Security, clearly.
Tinline is pre-release software. Open source is not a substitute for an independent security audit. Review the limitations before trusting it with sensitive conversations.
Encrypted calls
Calls use peer-authenticated iroh QUIC/TLS encryption, including when relayed. Signed device attestations bind each device to an identity, and signed grants authorize calls. Compare safety numbers through a trusted channel to confirm the person behind the identity.
Local protection
The recovery phrase and device secret key are encrypted in a vault with an optional passphrase. Android remembers an unlock key using Android Keystore so incoming calls can work in the background. Contacts and call history are local plaintext files protected by the operating system, not by the vault.
On desktop, no-passphrase identities use the system keyring when available. The current fallback stores a plaintext unlock key beside the vault; copying both exposes the identity. A long, unique passphrase provides a stronger file-copy protection model.
What this does not protect
- A compromised or already-unlocked device.
- A stolen recovery phrase: there is no global device revocation.
- Connection metadata: peers and relay/discovery providers can observe network information. Tinline is not anonymous.
- Data already held by another person: local deletion does not remotely erase their copy.
Tinline has no separate application-level media ratchet and is not an emergency-calling service. Calls require both devices to be reachable.
Report a vulnerability
Email osvauld@gmail.com with “Tinline security” in the subject. Include the version, affected platform and reproduction steps. Please do not send real recovery phrases, private keys or another person's data. Email is not an encrypted reporting channel; request a secure channel before sharing sensitive material.