WhishperLock
Whisper. Lock. Connect.
A privacy-first iOS messenger with encrypted text, files, locations, disappearing messages, and encrypted voice calls — protected by biometrics and built on a zero-knowledge server design.
What is WhishperLock?
WhishperLock is a real-time secure chat app for iPhone and iPad. You add friends, chat in private encrypted rooms, share encrypted files and locations, send self-destructing messages, and place encrypted voice calls. The server stores only encrypted payloads and cannot read your conversations.
💬 Encrypted Chat
Every text message is encrypted on your device with AES-256-GCM before it leaves your phone.
🔥 Self-Destruct
Messages that vanish after being read — from 5 seconds to 24 hours.
📎 Encrypted Files
Photos and documents encrypted before upload; decrypt with Face ID / Touch ID.
📍 Encrypted Location
Share your current location as an encrypted one-time message.
📞 Voice Calls
Real-time encrypted audio via WebSocket; integrated with Apple CallKit.
👥 Friends
Search users, send friend requests, see online status, and start private chats.
Complete User Guide — Table of Contents
- Getting Started & Sign In
- App Navigation & Tabs
- Friends, Search & Requests
- Private Chat Basics
- Reading Encrypted Messages
- Self-Destruct Messages
- Encrypted Files & Images
- Encrypted Location Sharing
- Encrypted Voice Calls
- Notifications
- Profile & Account Settings
- Subscription & Free Trial
- Network & Connectivity
- Security & Encryption
- Troubleshooting
- Privacy, Terms & Contact
1. Getting Started & Sign In
When you first open WhishperLock, you see the authentication screen with a dark glass-style interface.
Create an account (Register)
- Tap Sign Up (or switch from Login to Register mode).
- Enter a username, email, and password (and confirm password if shown).
- Tap the register button. On success, you are logged in automatically.
- Grant permissions when prompted: Notifications (recommended), and later Face ID, Microphone, or Location when you use those features.
Log in with email
- Stay in Login mode.
- Enter your email and password.
- Tap Login. Your session token is stored securely in the iOS Keychain.
Sign in with Apple
- Tap the Sign in with Apple button.
- Complete Apple’s authentication sheet (Face ID / Touch ID or Apple ID password).
- Choose whether to share or hide your email per Apple’s options.
- You are signed in without creating a separate WhishperLock password.
3. Friends, Search & Friend Requests
The Friends screen has three sub-tabs at the top:
Friends list
- Select the Friends tab.
- View all accepted friends with avatars and online indicators (green when connected via WebSocket).
- Tap a friend to open a private encrypted chat room.
- Long-press or swipe (where available) to remove a friend — confirm in the dialog. This removes the friendship on the server.
The list auto-refreshes periodically while the app is active.
Add Friend
- Select the Add Friend tab.
- Type a username in the search bar.
- Results appear as you search. Tap Add or Send Request next to a user.
- Wait for them to accept your request before chatting.
Friend Requests
- Select the Friend Requests tab.
- View incoming requests with sender username.
- Tap Accept to become friends and enable private chat.
- Tap Decline to reject the request.
When someone sends you a request, you may receive a push notification (if enabled).
4. Private Chat Basics
Each friendship has a unique room ID. Both users derive the same encryption key from this room ID — no key is sent over the network.
Opening a chat
- From Friends, tap your friend’s name.
- The app connects to the WebSocket for that room and loads message history.
- The top bar shows your friend’s username and a phone icon for voice calls.
- An End-to-End Encryption status bar appears above the input area.
Sending a text message
- Type in the message field at the bottom.
- Tap the send button (arrow).
- The message is encrypted locally, then sent through the server as ciphertext.
- Your message appears in the chat as an encrypted bubble until you or the recipient decrypts it.
Typing indicator
While you type, the other user may see a typing indicator when both are connected.
Deleting messages
- Long-press (context menu) on a message you sent or received.
- Choose Delete to remove it locally and request deletion on the server.
- Deleted messages sync to the other user in real time when connected.
5. Reading Encrypted Messages
Text messages display as locked encrypted bubbles with a shield/lock appearance.
Decrypt a message
- Tap the encrypted message bubble.
- Authenticate with Face ID, Touch ID, Optic ID, or device passcode when prompted.
- The decrypted text appears inside the bubble or in a detail view.
- Use Copy from the context menu to copy plaintext to the clipboard.
Encryption details screen
After decrypting, you may view encryption metadata (algorithm, room-based key derivation) in the decryption result UI for transparency.
6. Self-Destruct Messages
Self-destruct messages disappear after the recipient reads them and the timer expires.
Send a self-destruct message
- In the chat input bar, tap the flame icon (left of the text field).
- Choose a timer from the picker sheet:
| Option | Duration after read |
|---|---|
| 5 seconds | 5 sec |
| 10 seconds | 10 sec |
| 30 seconds | 30 sec |
| 1 minute | 60 sec |
| 5 minutes | 5 min |
| 10 minutes | 10 min |
| 30 minutes | 30 min |
| 1 hour | 1 hour |
| 24 hours | 24 hours |
- The selected time appears in a bar above the input. Tap the flame again to clear the timer.
- Type your message and send. The message is still fully encrypted.
- The flame icon stays highlighted while a timer is active.
Receiving & countdown
- Tap to decrypt the self-destruct message (biometric required).
- Once read, a countdown appears on the bubble.
- When the timer reaches zero, the message is removed from the chat.
Self-destruct with files or location
If you set a self-destruct timer before sending an attachment or location, that timer applies to that outgoing item as well.
7. Encrypted Files & Images
Send a file or photo
- In chat, tap the paperclip icon (next to the flame).
