Skip to content

Encrypted chats in Vire

Set up your keys, unlock new devices, and check who you are talking to.

End-to-end encryption means a Vire is locked on your device before it's sent, and only you and the person you're writing to hold the keys to open it. Viremail's servers carry and store it, but can't read it.

Vire chats start using these keys in an upcoming update. Keys are being opened up to accounts step by step: if Settings, Encryption shows Turn on encryption, you can set yours up now, so you're ready when it arrives. If it says encrypted chats aren't open for your account yet, you can set them up there once they are.

Set it up

  1. Open Settings, Encryption and choose Turn on encryption.
  2. If you have a passkey, you can let it unlock your chats too.
  3. Save your recovery key: 36 letters and numbers in 9 groups. Keep it in your password manager, or on paper at home.
  4. Type its last group to confirm, and you're done.
We can't show your recovery key again or recover it for you. It's your way back in if you lose every device.

Unlock a new browser

A browser you sign in on for the first time starts locked. Unlock it in any of these ways:

  • Your passkey. Signing in with a passkey can unlock your chats in the same step.
  • Your recovery key. Capitals, spaces and dashes don't matter.
  • Another device. Choose Approve from another device. Your unlocked phone or computer shows a request within a few seconds, with the new browser's name and IP address: choose Review, then Approve, and type the 6-digit code the new browser shows. The code makes sure nobody in between can slip in a browser of their own. Three wrong codes cancel the request, and it lasts 5 minutes.

On a shared or public computer, keys stay in that tab only. They're gone when you close or reload it, so you unlock again each time. Signing out removes them from the device too.

Check who you're talking to

You and each person you talk to share a safety number: 60 digits that are the same on both screens. Compare it in person or on a call, or scan their QR code, then choose Mark as verified. If their code changes later (for example after they replace their keys), you'll see a notice and can compare again. Marked someone by mistake? Open their number and choose Mark as not verified; your other devices follow.

If something goes wrong

  • Lost a device? Choose Replace your keys. You get new keys and a new recovery key, your other devices are signed out, and your history stays readable.
  • Lost a passkey? Remove it and tick Also replace my recovery key. Removing a passkey in Settings, Security also stops it unlocking your chats.
  • Replacing keys or your recovery key stops every other way to unlock. If you have a passkey, you'll be asked to confirm with it so it keeps working, and you can add others again afterwards.
  • Lost your recovery key and every device? Choose Reset encryption. Messages sent before the reset can't be read anymore.
  • Settings says "Your keys were replaced"? If you replaced them on another device, unlock this browser to get the new ones. If you didn't, choose Replace them from this browser, then change your password.
  • Two devices, two different keys? Unlock the one that's out of date with your recovery key, a passkey or another device. It then uses the keys saved in your account, like your other devices. Messages that only its old key could open may not be readable on it afterwards.
  • A red warning about your own security key? Viremail is showing a key for you that this browser didn't make, or an older one (which can happen after Viremail restores a backup). Sending pauses until you choose Replace your keys, and a new recovery key or passkey can't be added until then, because it couldn't unlock your other devices.

Each of these shows your new recovery key and asks you to type its last group before anything changes, so you can't end up without a working key. Your password is checked first, so a typo is easy to fix.

What Viremail can still see

Viremail can seeViremail can't see
Who talks to whom, and whenWhat your encrypted messages say
Roughly how big a message is, and how many attachmentsPhotos, videos and files sent encrypted
Reactions, and stories (stories aren't end-to-end encrypted)Your keys, your recovery key and your passkey's secret
When you add or remove a way to unlock, and passkey IDs
Whether you've turned encryption on, and when your keys changed
Requests to approve a new browser: when, its IP address and browser name

People who can message you can see whether you've turned encryption on, and your public key (they need it to write to you). If you only accept messages from friends, or from nobody, strangers can't look it up.

Where your keys live

Your keys are kept in this browser's storage on your device, never on our servers in a form we can open. In a web browser they're protected by your device: its login and disk encryption. Turn those on, especially on a laptop. In the Viremail desktop app, the key that seals your stored secrets is also protected by your computer's own key store when it has one. On a shared or public computer they stay in the open tab only.

Honest limits

  • In a web browser you rely on the code Viremail sends each time you open it. Someone who could change that code could get around encryption. The same is true of every web app.
  • Anyone who can use one of your unlocked browsers can read your chats until you replace your keys.
  • Messages sent before encryption was on stay as they were.
  • Your mail's OpenPGP key is separate, and works differently: it's protected by your account password. See Set up encrypted email.
Was this helpful?

All guides

Getting started

Mail

Security & privacy

Encryption

Vire & calls

Calendar & tasks

Notes & contacts

Drive and office apps

Account

Troubleshooting