In pre-release testing · TestFlight beta next

Privacy is yours.
We built the proof.

Veil is a privacy-first super app: end-to-end encrypted messaging, private voice and video calls, and everyday services — with zero data harvesting and no advertising trackers. Not as a setting. As the foundation.

No phone number. No email address. Your Veil ID is anonymous by design.

Living network

Encrypted activity,
visible and clear.

Every packet tells a story of privacy. Hover the field to see the network respond.

Veil NetworkEncrypted packets in transit
End-to-end encryptedMessages are sealed on your device before they leave it. Our server relays ciphertext it cannot read.
Anonymous identityA Veil ID needs no phone number, email, or real name — and no address book upload.
No trackers, everNo advertising SDKs, no analytics trackers, no ad ID. A platform guarantee, not a toggle.
Yours, locallyCall history and encryption keys live on your device — not in our cloud.

The app

One place for your digital life.
Private by default.

Every feature carries its real status — the same three grades we hold ourselves to in development. Green is proven. Blue is in testing. Gold is on its way.

Working

Encrypted messaging

End-to-end encrypted text and reactions, proven on real devices — including across app restarts. The server only ever sees ciphertext.

Working

Voice & video calls

Private calls over encrypted WebRTC, connected peer-to-peer wherever the network allows. Your call history stays on your device.

Working

Media messaging

Photos, video, and voice notes — fully end-to-end encrypted, verified on real devices.

Working

Anonymous Veil ID

Connect by exchanging anonymous IDs — no phone number, no email required. We don't build a social graph from your address book.

Working

Navigation

Real turn-by-turn walking, cycling, and driving directions — live GPS, verified on real devices including a full real-world network test.

Working

Markets

Live crypto, forex, and commodities pricing and trends — real data, verified on real devices.

Working

Private browser

Built-in tracker blocking and automatic cookie-consent rejection — verified on real devices, including over a live cellular network.

Working

Vault

Secure notes, passwords, and documents — locked behind Face ID, stored only on your device. Verified on real devices.

Working

Travel search

Real flight search, including genuine connecting itineraries — verified live in the app. Booking hands off to Google Flights; Veil never sees your itinerary.

Working

Video search

Search YouTube without your query ever reaching Google directly — proxied through Veil. Playback uses YouTube's own standard player, the same as watching YouTube anywhere else.

Preview

Everyday services

Rides, shopping, and a wallet — built into the app in preview, designed so convenience never costs you your data.

In development

Private AI

An assistant designed around privacy: no profile built on you, nothing harvested to train on your life. Shipping when it meets our bar.

Radical transparency

What actually happens to your data.

No mystique — here is the honest journey, stated plainly. Tap any step to see exactly what happens there, what data exists at that point, and what Veil never sees.

When you send a message

Your deviceThe message is encrypted before it leaves.

What happens: Your message is sealed on-device using the Matrix protocol's Olm/Megolm encryption before it's ever transmitted.

What data exists: Plaintext — briefly, only on this device.

What Veil never sees: The message content, at any point after this.

Our serverRelays sealed ciphertext it cannot read.

What happens: The encrypted packet is routed toward the recipient's device.

What data exists: Ciphertext, plus the routing information any relay needs — which accounts are in the conversation, and when a message was sent.

What Veil never sees: The message content. Honest caveat: routing metadata is real and disclosed, not hidden — see the metadata section below.

Their deviceOnly the recipient's keys can open it.

What happens: The recipient's own device keys decrypt the message locally.

What data exists: Plaintext again — only on their device.

What Veil never sees: The decrypted message, at any point in transit.

We couldn't read your messages if we wanted to. That's the point.

When you make a call

You callThe connection is negotiated peer-to-peer.

What happens: Your device and theirs negotiate a direct connection (WebRTC).

What data exists: Only connection-setup information (offer/answer/network candidates), authenticated by a shared app secret.

What Veil never sees: Audio or video content — it doesn't exist yet at this step.

Encrypted liveAudio and video travel over encrypted WebRTC.

