Skip to content
Merged
4 changes: 2 additions & 2 deletions docs/concepts/architecture.md
Original file line number Diff line number Diff line change
@@ -1,15 +1,15 @@
---
id: architecture
title: Architecture
description: How Pombo works without servers — Streamr transport, Polygon permissions, storage nodes, client-side crypto.
description: How Pombo works without a backend — Streamr transport, Polygon permissions, storage nodes, client-side crypto.
---

import Tabs from '@theme/Tabs';
import TabItem from '@theme/TabItem';

# Architecture

Pombo has no message backend — conversations never pass through a Pombo server. The client sits on top of three decentralized layers — transport, persistence, and ownership — and handles all cryptography itself:
Pombo has no message backend: no server receives, routes or authorizes your conversations. The client sits on top of three open layers — transport, persistence, and ownership — and handles all cryptography itself:

```
┌─────────────────────────────────────────────┐
Expand Down
5 changes: 4 additions & 1 deletion docs/concepts/privacy-model.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,8 @@ description: Ephemeral publisher identities, sealed sender, and what an observer

Pombo's privacy design has one organizing idea: **your real account should not be visible on the wire unless the context deliberately makes it so.**

This page explains how the protections work. For the separate question of what data leaves your device and who receives it, see the [privacy policy](/legal/privacy-policy).

## Ephemeral publisher identities

When you join a channel, Pombo generates **one throwaway keypair per channel** and uses it as your network-level publisher identity across all of that channel's streams. It is created on your first publish, never persisted, and discarded when you leave the channel or disconnect. The address the network sees is not your account.
Expand Down Expand Up @@ -44,7 +46,7 @@ Pombo intentionally has **no per-channel "anonymous mode" toggle**. If you want

## Metadata protections that are on by default

- **ENS lookups are decoyed**: each real lookup is mixed with decoy addresses so RPC operators can't tell which one you cared about.
- **ENS lookups are decoyed** in the direction that runs constantly: resolving the name behind an address you see mixes the real lookup with decoy addresses, in shuffled order, so RPC operators can't tell which one you cared about. Resolving a name *you typed* — starting a DM, sending an invite — is not covered, and the provider sees exactly the name you asked for.
- **Push notifications carry no content** and use k-anonymity tags so the relay can't tell who a notification is really for — and both wake signals and registrations are published under a fresh throwaway key. See [Notifications](../guides/notifications.md).
- **Cross-device sync is sealed to yourself**: state snapshots published to your own inbox are encrypted so only your key can read them, and any payload not authored by your own wallet is rejected.
- **Network node IDs are not derived from your wallet.**
Expand All @@ -60,3 +62,4 @@ Honest limits, in brief — the full list is in the [threat model](../security/t
- Membership of contract-backed channels is public blockchain state: who is allowlisted, who is banned, who paid for a subscription and until when.
- DM inboxes are enumerable, and their traffic pattern is public: given any address, anyone can find its inbox, and a plain HTTP request to the storage node returns its retained envelopes. When messages arrived and how many is readable by anyone. What that does *not* reveal is who they were from — every message carries a different throwaway publisher and sealed content ([threat model](../security/threat-model.md#visible-metadata)).
- Your IP address is visible to network peers, as in any P2P system. For now, use a VPN or Tor if IP privacy matters to you; a proxy-node layer built on Streamr Sponsorships is in development to address this at the protocol level.
- **ENS profile pictures are fetched from wherever their owner points them.** Seeing someone's avatar means your client requests an image from a server *they* chose, which learns your IP address — and someone can point their avatar at a server they run precisely to collect that. Pombo requires HTTPS and routes `ipfs://` avatars through a public gateway, neither of which hides who made the request. **Settings → Content → ENS Avatars** turns the fetch off entirely and falls back to the generated identicon; it is on by default, and off it holds everywhere an avatar is drawn, including the screens shown before you unlock and the pictures attached to notifications.
2 changes: 1 addition & 1 deletion docs/getting-started/identity.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ Your address (`0x…`) is your identity on the network: it's how people DM you,
## There is no "Forgot password"

:::danger[Back up your account]
Pombo has no servers, which also means **no account recovery**. No company can reset your password or restore your key. If you lose your device and have no backup, the account — and everything encrypted with it — is gone permanently.
