Security
Encryption & privacy
We say this plainly, to developers and to users: chats with businesses are not end-to-end encrypted.
Why#
Personal QuiC chats use the Signal Protocol: only the people in the chat hold the keys. A business chat has to reach your servers so your software can read and answer it, so it can't be end-to-end encrypted between the person and a device. Apps are never added to people's end-to-end encrypted chats or groups.
How business chats are protected#
- Encrypted in transit with TLS, between the person's device, QuiC and your webhook (HTTPS only).
- Encrypted at rest on QuiC's servers (AES-GCM), like other QuiC data.
- Webhooks are signed so you can prove an event came from QuiC; your signing secrets are stored encrypted.
- API keys are stored as hashes. QuiC can't show you a key again — only its prefix.
Who can read a business chat#
- The person, and your business — including anyone and any service you pass the messages to.
- QuiC's systems, to deliver messages, keep abuse under control and meet legal obligations.
What you must do#
- Publish a privacy policy that covers messages people send you on QuiC, and make it easy to find from your website.
- Collect and keep only what you need. Delete data when a person stops or blocks you, or asks you to.
- Keep API keys and webhook secrets on your servers, and rotate them if they leak.
What you learn about people#
You get an appUserId — a stable id that is different in every app, so ids can't be matched across businesses. You don't get a phone number, email or QuiC profile unless the person tells you in the chat. (Internal live apps may address people in their own organization by work email; the reply still identifies them only by appUserId.)