What happens: Audio and video travel encrypted end-to-end (DTLS-SRTP), direct between devices wherever possible.

What data exists: If a direct connection isn't possible, our relay forwards encrypted packets it cannot open.

What Veil never sees: The audio or video content, ever — the relay only ever sees opaque encrypted packets.

Call endsNo recordings. History stays on your device.

What happens: The call ends; nothing about it is recorded server-side.

What data exists: Your own call history, stored only on your device.

What Veil never sees: A record of the call — there's no server-side call log to see it in.

No recordings, no server-side call log — your history is yours alone.

What we collect about you

No advertising IDNothing follows you across apps or the web.

What this means: No identifier exists that could link your activity across apps or the web.

How it's enforced: No advertising SDK exists anywhere in the shipped app — a dependency-level fact, not a setting you could turn off.

What Veil never sees: An advertising identifier — there isn't one to see.

No trackersBlocked at platform level — there is no off switch to forget.

What this means: Analytics and advertising trackers are blocked before they load, inside Veil Browser.

How it's enforced: Requests to known tracker and analytics domains are intercepted and blocked automatically.

What Veil never sees: Your browsing activity — there's no tracking pipeline collecting it in the first place.

No data salesYou are the customer. Never the product.

What this means: Veil Technologies Ltd's business doesn't depend on your data.

How it's enforced: No analytics trackers, no ad SDKs, no data-broker relationships exist to sell through.

What Veil never sees: A profile built on your activity to sell — none exists.

Our business model is your support — not your data.

What Veil can see

Your Veil ID — anonymous, not linked to your real identity.
Whether your account exists and is currently active.
Your contacts list, including whatever name or label you type for each one — this is what you typed in, not a real address book we verify against.
Who's messaging whom. Message content is encrypted, but the messaging server still needs to know room membership to deliver messages to the right people — it no longer logs your IP address to do it, but this metadata isn't hidden. See the Metadata entry in the deep dive below.
Veil Mail content — protected in transit (TLS), but not yet encrypted at rest, so it's technically readable on our mail server, the same baseline most traditional email providers offer.

What Veil cannot see

Your conversations — text, images, video, and voice notes are end-to-end encrypted.
Your calls — voice and video are point-to-point encrypted (WebRTC/DTLS-SRTP); our relay only ever sees encrypted packets it cannot read.
Your Vault contents — notes, passwords, and documents never leave your device at all.
Your browsing history — never logged, on your device or ours.
Your real name, phone number, or personal email — none of these are required to create an account.

The evidence bar

We grade our own claims.

Most apps tell you everything works. We hold a stricter rule: a claim ships only when the technology behind it is proven. This board is the honest state of Veil — including what isn't finished yet.

CapabilityStatusWhat that means
Encrypted text & reactionsProvenVerified end-to-end on physical devices, including surviving app restarts.
Voice & video callsProvenBidirectional calls, mute, loudspeaker, and video verified on real devices.
Photo, video & voice messagesProvenFully end-to-end encrypted and verified on real devices — the server only ever sees ciphertext.
Anonymous Veil IDsProvenContact exchange with no phone number, email, or personal identifiers.
Tracker-free platformBy designNo advertising SDKs, no analytics trackers, no ad ID — verifiable in the shipped binary.
Turn-by-turn navigationProvenLive routing and GPS tracking, verified on real devices including a real-world 5G test.
Live market dataProvenReal crypto, forex, and commodities data, verified on real devices.
Private browsingProvenTracker blocking and consent rejection verified on real devices and over a live cellular network.
Vault (notes, passwords, documents)ProvenFace ID-gated, device-only storage, verified on real devices.
Flight searchProvenLive search verified in the app, including real connecting itineraries. Booking continues via Google Flights, not in-app checkout.
Video search & playbackProvenSearch is proxied through Veil and never reaches Google directly. Playback uses YouTube's standard player.
Everyday services (rides, shopping, wallet)PreviewIncluded in the app as previews while we finish the privacy engineering behind each one.
Private AI assistantIn developmentBeing built to our privacy bar before it ships — no profiles, no harvesting.

