Last updated: 14 July 2026
Espero's job is to translate your messages so people who speak different languages understand each other. That shapes our security model — and we'd rather explain it plainly than imply protections we don't provide.
End-to-end encryption means the server can never read your messages. Live translation means the server (and the AI translation service) must read each message to turn it into every reader's language. Those two goals are fundamentally opposed — you cannot translate text you cannot read. Espero is built around translation, so it does not offer end-to-end encryption, and we won't claim a protection we don't actually provide.
The current cloud-translation service sends cloud-message text to Espero's configured third-party AI processor. The exact provider, service tier, contracts and transfer records still require documented verification. Voice, video, image or interpreter input is sent only when that feature is selected. Translated call captions are not generally available: they have a separate disabled-by-default test and require both participants' current choice. Eligible cloud messages may receive semantic-search embeddings while that server feature is enabled; the current code defaults it on unless the production environment disables it. Relevant eligible conversation content is processed when an authorised participant requests summaries, AI answers, assistant replies, pronunciation or transliteration. Search queries and Ask Espero questions are processed when a requester submits them.
Espero does not use message content to train its own models, sell it or target advertising. The provider's handling depends on the service tier, contract and data-processing terms attached to the exact production configuration; limited safety, abuse-prevention or legally required retention may apply. Espero does not make a blanket provider-training, retention or region promise without that evidence, and the AI processor's applicable API terms govern its handling.
Ordinary one-to-one audio and video calls are available to all users on supported builds. Call signaling is handled by Espero. Media normally travels directly between the peers and may use a TURN relay service when a direct route fails. The other peer, STUN or TURN services can receive public IP addresses and ordinary network/protocol metadata. Espero does not store ordinary call audio or video as message content.
| Capability | Espero |
|---|---|
| App/API transport | HTTPS/TLS |
| Call-media transport | WebRTC encryption |
| Provider-managed storage encryption | Provider states encryption at rest |
| Server can read cloud messages (to provide declared features) | Yes — by design |
| Sold or used for advertising by Espero | No |
| Used by Espero to train AI models | No |
One-to-one calls use WebRTC. Call audio and video travel encrypted directly between the two devices — or through an encrypted relay (a TURN service) when a direct connection can't be established. Our servers never receive or store your call audio or video, and calls are not recorded. The server handles only call signaling and metadata — who is calling whom, call type, timing and state — needed to connect the call, keep your call history and prevent abuse. Setting up a call necessarily reveals limited network information, such as IP addresses and connection timing, to the other participant and to the relay when one is used.
So calls do not have the “server can read it” property that ordinary cloud messages do. We still don't call them formally end-to-end encrypted, because call setup passes through our signaling servers — but the audio and video themselves are not available to us. Translated call captions are not part of calls today; if they are ever offered, they will be a clearly separate, opt-in feature.
Primary account and message records live in our EU cloud infrastructure in the European Union (Ireland), behind transport encryption and access controls. Separate providers may handle media storage, call relay (TURN), email sign-in-code delivery, push-notification delivery and hosting of the public website. Payments are handled through your app store or our card processor — Espero receives entitlement and transaction status, not card details. Media, logs and processor copies do not all necessarily share the primary database region.
Secret Chat is not currently available. Do not rely on Espero for end-to-end encryption until a separately audited feature is actually released and this page is updated.
Found a security issue? Please email security@espero.live before disclosing publicly. We will assess the report and respond as appropriate.
Security claims about messaging deserve scrutiny. Espero uses encrypted transport and provider-managed encryption at rest, but ordinary cloud chats are not end-to-end encrypted because declared translation features require server-side processing. This page is intended to describe protections that can be supported by the actual product and provider documentation.