What is zero-knowledge messaging?
"Your privacy matters to us" is on the website of roughly every company that has ever sold your data. So when we say Queso is zero-knowledge, it's fair to ask what that actually means — and whether it's a promise or an architecture. Here's the plain-English version.
"Won't" versus "can't"
Most privacy promises are about restraint: a company holds your data and pledges not to misuse it. That's a policy, and policies can change, leak or be compelled. A stronger model removes the temptation entirely by making sure the company never holds anything readable in the first place. That's the difference between "we won't read your messages" and "we can't." Queso is built around can't.
End-to-end encryption, briefly
When you send a message on the Queso Network, it's encrypted on your device and only ever decrypted on the recipient's. In between, it's gibberish. The server that passes it along — the "relay" — never holds the key, so it can't turn that gibberish back into words. This is end-to-end encryption, the same idea behind Signal.
What "zero-knowledge relay" means
Our relay's job is simple: hold an encrypted message until the recipient is online, hand it over, then forget it. What makes it zero-knowledge is what it never learns:
- It only sees ciphertext — never the content of a message.
- Messages are addressed to a one-way-hashed mailbox, not a name or number, so the relay can't build a social graph.
- Undelivered messages are stored as encrypted blobs with a short lifetime and deleted the moment they're delivered.
- There are no accounts, phone numbers or contact database to leak.
"Zero-knowledge" here means zero knowledge of your plaintext — not that nothing passes through, but that nothing meaningful can be read from it.
Why the Double Ratchet matters
Queso uses the Double Ratchet, the protocol popularised by Signal, for conversations on its network. Its superpower is forward secrecy: the keys change constantly, so even if one key were somehow exposed, it couldn't unlock the messages before or after it. Under the hood, Queso builds this on Apple's CryptoKit using well-studied primitives — X25519 key agreement, HKDF, HMAC and ChaCha20-Poly1305 — with separate signing identities and safety numbers you can check to confirm you're talking to the right person. (More detail on our security page.)
What about translation?
Translation is the interesting edge case, because to translate text, something has to be able to read it. Queso's answer is to give you the choice. Free, on-device translation never sends anything — it runs entirely on your iPhone. If you want AI translation, our gateway carries only the text to translate and a short-lived token that proves the request came from a genuine copy of the app (via Apple App Attest) without telling us who you are. No name, no number, no logs of your message content.
And if "can't" still isn't enough
For organisations in law, finance, healthcare or government, even a zero-knowledge relay run by someone else can be one trust assumption too many. So the Queso relay is self-hostable: run it on your own server, or fully on-premises, and the encrypted messages never touch anyone else's hardware at all.
Privacy shouldn't rest on a company's good intentions. It should rest on maths and architecture. That's the bar we set for Queso — and it's coming soon.
More reading: How Queso keeps you safe · Why we built Queso