This board is updated as our testing progresses. If a capability isn't marked proven here, we don't advertise it anywhere else either.

The full architecture

Every claim, explained in full.

The same 11 entries our own team is held to internally — including the one place we're honest that something isn't fully solved yet. Filter by status, or open any entry for the full explanation and the technical detail behind it.

What Stays On Your Device

Proven
Vault contents never leave your device. Messaging and calls are both end-to-end encrypted, verified on real devices.

Vault — your notes, passwords, and documents — is stored only on your device, behind your biometric gate. It is never uploaded or transmitted anywhere. Messaging and calls both have real end-to-end encryption, verified on real devices: content is unreadable to Veil's own infrastructure, not just to outside observers.

Technical detail

Vault uses your device's own secure storage and makes no network request to store or retrieve its contents. Messaging uses genuine end-to-end encryption via the Matrix protocol's Olm/Megolm implementation (a real FFI binding to matrix-rust-sdk, not a stub) — verified on physical devices for text, reactions, images, video, and voice notes. Calls use WebRTC's own DTLS-SRTP encryption directly between devices.

Messaging — End-to-End Encrypted

Proven
Text, reactions, images, video, and voice notes are end-to-end encrypted — verified on real devices, not just claimed.

When you message someone on Veil, your messages — text, reactions, photos, videos, and voice notes — are end-to-end encrypted: content is unreadable to Veil's own infrastructure, not just to outside observers. This was built, broken, rebuilt, and verified across real testing on physical devices before we were willing to say so here.

Technical detail

Messaging runs on the Matrix protocol. Conversations use genuine end-to-end encryption (Olm for key exchange, Megolm for message content) via matrix-rust-sdk, verified via three consecutive clean passes on simulator and confirmed on physical devices for every content type this app sends.

Metadata — What's Actually Protected, and What Isn't

Known Limitation
Content is encrypted. Who you're talking to isn't fully hidden — the messaging server still knows room membership to route your messages, though it no longer logs your IP address to do it.

End-to-end encryption protects what you say, not who you're talking to. Veil's relay can still see who is contacting whom — the room membership itself isn't hidden, even in an encrypted conversation. Genuine metadata privacy ("sealed sender" or similar) would mean replacing how the underlying protocol routes messages, not a setting we can flip — we've scoped what that would actually take and it's a major undertaking, not something we're claiming is solved. What we have fixed: the messaging server's access log used to record your source IP address alongside your account identifier on every request, with no size or retention limit at all, growing forever. Both are now fixed — the access log no longer records IP addresses at all, and everything else logged is hard-capped and auto-rotating. What remains: the server still has to know which room you're in and who else is in it, to deliver your messages to the right people. That's a real, ongoing limitation, not one we're claiming to have solved.

Technical detail

The Cloudflare Worker that handles calls and contacts contains no code that writes IP addresses, timestamps, or message content to persistent storage. The Synapse homeserver's access logger previously had no explicit level set, so it inherited the root logger's default and recorded the client's source IP address, account identifier, request path, and timing for every API call. An explicit override now sets that logger alone to a quieter level, verified directly by making a live request and confirming no log line was produced for it. Message content, access tokens, and room-membership state are not logged at either level. The server's log driver is separately hard-capped and auto-rotating (roughly 50MB total) rather than growing forever. Room membership itself remains visible to the homeserver by protocol design — genuine metadata-hidden messaging would require replacing that delivery model entirely.

Vault — Fully On-Device

Proven
Vault contents are stored on-device, sandboxed, and protected by your biometric gate. Data does not leave your device.

Vault — your secure notes, passwords, and documents — never leaves your device. There is no upload and no server-side copy — nothing for Veil to store, read, or lose. Everything lives inside your device's own sandboxed storage, unlocked only by your biometric gate.

