Privacy & Security

Is PuchiDen encrypted?


Puchiden Security Brass Padlock
Puchiden Security Brass Padlock

Yes — but not end-to-end, because no service that connects a browser to a regular phone number can be.

What is encrypted:

  • Call audio between your browser and our infrastructure — WebRTC's DTLS-SRTP (AES-128). The signaling that sets up the call rides on TLS-protected WebSockets.
  • The website and dialer — HTTPS everywhere. We tell browsers, at our edge, to refuse plain-HTTP fallbacks for this domain.
  • Login codes we email you — SMTP STARTTLS in transit to your mail server.
  • Your session cookie — HttpOnly, Secure, SameSite=Lax. It expires after a certain amount of inactivity.

What we never store in the first place:

  • Passwords. PuchiDen uses one-time codes emailed to you for sign-in — there is no password on file to leak, phish, or reset.
  • Card details. Stripe handles your card directly; we only ever see the amount and date of a top-up.

What is not encrypted:

  • The PSTN leg of the call. Once your call leaves our telecommunications infrastructure provider and enters the public phone network to ring the destination phone, it travels over the regular carrier network. That part of the journey does not support media encryption — this is a property of the global phone system, not a choice we made.

If end-to-end encrypted voice is what you need, you want an app-to-app messenger like Signal, where both sides are running the same encrypting client. PuchiDen exists to call ordinary phone numbers privately — that's a different problem, and we solve it as well as it can be solved.

Last updated: May 12, 2026