BongoChat is engineered with security at its foundation. Every message, call, and file is protected by end-to-end encryption — we cannot read your conversations, and we never will.
Every security feature listed below is enabled by default. You do not need to configure anything — your protection begins the moment you create an account.
Every message, photo, voice note, and file is encrypted on your device before it is transmitted. Only you and the intended recipient possess the keys required to decrypt and read the content. BongoChat servers relay encrypted ciphertext but cannot decrypt it — this is guaranteed by the cryptographic design, not by policy alone.
Add an extra layer of physical security to BongoChat. Lock the entire app with your fingerprint, Face ID, or a custom PIN — so even if someone gains physical access to your unlocked phone, they cannot open your chats, view your contacts, or access any of your data. The biometric lock activates automatically after a configurable inactivity period.
Enable auto-delete for sensitive conversations by setting a timer — choose from 5 seconds to 1 week. Once a message is read and the timer expires, it is cryptographically erased from both your device and the recipient's device. Deleted messages are overwritten at the storage level and cannot be recovered by anyone, including BongoChat.
Every voice and video call on BongoChat is protected with the same end-to-end encryption as your text messages. Audio and video streams are encrypted in real time using SRTP (Secure Real-Time Transport Protocol). Call metadata (who you called, when, and for how long) is temporarily logged but is not linked to the content of your conversation. Group calls support up to 50 participants with full E2EE.
Every account is verified via SMS or phone call to ensure authenticity and reduce spam. Additionally, each conversation has a unique "Safety Number" — a fingerprint that you and your contact can verify out-of-band (in person or via another channel) to confirm that no man-in-the-middle attack has occurred. If a Safety Number changes, BongoChat will notify you immediately.
We collect only what is strictly necessary to operate the service. Your chat messages, voice calls, video calls, and shared files are never stored on our servers — they exist only on the sender's and recipient's devices. We do not build advertising profiles, do not serve targeted ads, and do not sell your data to any third party, ever. IP addresses are temporarily logged and purged within 90 days.
Your Device
Encrypted on device
Plaintext → AES-256-CBC → Ciphertext
BongoChat Server (relay only)
a7#k9$z1...xQ2! — unreadable
Decrypted on recipient
"Hello!" — readable only here
Recipient's Device
When you send a message on BongoChat, it is encrypted into an unreadable format on your device using the recipient's public key. It travels through our servers as ciphertext and is only decrypted when it arrives on the intended recipient's device using their private key — which never leaves their device.
Keys never leave your device
Your private encryption key is generated on your device and is never transmitted to our servers. BongoChat does not possess a copy of your keys, making it mathematically impossible for us to decrypt your communications — even if compelled by any authority.
Protection from server breaches
Even if BongoChat's servers were compromised, the attacker would only find encrypted ciphertext — the data would remain unreadable without the private keys that exist only on users' personal devices.
Forward secrecy
BongoChat uses the Double Ratchet Algorithm, which generates a new encryption key for every message. If a single key is compromised, only that specific message — not past or future messages — can be decrypted.
Applies to everything
Text messages, group chats, voice notes, file transfers, voice calls, and video calls are all protected by default. There is no way to disable end-to-end encryption on BongoChat.
Beyond encryption, BongoChat provides multiple layers of account security to ensure that only you have access to your profile, contacts, and conversations.
Add a custom 6-digit PIN to your account registration process. After verifying your phone number via SMS, you will be asked for this PIN before you can access your account on a new device. This means that even if someone obtains your SIM card, they cannot register your BongoChat account without the PIN.
View and manage all devices currently linked to your BongoChat account. You can see the device model, last active time, and IP address of each linked session. If you notice any unrecognized device, you can instantly log it out with a single tap. BongoChat supports linking up to 4 companion devices (desktop, tablet, etc.) simultaneously.
Lost your phone? Had your device stolen? You can remotely log out of BongoChat on any device by contacting our support team with your registered phone number and verifying your identity. Once confirmed, all active sessions will be terminated immediately, and the device will be deregistered from our system.
BongoChat notifies you immediately whenever your account is registered or accessed on a new device. This alert includes the device model, location (when available), and timestamp. If you receive a login notification for a device you do not recognize, you should change your 2FA PIN and contact support immediately.
You have full control over who can contact you. Block any user to prevent them from sending you messages, calling you, or seeing your profile. You can also report accounts that violate our community guidelines. Our trust and safety team reviews all reports and takes appropriate action, which may include warnings, temporary suspension, or permanent removal.
Every one-on-one chat has a unique 60-digit Safety Number (or QR code) derived from the public keys of both participants. You can verify this number by comparing it with your contact in person or through a trusted out-of-band channel. If a Safety Number changes at any point — for example, if a contact reinstalls BongoChat — you will receive an immediate in-chat warning.
Security at BongoChat is not a single feature — it is a multi-layered system designed to protect your data at the application, transport, and infrastructure levels.
| Data Type | In Transit | At Rest (Device) | At Rest (Server) |
|---|---|---|---|
| Chat Messages | E2EE (Signal) | SQLCipher / Keychain | Not stored |
| Voice & Video Calls | E2EE (SRTP) | Not stored | Not stored |
| Shared Files & Media | E2EE (Signal) | SQLCipher / Keychain | Not stored |
| Moments & Stories | TLS 1.3 | SQLCipher / Keychain | AES-256 |
| Account Profile Data | TLS 1.3 | SQLCipher / Keychain | AES-256 |
As a locally developed platform by Bongo Software Limited, we understand the importance of keeping Bangladeshi data within local jurisdiction. Our servers are located in Bangladesh or in jurisdictions that provide an adequate level of data protection as recognized under the Personal Data Protection Act 2023. We are committed to complying with all local data protection regulations, ensuring that your digital rights are protected under the laws of Bangladesh.
We believe in transparency and actively encourage the security research community to help us identify and resolve vulnerabilities before they can be exploited. If you discover a security issue in BongoChat, we ask that you report it responsibly so that we can address it promptly and protect our users.
Report the vulnerability to [email protected] with a detailed description, steps to reproduce, and potential impact.
Do not publicly disclose the vulnerability until we have resolved it and notified affected users. We commit to responding within 3 business days and resolving critical issues within 7 days.
Eligible researchers who follow our guidelines may receive public acknowledgment on our security page and BongoChat-branded merchandise as a token of our appreciation.
3-Day Response
We acknowledge all vulnerability reports within 3 business days.
7-Day Critical Fix
Critical vulnerabilities are patched and deployed within 7 days.
Researcher Recognition
Qualifying researchers receive public credit and BongoChat merchandise.
No Legal Action
We will not pursue legal action against researchers who follow our responsible disclosure guidelines in good faith.
Regular Audits
We conduct periodic third-party penetration testing and code audits to proactively identify weaknesses.
Whether you have a question about our security practices or want to report a vulnerability, our team is here to help.
বঙ্গোচ্যাট বিনামূল্যে পান
গুগল প্লে-তে উপলব্ধ