How Letro protects your messages¶
A plain-language explanation of the end-to-end encryption that keeps your Letro conversations private — and what you need to do to benefit from it.
Security note: Everything in Letro — messages, files, calls — is end-to-end encrypted by default. You don't switch it on. The one thing you do need to do is set up a secure backup and recovery key so you never lose access to your own encrypted history.
What "end-to-end encrypted" means¶
When you send a message in Letro, it's scrambled (encrypted) on your device before it leaves. It travels scrambled, is stored scrambled, and is only unscrambled (decrypted) on the devices of the people you're talking to.
The important consequence: the content of your conversations can't be read by
- the servers that relay your messages,
- anyone who intercepts your network connection, or
- Letro as a company.
Only you and the people in the conversation hold the keys. This is different from most email and many chat apps, where the provider can read your messages.
Where your keys live¶
The keys that unlock your messages are held on your devices, not on a server. That's what makes the encryption trustworthy — but it also means that if you lose your only device, those keys could be lost with it.
Letro solves this with two things you set up once:
- Secure backup (key storage). An encrypted backup of your message keys, stored on the server in a form only you can unlock. It lets a new device recover your past messages. See Set up secure backup & key storage.
- Recovery key. A long, one-time key that unlocks your secure backup. It's your safety net if you ever lose access to all your signed-in devices. See Your recovery key.
Because the backup is itself encrypted with your recovery key, the server stores your keys but still can't read your messages.
How you know you're talking to the right person¶
Encryption protects your messages in transit, but it can't, on its own, tell you that the "Alex" you're messaging is really Alex. Letro adds verification for that:
- Verify your own devices so each new phone or laptop you sign in on is confirmed as yours. See Verify your own devices.
- Verify other people by comparing a short code (or scanning a QR) once, after which Letro shows a green shield next to them. See Verify other people.
Verification is how you get from "this message is encrypted" to "this message is encrypted and I know exactly who's on the other end."
Your identity in Letro¶
Each person has a digital identity tied to their PostNumber. If someone resets their identity — for example after losing all their devices — Letro warns the people who had verified them, so a reset can't be used to quietly impersonate someone. See Digital identity & reset alerts.
What encryption does not hide¶
End-to-end encryption protects the content of your conversations. To run the service, the server still handles some operational information — for example which accounts exist, which devices are active, and when messages are sent (not what they say). On a Letro Dedicated Server, your organization controls where even this operational data lives.
Good to know¶
- You don't need to be technical. Letro guides you through backup, recovery, and verification with prompts; this section walks through each step.
- Set up your safety net early. The most common way people lose encrypted history is signing in on a new device without ever having set up secure backup and a recovery key. Do it now — it takes a minute.
- Losing all devices without a recovery key means past encrypted messages can't be recovered — that's the trade-off for encryption no one else can break. The recovery key is how you avoid it.
Related: