Minimisation, not an invisibility claim
Direct identifiers have been removed from several stored communication paths or replaced by opaque conversation-scoped references. Signed authorship can reside inside protected payloads.
The running service still sees relationships and technical metadata required for routing, membership and operations. A fully metadata-free service is not claimed.
Affected timestamps are reduced to minute granularity. Local drafts, interface preferences and safety verification are account-scoped; revoked-account traces are removed selectively without indiscriminately deleting a second account's data in the same browser.
In the current source/test state, the cold-start possession proof reconstructs the opaque identifier directory from encrypted account state and counts only proofs actually sent. History transfers without a target mark are skipped rather than guessed; the live signed runtime requires a separate app release and migration for these changes.
Profile images are a separate boundary: retrieval requires authentication and storage is protected at rest, but the images are not end-to-end encrypted and remain readable to the service.
Public website
The product website uses no external advertising trackers. Its own audience measurement works without cookies or personal data, counts daily totals only and is documented separately.
Review the claim independently.
Review the Evidence Center, documentation and operational status together.
