Evidence and risk△Partial evidence/△CautionSome material claims still need confirmation.; those sources show trade-offs worth reading.
Last reviewedReviewed 5 Sep 2026KYC checked 5 Sep 2026 · inferred jurisdiction · Source → official siteHow to cite this pageSource coveragePartial evidenceRecorded riskCaution
Evidence and facts
Evidence and facts
CUNICULA SCORE 4.0
36/100△Limited evidencePrivacy 12/25 · Control 0/20 · Transparency 0/20 · Security 17/25 · Accountability 7/10 · Cap 69 · Method
JURISDICTIONCH
CAUTIONInitial setup connects to an STF seed node that can see but says it does not record the IP address. Fast push notifications expose a device IP and token to Apple or Google and an account ID and token to an STF push server. The last official independent app audit located is from 2021. Development resumed in July 2026 with three developers, but resources remain highly constrained and funding still relies on donations and nonprofit grants.
AUDITED BYQuarkslab
OPERATOR DATAHosted operator recorded
SOURCE COVERAGE
△Partial evidenceINDEPENDENT AUDIT1/6Reviewed 5 Sep 2026 · Source → official site
LAST CHECKED2026-06-24
LAST UPDATED2026-09-05
Specs
DOCUMENT CHECKNone recorded
IDENTITY EXPOSURELevel 0/4
KYC TRIGGERSNo phone number, no email. Session ID only. Decentralized message storage.
FEEFree
CATEGORIESComms, Privacy Tools
COMMON USESAnonymous messaging, No-account comms, Decentralized privacy
FEATURESNo phone number, No email required, End-to-end encrypted, Community-operated node network, Metadata-minimizing design, Open source, iOS, Android and Desktop, Onion routing
TORNot listed
REGIONSGlobal availability
Review analysis, source material, related services, and history
About
Decentralized encrypted messenger needing no phone number or email, stewarded by a Swiss foundation.
Analysis
OVERVIEW
Session is a decentralized messenger needing no phone number or email, only a generated Session ID, and its Quarkslab security audit is recorded as published with major findings resolved.
LIMITS
The 2026 funding review notes development resumed only in limited capacity after a donation campaign and long-term runway remains a watch item, and the project relocated from Australia to a Swiss foundation in 2024 after Australian police sought user data from an employee.
USEFUL FOR
People wanting phone-free, email-free messaging who are tracking the project's funding runway as an ongoing risk factor.
No identity verification is recorded for typical use. No phone number, no email. Session ID only. Decentralized message storage.
Which payment methods are accepted?
Please check the provider site for accepted payment methods.
Where is it available?
Recorded availability: GLOBAL.
Is the operator based in a Five Eyes country?
No. The recorded jurisdiction is CH, which is not a Five Eyes country. This is jurisdiction context and does not by itself establish that a service is safer or less safe.
How are identity, operator, and evidence fields reported?
Identity exposure is level 0 of 4. A hosted operator is recorded. Jurisdiction is shown as context, not a safety verdict. Source coverage is partial evidence, last reviewed 2026-09-05, and recorded risk is caution.
No changes to the documents we watch since we started checking on 9 Aug 2026. Last checked 9 Aug 2026.
Evidence basis: Claims on this page are linked to published sources for comparison, not certification, audit, endorsement, or recommendation; read the methodology and coverage map before relying on an entry.
Service history
Latest meaningful changes to the facts shown on this provider page.
Review overdue providers against current sources
Features, KYC last checked, Last reviewed, Privacy warning, and 2 more
Apply full-service rereview and score 4.0
Privacy warning, Score assessment
Corporate registry information updated
Corporate / Entity type
Full service history
updated
Review overdue providers against current sources
Features
No phone number, No email required, E2E encrypted, Decentralized network, No metadata collection, Open source, iOS + Android + Desktop, Onion routing → No phone number, No email required, End-to-end encrypted, Community-operated node network, Metadata-minimizing design, Open source, iOS, Android and Desktop, Onion routing
KYC last checked
2026-03-13 → 2026-09-05
Last reviewed
2026-07-05 → 2026-09-05
Privacy warning
The app requires an initial connection to an STF-organised seed node, which can see but says it does not record the connecting IP; Apple/Google may collect OS telemetry. The only cited independent code audit is from 2021, while 2026 development resumed with a reduced three-developer team funded mainly by donations. → Initial setup connects to an STF seed node that can see but says it does not record the IP address. Fast push notifications expose a device IP and token to Apple or Google and an account ID and token to an STF push server. The last official independent app audit located is from 2021. Development resumed in July 2026 with three developers, but resources remain highly constrained and funding still relies on donations and nonprofit grants.
Source reviewed
older source, not independently verified → https://getsession.org/app-privacy-policy
not set → Outcome: HOLD; Checked at: 2026-08-25; Inputs: Operator data exposure: unknown; Control model: unknown; Source model: unknown; Audit: Score eligible: no; Reason: No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit.
Originally Australian (Five Eyes). Relocated to Swiss non-profit (Session Technology Foundation) November 2024 after Australian police visited an employee seeking user data. Switzerland has its own surveillance laws but the relocation significantly reduces compulsion risk. Quarkslab security audit published - all major findings resolved. → The app requires an initial connection to an STF-organised seed node, which can see but says it does not record the connecting IP; Apple/Google may collect OS telemetry. The only cited independent code audit is from 2021, while 2026 development resumed with a reduced three-developer team funded mainly by donations.
Score assessment
not set → Operator data exposure: moderate; Control model: hosted-account; Source model: open
Decentralized encrypted messenger requiring no phone number or email. Swiss foundation stewardship, no registration, no metadata collection claim. 2026 funding review: development resumed in limited capacity after a donation campaign, but long-term runway remains a watch item. → Decentralized encrypted messenger needing no phone number or email, stewarded by a Swiss foundation.
Originally Australian (Five Eyes). Relocated to Swiss non-profit (Session Technology Foundation) November 2024 after Australian police visited an employee seeking user data. Switzerland has its own surveillance laws but the relocation significantly reduces compulsion risk. Quarkslab security audit published — all major findings resolved. → Originally Australian (Five Eyes). Relocated to Swiss non-profit (Session Technology Foundation) November 2024 after Australian police visited an employee seeking user data. Switzerland has its own surveillance laws but the relocation significantly reduces compulsion risk. Quarkslab security audit published - all major findings resolved.
Decentralized encrypted messenger requiring no phone number or email. Messages stored on the Oxen Service Node Network. End-to-end encrypted, no metadata collection. → Decentralized encrypted messenger requiring no phone number or email. Swiss foundation stewardship, no registration, no metadata collection claim. 2026 funding review: development resumed in limited capacity after a donation campaign, but long-term runway remains a watch item.