- Select a file or image from the iOS file picker / photo library.
- The app encrypts the file with the room key, uploads the ciphertext, and sends a reference message.
- Maximum raw file size is approximately 24 MB (to stay under server limits after encryption).
The paperclip is disabled when not connected to the server — wait until the connection indicator shows connected.
Receive & open a file
- Tap the encrypted file bubble in the chat.
- Authenticate with Face ID / Touch ID.
- The file decrypts and previews or opens. You may share the decrypted file to other apps from the share sheet where supported.
8. Encrypted Location Sharing
Send your location
- Tap the location pin icon in the chat input bar.
- Grant Location When In Use permission if iOS asks.
- The app fetches your current coordinates once, encrypts them, and sends as a message.
View a shared location
- Tap the encrypted location bubble.
- Authenticate with biometrics.
- View the location on the map inside the app. Open in Apple Maps if offered.
Location is embedded in the encrypted message — the server does not receive plaintext coordinates.
9. Encrypted Voice Calls
Start an outgoing call
- Open a private chat with your friend.
- Tap the phone icon in the top-right toolbar.
- The app sends a call offer over WebSocket. Wait for the other user to answer.
- When connected, the Active Call screen shows duration, mute, and speaker controls.
Receive an incoming call
- You may see Apple’s CallKit banner at the top (Accept / Decline) — even when the phone is locked.
- Alternatively, the full-screen Incoming Call UI inside the app appears with Accept and Decline buttons.
- Tap Accept on either the system banner or in-app UI — both connect through CallKit for proper audio.
- Tap Decline to reject.
During a call
- Mute — toggle microphone off/on.
- Speaker — route audio to speakerphone.
- End call — hang up; both sides return to chat.
How call encryption works
Audio is captured at 48 kHz, downsampled to 16 kHz mono PCM, encrypted with AES-256-GCM per packet, and sent over WebSocket. Audio is never stored on the server.
10. Notifications
Enable notifications
- Go to Profile tab → Notification Settings.
- Turn on Message Notifications.
- If iOS denied permission, tap Open Settings and enable notifications for WhishperLock.
What triggers notifications
- New messages when you are not viewing that chat room.
- Friend requests.
- Incoming voice calls (via VoIP push + CallKit).
Suppressed notifications
While you are actively viewing a chat, notifications for that room are suppressed to avoid duplicate alerts.
11. Profile & Account Settings
The Profile tab shows your “access card” with username and email.
Edit profile
- Tap Edit Profile.
- Update display fields (e.g., username) and save.
Log out
- Tap Logout.
- Your session ends; device tokens may be removed from the server. You return to the login screen.
Delete account
- Tap Delete Account.
- Read the warning: profile, messages, friends, and notifications will be permanently deleted.
- Confirm deletion. Email users must enter their password; Apple users confirm via Apple Sign-In.
12. Subscription & Free Trial
WhishperLock offers a 3-day free trial for new users, then optional subscriptions:
- Monthly —
com.whishperlock.subscription.monthly - Yearly —
com.whishperlock.subscription.yearly
Subscribe
- When the trial expires, a paywall or banner prompts you to subscribe.
- Open Profile → Manage Subscription or tap the trial banner.
- Select Monthly or Yearly, then tap Subscribe.
- Confirm with Face ID / Touch ID or Apple ID password through the App Store sheet.
Restore purchases
- On the paywall, tap Restore Purchases.
- Existing subscriptions linked to your Apple ID are restored.
Cancel or change plan
Use iOS Settings → [Your Name] → Subscriptions → WhishperLock. Apple handles billing and refunds per App Store policy.
13. Network & Connectivity
- The app monitors network status and may show alerts when offline.
- WebSocket reconnects automatically with backoff when the network returns.
- In background, heartbeat intervals extend to save battery while keeping sync where possible.
- Background tasks sync messages, refresh tokens, and clean up expired data per iOS background scheduling.
If messages stall, pull to refresh or leave and re-enter the chat to force reconnect.
14. Security & Encryption
| Feature | Technology |
|---|---|
| Message / file / location encryption | AES-256-GCM (CryptoKit) |
| Key derivation | SHA-256(roomId) → 256-bit symmetric key |
| Key storage | iOS Keychain (device-only when possible) |
| Voice call encryption | AES-256-GCM per audio packet |
| Transport | HTTPS / WSS (TLS) |
| Password storage (server) | Hashed (PBKDF2); not plaintext |
| Session tokens | JWT; stored in Keychain on device |
| Biometric gate | Face ID / Touch ID / Optic ID for decrypt |
Both chat participants independently compute the same room key — no key exchange over the network. The server stores ciphertext only and cannot decrypt your content.
15. Troubleshooting
| Problem | What to try |
|---|---|
| Can't log in | Check email/password; try Sign in with Apple; ensure network is available. |
| Messages won't send | Wait for WebSocket “connected”; check network alert; restart app. |
| Decrypt fails | Re-authenticate biometrics; ensure correct chat room with that friend. |
| No push notifications | Profile → Notification Settings; iOS Settings → Notifications → WhishperLock. |
| Call won't connect | Allow Microphone; answer via CallKit or in-app Accept; stay on stable Wi‑Fi/cellular. |
| Subscription not active | Restore Purchases; check Apple Subscriptions settings. |
Still need help? Email aaronyang470128@hotmail.com or visit the Support page.
16. Privacy, Terms & Contact
Apple App Store and privacy regulations require public links to:
- Privacy Policy — what data we collect, how we use it, and your rights.
- Terms of Service — rules of use, subscriptions, and liability.
- Support — FAQs and contact information.
Developer contact:
Aaron Yang
Email: aaronyang470128@hotmail.com