Changelog

Release notes

What shipped, when. Changes with security consequences are called out explicitly rather than folded into “bug fixes and improvements”, and material revisions to policies or the threat model are logged here too.

This log starts at the public beta. Closed-beta builds are not listed. See the roadmap for what is coming.

Current

Open Beta Update 1.0.3

The first update since the public beta. It brings the fixes from our internal security review of the Android and iOS clients, a guided first run, and a round of changes requested by beta testers.

Features

  • Step-by-step onboarding: new users set their name, photo and a PIN, with an explanation of what the PIN protects, then land on Chats.
  • Simplified Chinese. Strings that were missing in the other languages are now translated.
  • Send without notification: long-press the send button.
  • Sending an invite opens the chat with that person, which shows whether the invitation is still pending or was declined. The new-chat picker has an “Invite new person” tile.
  • A chat whose contact was deleted now says so and offers to delete the chat, instead of waiting for a secure session that will never come.
  • Auto-delete now runs while the app is closed, scheduled by the operating system, and catches up whenever the app starts, returns to the foreground or is unlocked.
  • Auto-delete periods now run from 24 hours to 2 weeks, and new accounts default to 2 weeks. Longer existing settings are shortened to 2 weeks; an update never lengthens how long your history is kept.

UI/UX improvements

  • The day label stays pinned to the top of a chat while you scroll.
  • Chat font setting: a text size for chat threads, applied on top of the system font size.
  • Your avatar appears on the Profile tab, and cropping a photo saves exactly what the circle shows.
  • Notebook rows show their first attachment as a tile. Saving to a new note keeps the text, and attachments sent from the notebook keep their file names.
  • Redesigned PIN keypad, with larger keyboard keys that are easier to hit. The keypad always opens on numbers, so it no longer shows anyone holding the phone whether your PIN contains letters.
  • The whole app now works on small phones and at large system font sizes.
  • Taking a photo or picking media no longer locks the app behind the picker, and recording a video gets five minutes before the app locks.
  • Turning several protections off in a row asks for your PIN once, then accepts further changes for 30 seconds. Terminating the account always asks.
  • The voice recorder no longer jitters under a held thumb.
  • iOS: Face ID no longer freezes the unlock screen, there is no black screen after Face ID on a cold start, Home no longer freezes when you come back to it, and tab bar icons no longer jump.

Security updates

  • Every protocol command is now checked against its authenticated sender, so one contact cannot send a command that appears to come from another.
  • Safety numbers to verify a contact, and a warning when a contact’s key changes.
  • Wrong PINs are now limited: a maximum you choose (3 to 10, default 5), with growing delays and an option to erase the app’s data after the last attempt. The erase option is on for new accounts and offered to existing ones. Weakening a security setting asks for your PIN again.
  • Downloaded attachments are checked against a hash declared by the sender.
  • Data at rest: stored encryption sessions are now encrypted, and your long-term private key is no longer kept inside them. The database zeroes deleted content, keeps its temporary data in memory, and clears its write-ahead log every time the app locks. Queued uploads are stored encrypted, and leftover temporary files are removed at startup.
  • Keylane data is excluded from device backups and phone-to-phone transfers. On iOS, the account store and attachments use the strictest Data Protection class, so they cannot be read while the phone is locked.
  • Lock: an incoming call no longer opens a locked app. App content is hidden from the app switcher, including Android’s live Recents preview. A call link opened while the app was locked no longer dials by itself after you unlock.
  • Calls: the incoming-call screen never shows a caller name supplied by the server, and Keylane calls are kept out of the iOS Recents list.
  • Passwords and other secrets copied from the notebook are hidden from clipboard previews and keyboard suggestions, never sync to your other devices, and clear from the clipboard after 60 seconds.
  • Release builds no longer write app logs, and log lines that could carry message content were removed.
  • A malformed or hostile message can no longer crash the app through a crypto error or an oversized image.
  • Attachments and directory lookups for contacts on other servers now go through your own server, so a foreign server never sees your device’s address.

Public beta

Keylane leaves closed beta. Android and iOS clients are available to everyone, with no invite required.

Added

  • Public availability on Google Play and the App Store
  • Open registration — no invite code required to create an identity

Documentation

Known limitations

  • No independent security audit has been completed. One is being commissioned.
  • Full client source is not yet published. The Kodium crypto core is public under the Apache License 2.0.
  • Self-hosting is not yet available as a packaged release.
  • No desktop client.

Contact forms replace mailto links

  • Every “email us” link on the site now goes to a contact form — support, feedback, security reports, legal requests, press, brand assets, commercial and self-hosting enquiries, and website corrections. It posts to our own function on this domain and is relayed to us by email; no third-party form service is involved, nothing is stored in a database, and your IP address is written neither to the email nor to our logs. The privacy policy now describes exactly what the form processes.
  • Addresses are still published where a form is the wrong instrument: the data controller card on the policy pages, legal service, and security.txt.

Secure notebook

  • Private notes and credentials can now be kept in the app, under the same on-device encryption as your messages. Notebook entries never leave the device and are covered by the same PIN.
  • The notebook sits outside history expiry, by design: whatever you write there or copy into it stays until you delete it from the notebook yourself. Expiring messages, clearing a chat, and deleting a contact together with their media all leave notebook entries untouched — it is complementary long-term storage, not a copy of your history.

Donations are live

  • Voluntary donations are now open via GitHub Sponsors, Ko-fi, or direct SEPA transfer — details on the pricing & funding page. A donation carries no perks and changes nothing about an account: it pays for the public relay, and privacy is not a tier.

Website corrections

  • Revised the pricing & funding page: free-network allowances are now described as generous fair-use rather than “no cap”, with any future change announced here first; noted that calling has shipped and is free on the public relay during the beta; added a commitment to disclose any accepted public-interest grant on that page.
  • Corrected pages that described multi-device linking as already available (support, download, and the Keylane ID guide). A Keylane ID lives on exactly one device today; multi-device remains on the roadmap.
  • Corrected the site footer: “Keylane” is a trademark of Livotov Labs Ltd., not yet a registered one.
  • Corrected the licence stated for the Kodium cryptographic core throughout the site and the terms of service: it is published under the Apache License 2.0, not GPLv3.

Policy update

  • Documented the abuse-reporting path in the terms of service and privacy policy, covering what a report contains and how it is handled given that we cannot read the reported conversation.

Cryptography whitepaper

  • Published the protocol specification: identity, proof-of-possession authentication, PQXDH key exchange, payload encryption, group fan-out, zero-knowledge routing, attachments, and privacy-preserving push.

How we log changes

Security-relevant fixes are described here rather than shipped silently, including those reported by outside researchers, who are credited unless they ask not to be.

Material revisions to the threat model, the privacy policy, or the funding model are logged here as well. A promise that can be quietly edited is not a promise.