They told Google Play they collect nothing. They told the FAQ they keep the messages.

Kloak’s privacy story has three narrators: the marketing site, the FAQ accordion, and the Play Store Data safety form. They do not agree. The operators can still read the messages.

What they say they collect

FAQ, “What data does Kloak collect about me?”

Kloak collects the minimum required to operate the service: your username, a one-way hash of your secret key, your messages and content, optional profile information you choose to add, and server membership records. No email address, phone number, real name, location, or biometric data is ever collected. Unlike most platforms, we also collect zero analytics, tracking pixels, or behavioral data.

Privacy policy, last updated January 2025, a year before About’s January 2026 “quiet” opening:

We collect only what is absolutely necessary: your username (chosen by you), a hash of your secret key (one-way encrypted), your messages and content (to deliver them), optional profile information (you control it), and server membership records (to show you your servers). That’s it.

Play Store, official Android app, Data safety, still live in September 2026:

No data shared with third parties. No data collected.

One of those documents is a store listing filled in as if the app were a calculator. The other two admit a chat archive.

What “encrypted” means here

FAQ, “Is my data encrypted?”

Your secret key is hashed using SHA-256 before being stored. We never see or store your actual key. All data is transmitted over encrypted HTTPS connections. We are currently working toward implementing end-to-end encryption for messages, which will ensure that only the intended recipients can read them. We will always be transparent about exactly what level of encryption is in place.

TLS to a server that can read the body is how Discord works. SHA-256 of a login secret is a password hash with a prettier name. The Join page still talks about Signal Protocol, Sender Keys, and libsodium as the work of a role they are hiring for. About estimates six months to two years. AlternativeTo listed “End-to-End Encryption” as a Kloak feature anyway.

A founder, quoted from inside the product on Hacker News, skipped the slogan:

Messages are stored on our servers and are technically accessible at the database level, we won't pretend otherwise. … But we're not there yet, since after all we need to make sure the platform is safe and not to shield illegal content being sent.

That last clause is the trade they made: keep the logs so staff can moderate, then sell the app as a place that does not watch you. Child-safety policy says they cooperate with law enforcement. You cannot hand over what you cannot read. They can read it.

The secret key is the account

Show HN, lakshikag, early 2026: “There is no recovery mechanism… If the key is lost, the account is gone. This is intentional.” Official YouTube tutorial: same warning. About, later: they are “designing a recovery system” because “encryption that locks you out permanently is not a solution, it is a different problem.” The FAQ now says you can rotate the key from settings, and that they cannot show the raw key because only a hash is stored. Cookie policy says Local Storage holds “your authentication key (so you stay logged in).”

So the key is: generated once, pasted to log in, kept in the browser, hashed with SHA-256 on the server, and fatal if lost, except when they add recovery, which they have not finished. February 2026, users on r/discordsucks reported the login form calling valid keys invalid after strangers appeared in private servers. That week is its own page.

Third parties, from the file they shipped

Cookie policy: “Each one is another company with access to your data. We built everything in-house.” Production index.html Content-Security-Policy, 20 September 2026, still allows:

HostRole
foquucurnwpqcvgqukpz.supabase.coHosted backend, named in the FAQ (AWS EU West). A vendor. Message content is still readable by Kloak.
hcaptcha.comRegistration captcha. Device and bot scoring.
api.giphy.com / media*.giphy.comGIFs.
static.klipy.comMore media.
fonts.googleapis.comInter, loaded on a site that sells “no tracking.”
kloakweb.b-cdn.net / kloakcdn.b-cdn.netBunny CDN.
kloak-ws.fly.devWebsocket.
api.pocketsflow.comPayments infrastructure.
api.kibun.social / livekit.kibun.socialLiveKit voice on the founder’s earlier product domain.
YouTube, Vimeo, Steam, Spotify, SoundCloud, Twitch, KickEmbeds.

Buy Me a Coffee is a further processor for donations. The FAQ admits donors “interact with Buy Me a Coffee’s own platform, which has its own privacy policy and terms.” Cloudflare terminates TLS for kloak.app. None of this is evil in a normal web app. It is fatal to the sentence “your conversations shouldn’t pass through a dozen different companies.”

Ghost channels, still on a server

Official YouTube: Ghost Channels are “fully anonymous spaces. No usernames, no profiles, no history attached to you.” Hiding a username from other members is not the same as hiding the text from Kloak. The founder already said message content is accessible at the database level. Anonymity toward other users is not anonymity toward the operator.

Age 13, unverified, on purpose

Terms: you must be 13, and under 18 you need a parent. “We don’t verify age because that would require collecting personal information, which defeats the purpose of a privacy-first platform.” Play Store rating: Parental Guidance, Users Interact. Child-safety page: zero tolerance, reports, law enforcement, safety@kloak.app. They will not collect a date of birth. They will keep the messages. Those two choices sit in the same legal folder.

The policy date

Privacy, terms, and cookies all say “Last updated: January 2025.” About says the product opened in January 2026. The Hacker News account that launched Kloak was created 12 January 2025. Either the legal pages were written a year before the “quiet alpha,” or the date is leftover copy that nobody bumped. Child safety was updated July 2026. The other three were not.

Next: who ships this