Nobody holds your key. If you lose your device and have no backup, the account — and everything encrypted with it — is gone permanently.

Export a backup file as soon as you create your account: see [Backup and recovery](../guides/backup-and-recovery.md).
:::
Expand Down
2 changes: 1 addition & 1 deletion docs/guides/backup-and-recovery.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ description: Export a portable, encrypted backup of your account — the only re
# Backup and recovery

:::danger[The one rule]
Pombo has no servers and no custodians, so there is **no "forgot password", no account recovery, no support ticket** that can bring an account back. Your backup file *is* the recovery mechanism. Make one when you create your account, and keep it somewhere safe.
Nobody holds your key and there is no custodian, so there is **no "forgot password", no account recovery, no support ticket** that can bring an account back. Your backup file *is* the recovery mechanism. Make one when you create your account, and keep it somewhere safe.
:::

## Exporting a backup
Expand Down
2 changes: 1 addition & 1 deletion docs/help/faq.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,4 +38,4 @@ Pombo is **pseudonymous with strong wire privacy**, not an anonymity network. Yo

### How is this different from Signal? From Matrix? From Farcaster?

Briefly: **Signal** is the gold standard for content encryption, but it requires a phone number — a real-world identity anchor — and runs on central servers you have to trust to stay up and neutral; Pombo asks for no identifier at all and has no servers. **Matrix** federates servers; Pombo has no servers to federate — transport is P2P and state is on-chain. **Farcaster**-style social protocols are public-first; Pombo is messaging-first with E2EE DMs and encrypted channels. Pombo's particular corner is: no sign-up, no servers, creator-owned channels, sealed-sender DMs.
Briefly: **Signal** is the gold standard for content encryption, but it requires a phone number — a real-world identity anchor — and runs on central servers you have to trust to stay up and neutral; Pombo asks for no identifier at all and has no backend to trust. **Matrix** federates servers; Pombo has no backend to federate — transport is P2P and state is on-chain. **Farcaster**-style social protocols are public-first; Pombo is messaging-first with E2EE DMs and encrypted channels. Pombo's particular corner is: no sign-up, no servers, creator-owned channels, sealed-sender DMs.
2 changes: 1 addition & 1 deletion docs/security/threat-model.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ Privacy tools earn trust by being precise about their limits. This page is the h

## Trusted or centralized components

Pombo has no backend, but it is not free of third parties. Today you are trusting:
Pombo has no backend: no server implements the app, and every piece of infrastructure it touches can be swapped for someone else's. That does not make it free of third parties. Today you are trusting:

| Component | What it could learn or do |
|---|---|
Expand Down
6 changes: 3 additions & 3 deletions docs/welcome.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
id: welcome
title: What is Pombo?
slug: /
description: "Pombo is an open-source, permissionless messaging and social media app: peer-to-peer, with no accounts to approve, no servers in the middle, and channels whose creators keep everything they charge."
description: "Pombo is an open-source, permissionless messaging and social media app: peer-to-peer, with no accounts to approve, no server that can read your messages, and channels whose creators keep everything they charge."
---

# What is Pombo?
Expand All @@ -17,9 +17,9 @@ Your account is a cryptographic keypair generated on your device the first time

Creating a channel is the same: you register it and it is yours. It becomes your property. Accounts are free and instant, so keeping separate identities for separate parts of your life costs nothing.

## No servers in the middle
## Anyone can run the infrastructure

Messages travel peer-to-peer across the [Streamr Network](https://streamr.network). There is no Pombo backend they pass through, so there is nothing to hack, subpoena or switch off.
Messages travel peer-to-peer across the [Streamr Network](https://streamr.network). No server sits between you and the person you are talking to, and the infrastructure that carries and keeps your messages only ever handles ciphertext.

History is kept by storage nodes. Pombo runs a default cluster, but a channel's owner can point it at a different node, and [anyone can run one](operators/run-a-storage-node.md). The same is true of the [relay](operators/run-a-relay.md) that delivers push notifications.

Expand Down
1 change: 1 addition & 0 deletions docusaurus.config.js
Original file line number Diff line number Diff line change
Expand Up @@ -102,6 +102,7 @@ const config = {
items: [
{label: 'Website', href: 'https://pombo.cc'},
{label: 'Open App', href: 'https://app.pombo.cc'},
{label: 'Privacy policy', to: '/legal/privacy-policy'},
],
},
{
Expand Down
Loading