FlatFold
An end-to-end encrypted messenger where the server holds nothing it can read — including your history.
contact
Get help with FlatFold
Email is the fastest route, and it always works — the form below is a convenience, not the only way in.
A first reply within two business days, from anmol@ponderance.dev.
Send a message
It reaches the same inbox, tagged with FlatFold.
Common questions
I forgot my password. How do I get back in?
You cannot, and neither can Anmol. Your messages and contacts are encrypted with a key derived from your password, which never leaves your device — so there is no reset, no escrow, and no backup. A forgotten password means that history is gone for good; the only way forward is a new account.
Why is that the design?
A reset link would mean the server could hand your history to whoever holds your email — which is exactly the power this app is built not to have. The unrecoverable password is the price of the server being unable to read anything.
How do I add someone?
Type their exact username. There is no directory and no search, because a searchable list of users is itself a leak — so you need to get the username from them some other way.
Can I read my old messages on a new device?
Sign in with the same username and password and your history decrypts locally on that device. Anything that only existed on a device you no longer have, and was never synced, stays there.
What does the server actually store?
Your username, a verifier derived from your password (not the password), the public keys you publish, and undelivered messages as ciphertext — deleted once your device confirms delivery, and in every case within 14 days. The transparency page spells this out.
Do notifications leak my messages?
No. If you turn them on, the push subscription carries no message content — only that something arrived.
When something goes wrong
in the order it actually failsA message won’t send
- Check that the recipient username is exact — a near-miss is a different account, not an error.
- Reload the page: the encrypted session is re-established on load, and a stale tab is the most common cause.
- Confirm the other person has signed in at least once, so they have published the public keys your device needs.
- If it still fails, email anmol@ponderance.dev with the time and your username. Never send your password — it is not useful to anyone, including Anmol.
Your data
- Your messages, contacts, and history are encrypted on your device with a key derived from your password and never leave it in readable form.
- The server keeps your username, a password verifier, your public keys, and ciphertext waiting for delivery — nothing it can read.
- Undelivered messages are deleted once your device confirms it received them, and in every case within 14 days. Attachments are deleted once fetched.
- IP addresses are never logged.
- To delete an account, email anmol@ponderance.dev from a device signed into it. The encrypted history on your own device goes when you clear that browser’s storage.
Known issues
said here so you don’t have to ask- There is no password reset and there never will be — this is the design, not a missing feature. Write your password down somewhere safe.
what you need
Requirements
- Any modern browser.
- A username and a password you can remember. The password is the key — read the next section before you pick one.
- The exact username of anyone you want to talk to; there is no directory to search.