Technical detail

Vault items are persisted using your device's native secure storage (Keychain for notes and passwords; sandboxed app storage for documents), gated by on-device biometric authentication with a passcode fallback. No network request is made to store or retrieve Vault contents.

Wallet — Real Flows, Simulated Payments

Preview
Wallet's transaction flows are real. Payment infrastructure and balances are still simulated.

Sending, receiving, and viewing transaction history in Veil Wallet all use real interface code. What isn't real yet: live payment infrastructure. Balances and the VLT token itself are simulated while we finalise partnerships with payment providers. No real money moves through Wallet today.

Technical detail

Wallet's UI and local state management are fully implemented. No connection exists yet to any payment processor, blockchain, or financial institution — VLT balances are stored and updated locally, not backed by real value or a real ledger.

Private Browsing

Proven
Veil Browser blocks known trackers, rejects cookie-consent banners automatically, and resists browser fingerprinting across every major signal but one.

Veil Browser blocks requests to a known list of tracker and analytics domains before they load, and automatically rejects cookie-consent banners from major providers. Third-party cookies and on-device storage are disabled for every page you visit. No browsing history is saved — not on your device, not on our servers. Fingerprinting resistance now covers canvas, WebGL, AudioContext, font-enumeration, installed plugins, and browser language — the deliberate exception is screen resolution, left alone since spoofing it risks breaking real responsive layouts for limited privacy benefit on a mobile device.

Technical detail

Tracker blocking intercepts fetch and XMLHttpRequest calls, removing matching script/image/iframe tags for a maintained list of tracker and analytics domains. Fingerprinting resistance: canvas reads get per-session pixel noise, WebGL's getParameter returns a generic vendor/renderer, AudioContext channel data gets small per-sample noise, installed plugins are hidden and browser language is normalised. There is no custom Veil-operated DNS resolver — DNS resolution uses your device's normal network configuration.

VPN — Early-Stage, Verified, Not Yet Live

Early-Stage
A real WireGuard tunnel has been built and verified working on a physical device. It is not part of this build, and not for production use yet.

We've built and tested a real WireGuard VPN tunnel — genuine handshake, genuine encrypted traffic, confirmed working on a physical device, not a mockup. It is an early-stage spike, by design: it isn't included in this build, has no user-facing on/off control yet, and we haven't finished auditing what the VPN server itself logs. We're not switching it on for anyone until all of that is true and reviewed.

Technical detail

WireGuard's standard protocol suite (Curve25519 key exchange, ChaCha20-Poly1305 encryption, BLAKE2s hashing) via a native iOS Network Extension. Verified end-to-end on a physical device: real handshake confirmed both client- and server-side, full-tunnel routing confirmed via the server's own packet counters. Explicitly Phase 1: single hardcoded test key pair, no consent or toggle UI, excluded from this build's entitlements. Server-side logging posture has not yet been audited the way the messaging server's has — treat it as unverified until it is.

Push Notifications — Content-Free by Design

Proven
Notifications tell you a message arrived. They never carry what it says.

When you get a Veil notification, it says someone sent you a message — never what the message contains. The actual content stays encrypted on your device and is never included in what we send to Apple's notification service.

Technical detail

Verified on a real physical device via a genuine EAS build, not a simulator result. The notification body is a fixed, generic string ("[name] sent you a message"); the real message text is never passed to the push-sending code path.

Block & Report — Without Breaking Encryption

Proven
Blocking is enforced by the messaging server itself, not just hidden in the app. Reporting only ever includes what you choose to share.

Blocking someone stops them at the server level — Veil's messaging server is told to ignore them for your account, the same mechanism the underlying protocol provides for this, not something we bolted on client-side that a modified app could ignore. Reporting a user works the way privacy-respecting messaging apps have to: since we can't read your messages, a report only ever includes what you explicitly choose to attach — you see exactly what would be sent before you send it, every time.

Technical detail

Block sets the account's m.ignored_user_list on the Matrix homeserver (server-enforced filtering, not a client-side list) and leaves the shared conversation. Report evidence, when included, is the already-decrypted plaintext as displayed on the reporting device — the encrypted content itself is never touched or decrypted by anything server-side. Reports are stored for 90 days for review.

