{"blind_signature_key_id":"25f7bb37749355614e24d749df48efd1bca1c3ca24de5810991875e8fcc23d52","cache_secs":60,"generated_at_ms":1789119077964,"holds":{"active_sessions":0,"blind_mailbox":{"addresses":0,"fields":["opaque 32-byte address (rotating, not invertible to a user)","fixed-size AEAD blob","hour-coarse timestamps","insertion sequence"],"items":0,"note":"offline ciphertext storage has no sender or recipient column; authenticated requests, IP addresses, timing and address lookups can still reveal relationships","retention":"auto-deleted 30 days after deposit or on acknowledgement"},"devices":{"count":0,"fields":["device_id","platform","created (rounded to the day)","revoked"]},"discoverable_handles":{"note":"opt-in only (B-023): HMAC of the handle, the identity, and a masked request token — each handle proven by a code sent to it"},"identities":{"count":0,"fields":["user_id","ed25519 public key","created (rounded to the day)","last seen (rounded to the hour)"]},"one_time_prekeys_available":0,"pending_verifications":{"count":0,"fields":["HMAC of contact","HMAC of code","expiry"],"retention":"purged 24h after expiry"},"public_key_bundles":{"count":0,"fields":["signed public prekey bundle per device (opaque)","timestamps rounded to the hour"]},"spent_registration_tokens":{"count":0,"fields":["SHA-256 of token","day spent"],"note":"unlinkable to the contact that obtained it (RFC 9474 blind signature); kept for the lifetime of the signing key so a token can never be replayed"},"verified_contacts":{"count":0,"fields":["HMAC of contact","how many registration tokens issued","day of last issue"],"note":"registration does not store an identity link here; day-coarse timestamps reduce timing precision but do not prevent correlation; opt-in discovery separately links a handle HMAC to an identity"}},"in_front_of_the_server":{"database_encryption_at_rest":"innodb_encrypt_tables with a keyfile on the same host: this protects a stolen disk or datadir copy, not a compromised running host","nginx_access_log":"The supplied deployment disables access logs on /v1/keys, /v1/mls, /v1/mailbox, /v1/rendezvous, /v1/discovery and /v1/invite. Other routes can log IP, status, method and path. Daily rotation keeps two older copies, including rotation of empty logs; retention depends on the operator running logrotate. Upstream proxies may log separately.","nginx_error_log":"The supplied deployment discards error logs on those sensitive API paths. Other error logs can include request paths and IP addresses."},"never_holds":["plaintext message bodies","users' private end-to-end encryption keys","plaintext contact lists and group names","plaintext file and media payloads"],"observable_metadata":["IP addresses, request timing, authenticated device identity, key lookups and mailbox retrieval addresses can be correlated","plaintext phone numbers or e-mail addresses are processed transiently for verification delivery; persisted contact values use HMAC","opt-in discovery stores a handle HMAC linked to an identity","some creation and activity timestamps are coarse; challenges, expiry, revocation and administrative records can have finer timing","the server holds its own registration, release and transparency signing keys"],"privacy_scope":"These statements describe application storage in this implementation, not a guarantee of anonymity against the running server or network observers.","release_public_key":"754626041c4ef901765208b971fd2ab0df5f94a1ef4ec93f7c3ae874a8c1b3f4","server_version":"0.1.0"}