Security
Last updated 24 September 2026
What Fariin does to keep your conversations private, what it cannot see, and how to tell us if you find a problem.
Encrypted end to end
The contents of your messages and calls are encrypted on your phone before they leave it. The key that opens them exists only on the phones in the conversation. We cannot read your messages, see your photos or listen to your calls, and neither can anyone who breaks into our servers.
Everything in transit is also carried over an encrypted connection, so the encrypted message travels inside a second layer of encryption.
What we can see
To run an account and deliver a message we hold a small amount of information: who you are, which devices you use, and when something was sent. The privacy policy lists all of it, and says how long each part is kept.
Your account
- Fariin never asks for your phone number and never uploads your contacts.
- You can protect your account with a passkey and with two-step verification, an extra password of your own.
- You can lock the app with Face ID, Touch ID or your passcode.
- You can see every device signed in to your account, and sign any of them out, in Settings.
- You can check that a conversation is really with the person you think by comparing a safety number with them.
How the service is protected
- Database rules are enforced by the server, so one account cannot read another's data even with a modified app.
- Access to the servers is limited to the person who runs Fariin and protected by two factor authentication.
- If there is ever a breach that puts your data at risk, we will say so. The privacy policy sets out how and when.
No system is beyond breaking. What end to end encryption buys you is that a breach of our servers still does not expose what you said.
Report a security problem
If you find a weakness in Fariin, the app, this website or the servers behind them, write to support@fariin.com with "Security report" in the subject. Tell us what you found and how to reproduce it.
- We will reply to confirm we have it, and tell you when it is fixed.
- Please give us a reasonable time to fix it before telling anyone else.
- Do not read, change or delete other people's data while testing, and do not disrupt the service. Research done in good faith within these limits will not be pursued.