nampa Get an invite

Security overview and threat model

How Nampa protects your voice notes, and an honest account of what it can't protect against.

Last updated 2 October 2026. These policies take effect when the Nampa app launches. Until then they describe how we are building it.

Voice notes are encrypted on the sender's device. Nampa stores encrypted audio and is designed so our systems cannot play your private notes. This isn't end to end encryption in the strict sense, and we won't call it that. While a note is alive, its key is held by a separate Nampa service so the recipient can open it. This page explains how that's protected, and where the limits are.

How a note travels

  1. You record on your phone, and the audio is encoded as Opus.
  2. Your phone makes a fresh 256 bit key for that one note and encrypts the audio with AES-256-GCM.
  3. The encrypted audio goes to our storage. The key goes to a separate key service over its own encrypted connection.
  4. The recipient's app fetches both, decrypts the note in memory and plays it. Nothing is written to their phone.
  5. After the replay, or 24 hours if it isn't played, the key service deletes the key and storage deletes the audio.

Keeping keys and audio apart

  • The key service and audio storage run separately, with different credentials. Neither can reach the other's data.
  • No member of staff has standing access to both. Any access to production systems needs a second person to approve it, and every access is logged.
  • All connections use TLS 1.3, and the app only trusts our own certificates.

On your phone

  • Playback screens are protected from screenshots and screen recording using the system protections iOS and Android provide.
  • If screen recording starts, playback stops and the sender is told.
  • Your voice key, if you set one up, never leaves your phone's secure enclave.

Threat model

What Nampa is designed to protect against, and what it isn't.

ThreatProtected?
Someone breaks into our audio storageYes. They'd find only encrypted audio. The keys live in a separate service.
Someone watches the networkYes. Notes are encrypted before they leave your phone, and every connection uses TLS.
A note after it has endedYes. The key and audio are deleted, so copies in backups can't be played.
Screenshots and screen recordingMostly. Blocked on standard phones. A phone that has been rooted or jailbroken may get around it.
Someone with access to both the key service and audio storage while a note is alivePartly. Separation, two person approval and logging make this hard. It's the main reason we don't call Nampa end to end encrypted.
A legal demand while a note is alivePartly. Notes end within 24 hours at most, and we won't build tools to decrypt them. See our law enforcement policy.
Someone takes over your phone numberPartly. Signing in on a new phone alerts your old one, and notes sent before the takeover have usually already ended.
Malware on your phone or the recipient'sNo. A compromised phone can hear notes as they play.
A second phone recording the speakerNo. No app can stop this. We'd rather say so than pretend.
Someone you trust repeating what you saidNo. That's about trust between people, not technology.

What we will never build

  • A back door or master key.
  • Any way to transcribe, analyse or quietly keep your notes.
  • A way to turn off deletion for one person without telling them.

Independent review

Before public launch we'll have an independent firm review Nampa's security, and we'll publish a summary of what they found and what we fixed.

Reporting a security problem

If you find a weakness, write to hello@nampa.app. We'll reply within 3 working days and keep you updated until it's fixed. If you act in good faith, don't access other people's data and give us reasonable time to fix the problem, we won't take legal action against you. Our security.txt has the details in a standard format.

Questions

Write to hello@nampa.app. A person reads every message.