Privacy & Security
Miracal is designed with privacy and security as core principles. Our messaging architecture uses end-to-end encryption and cryptographic device authentication to help protect private communication between users.
End-to-End Encryption
Miracal uses end-to-end encryption to protect the content of private conversations.
Messages are encrypted before they leave the sender's device and can only be decrypted by an authorized recipient device.
The encryption process is designed so that intermediary systems cannot access the plaintext content of an encrypted message while it is being transmitted.
Protected Content
End-to-end encryption may protect supported communication such as:
The exact encryption behavior may vary depending on the communication feature and device.
Cryptographic Key Architecture
Miracal uses public-key cryptography to establish secure communication between authorized devices. Each participating device has cryptographic identity material used during the secure communication process.
Used as part of the device authentication and key-establishment process with other verified devices.
Kept confidential exclusively by the hardware device and never intended to be shared publicly or transmitted.
Ephemeral symmetric keys derived dynamically to establish protected communication between authorized endpoints.
Private cryptographic material must remain confidential. It should never be manually copied, transmitted or shared with another person.
ECDH Key Exchange
Miracal uses Elliptic Curve Diffie-Hellman (ECDH) as part of its secure key-establishment process. ECDH allows two authorized devices to establish shared cryptographic key material without directly transmitting the resulting secret over the network.
High-Level Process:
The private component of the key pair is never intended to be exposed to another user.
QR-Based Device Linking
Miracal supports QR-based authentication for linking a web or additional device to an existing account. The QR code acts as a secure mechanism for initiating the device-linking process.
Linking Flow:
- 1. The new device generates the information required for the linking request.
- 2. A QR code representing the linking request is displayed.
- 3. The user scans the QR code using an already authenticated device.
- 4. The existing device verifies the linking request.
- 5. Required public cryptographic information is exchanged.
- 6. A secure key-establishment process is performed.
- 7. The new device becomes an authorized linked device.
- 8. Encrypted communication can then be established according to the application's security protocol.
Scanning a QR code alone should not be considered equivalent to exposing a private encryption key.
Linked Devices
Linked Devices allows users to access their account from supported additional devices. Every linked device should be treated as a separate trusted endpoint.
Users should regularly review their linked devices and remove devices that they no longer recognize or use.
Device Verification
When linking a device, the application performs authentication and cryptographic verification before establishing the trusted relationship. Only successfully authorized devices should be allowed to participate in protected account communication.
Private Key Protection
Private cryptographic keys are security-sensitive credentials. Miracal's security model is designed around keeping private key material under the control of the authorized device.
Users should never:
- Share a private key with anyone
- Send a private key through chat messages
- Upload a private key to an unknown service
- Paste private key material into support conversations
- Manually transfer private key material to another person
If private cryptographic material is exposed, the security of the associated device identity may be compromised.
Message Encryption
Before a protected message is transmitted, the message content is processed through the application's encryption mechanism.
The encrypted representation is designed to prevent unauthorized parties from directly reading the original message content. The recipient device performs the corresponding decryption operation after the message has been received and successfully authenticated.
Message Authentication
Encryption protects confidentiality, while authentication helps protect message integrity and origin.
Miracal can use cryptographic authentication mechanisms to help ensure that encrypted communication has not been modified unexpectedly during transmission.
A message that fails the required cryptographic verification should not be treated as trusted communication.
Secure Device Authentication
Device authentication helps establish whether a device is authorized to participate in an account's protected communication.
Authentication may involve:
The exact authentication mechanism depends on the account and device flow being used.
Session Security
Secure communication may use session-specific cryptographic material to reduce the exposure associated with long-term keys.
Session keys are intended to protect communication during an established secure session and should not be treated as permanent account credentials.
The application is responsible for managing the lifecycle of session cryptographic material.
Chat Privacy
Users can take additional steps to protect conversations on their devices.
Encryption protects communication, while device security protects the information displayed on the device itself.
Disappearing Messages
Disappearing Messages allows supported messages to be automatically removed after a configured period. This feature provides additional control over message retention.
However, disappearing messages should not be considered a guarantee that information can never be retained. A recipient may still be able to capture or reproduce content before it disappears.
View Once Media
View Once allows supported media to be shared with limited viewing availability.
Once the supported media has been viewed, it is removed from the normal conversation experience according to the application's implementation.
Users should still avoid sharing highly sensitive information with recipients they do not trust.
Block and Report
Users can block unwanted contacts and report suspicious or abusive behavior.
Blocking helps prevent unwanted communication from a selected account.
Reporting provides a mechanism for users to notify the platform about activity that may violate applicable rules or security policies.
Account Security
Users are responsible for protecting their account and authentication information.
For better account security:
Security Limitations
End-to-end encryption protects communication content during secure communication, but it does not protect a device that has already been compromised.
For example, if an unauthorized person has access to an unlocked device, they may be able to access information that is already available on that device.
Users should therefore consider both communication security and device security when protecting their account.
Privacy by Design
Miracal's security architecture is designed around limiting unnecessary access to private communication. Security measures may include:
Security mechanisms are continuously reviewed and improved as the platform evolves.
Frequently Asked Questions
Security is a Shared Responsibility
Miracal provides security technologies designed to protect private communication, but users also play an important role in maintaining account security.
Keep your devices secure, protect your authentication information, review linked devices regularly, and never share private cryptographic keys.