End-to-end encryption
Each session uses an ephemeral AES-256-GCM key negotiated via ECDH (Curve25519). Both parties authenticate each other before any data is transferred. The key is discarded after the session — even we cannot decrypt content afterwards.