Skip to content
Textual
Menu

Private messages, encryption, and local logs

Understand what TLS and OTR protect, and where other copies of a conversation may remain.

On this page

A private-message window is not a promise that only its two participants can access every part of the exchange. The network, the connection method, local logging and the other person's client all matter.

TLS and OTR do different jobs

TLS encrypts a connection between Textual and the server it connects to. Off-the-Record Messaging, or OTR, adds end-to-end encryption to supported one-to-one conversations when both clients establish an OTR session.

In Textual's documented OTR interface, the status control above a private conversation lets you start a session and authenticate your partner. An encrypted but unauthenticated conversation does not confirm that you are talking to the right person. Use the authentication process and verify identity through an appropriate independent channel.

What is and is not covered

The original implementation documentation covers ordinary private messages, actions and notices. It explicitly excludes CTCP requests and DCC file transfers. OTR also does not hide all connection metadata or turn an ordinary IRC channel into an encrypted group conversation.

Do not infer OTR protection from a TLS connection or the presence of a private-message tab alone. Check the conversation's actual state, and consult the original OTR reference for its status descriptions and version-specific controls.

Logging and stored keys

If chat logging is enabled, a readable local copy of a conversation may still be written to disk. Review Preferences → Advanced → Log Location, your backup arrangements, and the other participant's logging practices before discussing sensitive information.

OTR also maintains identity keys, fingerprints and related state. The legacy guide lists historical storage locations for different distributions; the 7.2.4 sandbox transition means those paths must not be treated as universal. Use preference backups and take care before deleting app data or encryption identities.

Inline media and external requests

Displaying an image or other embedded resource can contact the service hosting that resource. That service can receive connection information from the fetching client even though the link appeared inside a private conversation. Textual's historical media-scanner explanation is retained for website operators investigating its user agent.

Legacy encryption commands

The old command reference also includes Blowfish commands such as /keyx and /setkey. They are separate from OTR and should not be treated as interchangeable security guarantees. Their original syntax and limitations remain in the legacy command reference.

Keep reading

Source material

Adapted from the Textual knowledgebase, with related historical details preserved in the legacy library.

Need a hand? Contact us about this guide.

Textual screenshot