4. Push notifications
Notifications are off by default. When you turn them on, the server binds a push token issued by Apple for this device to your address. When something arrives, the server sends a notification through Apple's push service. The notification contains only a type ("You have a new message", "You have a new friend request", "You have a new group invitation"). It contains no content and no sender. Apple therefore only learns that this device received a Dmessenger notification.
Turning notifications off removes the token from the server.
5. Your display name
The display name you set in your profile is sent inside encrypted messages to your contacts and fellow group members so they know what to call you; the server cannot see it. If someone has already given you a nickname, they see that instead. When a stranger sends you a friend request you do not see their display name, only their address and their note.
6. Device permissions
- Photos and camera: used only at the moment you pick a photo or take one. Only the photo you choose is read, and it is encrypted like a message before it is sent.
- Microphone: records only between the moment you press the microphone and the moment you stop. The recording is encrypted like a message before it is sent.
- Face ID / Touch ID: used only to unlock your identity (section 2).
None of this leaves your device in unencrypted form.
7. What we do not do
- No analytics, no advertising, no third-party tracking or crash-reporting SDKs. The only things the app connects to are our relay server and Apple's push service.
- We do not sell or share any data. We have nothing to share.
- We do not keep delivered messages. There is no cloud backup and no chat-history sync across devices. When you restore your identity on a new phone with the recovery phrase, your chat history does not come with it. This is by design.
8. Forgotten passwords
Your password never leaves your device. There is no reset mechanism and no back door. If you forget it, the only option is to reset it with your 12-word recovery phrase; your identity and contacts are kept, but the chat history on that device is wiped (it was locked with a key derived from the old password, and nobody can open it).
9. Expiry and deletion
- You can set a message timer per conversation; expired messages are deleted on both devices.
- "Delete for everyone" asks the other device to delete that message (within 24 hours of sending). It is a request to the other person's app; we cannot guarantee their device carries it out.
- There is no copy of a delivered message on the server to delete; it is removed the moment it is delivered.
10. Children
Dmessenger is not designed for children under 13. We have no way of knowing a user's age, because we collect no age and no personal information at all.
11. Changes to this policy
Changes are published on this page with an updated revision date. Material changes to how data is handled are also mentioned in the app's release notes.
12. Contact
Please note that because we cannot read any message content, abuse reports can only be handled on the basis of the description and screenshots you provide.