Buzzio documentation
Site: doc.buzzio.dev · Product: buzzio.dev · Support: support.buzzio.dev · Status: status.buzzio.dev · Updates: update.buzzio.dev · Developers: developers.buzzio.dev · Stickers: sticker-api.buzzio.dev · Forum: forum.buzzio.dev · All official sites
Buzzio is a privacy-first messenger with two product lanes: a Privacy section (sealed — 1-to-1, E2E groups, Whisper private chat) that aims to be a blind relay, and a Feature mode (shared — open-history groups, Communities, Broadcast) that stores more by design — and says so. Data is never sold.
Who this site is for
| Audience | Start here |
|---|---|
| New users | Quickstart → FAQ |
| Privacy-focused readers | Privacy guarantees → What Buzzio can see → Threat model |
| Developers / researchers | How to verify → Verify zero metadata → Crypto → Developer integrations → Crypto OSS · Client OSS |
| Press / auditors | What Buzzio can see → Privacy guarantees → Protocol one-pager → How to verify → Independent security audit → Security disclosure |
Start here
- Quickstart — install, create identity, send a first sealed chat
- Download and requirements — platforms and age rules
- Move to a new phone — restore identity and history
- Protocol one-pager — sealed-path diagram + Privacy vs Features · PDF download
- Glossary — Buzzio ID, sealed, sealed sender, Whisper, Secure View, and more
- Sealed vs shared — which features are operator-blind
- Privacy guarantees — promises, ceilings, and product refusals
- How Buzzio approaches privacy — mechanisms behind the claims
- Why E2E chat is not on the web — linked web companion vs sealed phone chat
Verify claims
| Check | Page |
|---|---|
| Zero durable chat metadata (1:1 & Whisper) | Verify zero metadata |
| Open-source crypto + client tests + claim ceilings | How to verify |
| Plain-language encryption | Encryption in plain language |
| What operators / infra can see | What Buzzio can see |
Browse by topic
| Topic | Pages |
|---|---|
| Privacy | Guarantees · What we can see · Verify zero metadata · Approaches privacy · Sealed vs shared · Why not unidentified delivery · Zero metadata |
| Architecture | System · Delivery path · One-pager + PDF · Shared media dedup |
| Cryptography | Plain language · Overview · How to verify · Crypto OSS · Client OSS · X3DH / Double Ratchet · Sealed sender · Groups |
| Features | 1-to-1 · Calls · Whisper · Groups · Communities · Broadcast · Stories · Bots · Privacy notices · Note to Self · Saved Messages · Official chat · Vault · Wallet · More |
| Developers | Overview · Bot API · Worker bots · Sticker import · developers.buzzio.dev · sticker-api.buzzio.dev |
| Trust | Privacy guarantees · Threat model · Independent security audit · vs Signal / WA / Telegram · Security disclosure |
| Reference | Retention · Premium and quotas · Subprocessors · Data safety · Legal · Changelog |
| Help | FAQ · Troubleshooting · Safety · Delete account · Status (docs note) · Updates · Support · Forum · Contact · Official sites |
Honest ceilings (read once)
- Buzzio does not claim Tor-grade network anonymity.
- “Zero metadata” is scoped — see definition.
- Sealed sender write cutover is complete on 1:1 (legacy plaintext-
fromwrites off). - Open-history groups, Communities, and Broadcast use TLS in transit but store text and media without at-rest encryption; Buzzio can read them. Shared-room media dedup is Phase 1+2 in source / rolling out.
- Private Vault and backup optionally use separate, domain-separated wrapping keys derived locally from the account seed; the phrase is never uploaded.
- Full promise / refusal table: Privacy guarantees.
Full reading order: INDEX