Calls — End-to-End Encrypted

Proven
Voice and video calls are encrypted directly between your device and the person you're calling — a different mechanism than messaging, with one honest gap: no manual identity verification yet.

Calls use WebRTC with DTLS-SRTP encryption directly between your device and the person you're calling. There is no server in the call path that can decrypt the audio or video — our TURN relay, used only when a direct connection isn't possible, forwards encrypted packets it cannot read itself. That part is end-to-end encrypted — the same real guarantee messaging has. What calls don't yet have is messaging's device-level cryptographic identity: every Matrix conversation is tied to registered device keys for each Veil ID, while a call's signalling is authenticated only by a shared app secret, not by your specific identity. We also don't yet expose a way to manually verify device identity for calls (or messages) in the app — a real, open gap, not glossed over here.

Technical detail

WebRTC peer connections negotiate DTLS-SRTP automatically; media never transits in plaintext at any point between devices. The TURN relay only ever sees encrypted RTP packets when a direct peer connection isn't possible. Call signalling (offer/answer/ICE candidates) is authenticated via a shared Worker secret, not per-device Matrix keys — a real, different, weaker identity guarantee than messaging's Olm/Megolm device trust.

Mail — Zero-Access Architecture, Verified End-to-End

Proven
Mail between two Veil users is end-to-end encrypted. Mail from the outside world is encrypted the instant it reaches our server, before it's ever stored. Mail sent to a non-Veil address is protected in transit only — the same limitation every mail provider has.

Veil Mail follows the same zero-access model ProtonMail itself uses, verified against our real production server, not just designed. Mail between two Veil users is encrypted on your device before it's ever sent — our server never holds a readable copy, not even momentarily, the same guarantee messaging has. Mail arriving from outside Veil (Gmail, iCloud, Proton, anyone) is encrypted the instant it reaches our server, before it's written to storage — our server holds it in plaintext only for the fraction of a second the delivery itself takes, never at rest. Mail you send to someone outside Veil is protected in transit only (TLS), readable at their own provider the same way it would be anywhere else — a physical property of how ordinary email works, not a gap in our effort, and the same limitation ProtonMail states plainly for its own outbound mail.

Technical detail

Self-hosted Stalwart mail server, real JMAP backend. Client-side keypair (X25519, via libsodium's crypto_box_seal) generated and stored on-device at first Mail setup. Veil-to-Veil sends are sealed to the recipient's registered public key before sending. Outside-world mail is intercepted by a custom mail-server hook at the SMTP delivery stage — before the message is committed to any mailbox — which seals the body to the recipient's public key. Both flows verified end-to-end against the live server: a real external delivery and a real Veil-to-Veil send both decrypt correctly on the recipient's device.

Our philosophy

Technology should serve people. People should never become products.

Privacy is not a premium feature — it is a human right, recognised in Article 12 of the Universal Declaration of Human Rights. Veil exists to make that right practical in everyday life, and Veil Technologies Ltd is structured with a commitment to community benefit, not data extraction.

Privacy is yours

Your conversations, your keys, your history — held by you, not by us.

Evidence before claims

Nothing is advertised until the technology behind it is proven. Our evidence board is public.

Technology with conscience

Funded by the people who use it, with a share of revenue committed back to community benefit.

Early access

Ready when you are.

Veil is in active pre-release development by Veil Technologies Ltd, with a TestFlight beta as the next milestone.

Core app builtEncrypted messaging, calls, and anonymous identity — working on real devices.
Company foundedVeil Technologies Ltd, 2026.
Final verificationConfirming reliability across real device pairs ahead of beta.
TestFlight betaInvites go to the early access list first.
App Store launchiOS first. UK first.

Be first through the door.

Email us and you're on the early access list. True to form: we store your address for invitations only, share it with no one, and delete it on request.

Request early access

contact@veilsuperapp.com · support@veilsuperapp.com