Private messenger · iOS and Android

A conversation belongs to the people who are having it.

Baal encrypts messages end-to-end with MLS. No phone number is required, and every new device needs your explicit approval.

Planned launchEarly access from December 4, 2026 · iOS · Android
MLS · RFC 9420no phone numberiOS and Android

Privacy model

Plaintext never leaves your devices.

Protection does not depend on a promise that we will not look at your conversation. The system is designed so the delivery service never receives the material required to read it.

01

On your device

Encrypted on-device vault

History and keys remain in an encrypted on-device vault. A read message is logically deleted 12 hours after it is first opened, and reopening it does not extend that time.

02

Between devices

MLS and key verification

MLS updates keys when group membership changes. Safety numbers and a public key-transparency log help detect key substitution, and an inconsistency blocks the contact.

03

On the service

Delivery, not an archive

A ciphertext remains only in RAM until delivery is acknowledged, for no more than 24 hours. An ACK or server restart removes it earlier; messages never enter PostgreSQL or a backup.

Documented operator data boundary

Baal means no phone number, no key escrow and no persistent message archive.

Account and keys
  • the account receives a random AccountId; a phone number is neither required nor collected
  • private account, device and MLS keys remain on users’ devices
  • no key escrow, recovery key or operator master key
  • the operator never receives the material required to decrypt a message
The server delivers, not archives
  • Baal’s data schema contains no persistent message table or IP address field
  • an undelivered ciphertext exists only in RAM for up to 24 hours; an ACK or restart removes it earlier
  • an IP address is processed in RAM for no more than 60 seconds for abuse protection and is not stored by Baal or the website
  • the operator sees random identifiers and delivery metadata needed to route the ciphertext

This boundary is documented: we state what the operator receives, never receives and how long each class of data exists. E2EE protects content, but not all metadata or a message displayed on an unlocked or compromised device. The infrastructure provider may keep its own logs under its policy; details are in the Baal Privacy Policy.

Post-launch plan

After launch: all of Baal for €22.99 a year.

Following the planned public launch, we expect to offer one subscription plan. The fee will support the continued development and operation of a private messenger — without advertising, data sales or paid tiers of security. Current development contributions are voluntary donations and do not purchase or activate a subscription.

3-day trialiOS and Androidevery approved device
3-day trialannual plan
€22.99incl. VAT / year

Full access to Baal on every approved device connected to one account.

Read the subscription terms

After the 3-day trial, you will be charged €22.99 for one year unless you cancel first. You can manage your subscription in the store where you purchased it. Cancellation does not end access before the current period expires.

Support BAAL

Help us bring privacy to launch.

Your support will help fund final iOS and Android testing, Store integrations, infrastructure and preparation for an independent security audit.

Shared goal

Development and independent audits

PLN 2,430 of PLN 150,000
1.62% fundedAll support channels combined · updated manually
Available now

Donation via Stripe

Make a voluntary, one-time donation with no benefit in return. Pay by card, Apple Pay or another method available through Stripe and choose the amount yourself.

Donate via Stripe
Available now

Bank transfer

Account holderSKY LEGAL TECHNOLOGY Sp. z o.o.

Transfer titleBAAL development and audits

Coming soon

Kickstarter

We are preparing a campaign that will explain the development stages and funding goals.

Campaign link will appear here

Contributions made through Stripe, BTC and bank transfer, as well as Kickstarter pledges without a reward, are voluntary donations with no benefit in return. They are outside the scope of VAT; they do not activate or purchase a Baal subscription and do not entitle the donor to a product or other reward. Kickstarter pledges linked to a reward are accounted for separately under the rules applicable to that reward.

Building toward launch

The privacy foundation is already working.

MLS encryption, the encrypted local vault, explicit device approval, safety numbers and public key transparency are already working. Ahead of the planned December 4, 2027 launch, we are implementing Store payments and hardware-backed key protection, completing physical-device testing and preparing for an independent audit. Your support helps bring this privacy model to the App Store and Google Play. Links and QR codes will appear after publication. Sky Legal Technology (SLT) closely follows developments in quantum key distribution (QKD) and evaluates its future practical applications in secure communications; QKD is not currently part of Baal’s architecture.

iOS

App Store

Placeholder QR code for the App StorePlaceholder QR code
Android

Google Play

Placeholder QR code for Google PlayPlaceholder QR code

Straight answers

Privacy and subscription.

Can Baal access the contents of my messages?

No. A message is encrypted on the sender’s device and decrypted only on the recipient’s device. The server delivers an encrypted frame but never receives the keys required to read the conversation.

Do I need to provide a phone number or my address book?

No. Your technical identity is a random 256-bit AccountId. Your chosen pseudonym is a separate signed public profile; no phone number or address book is required.

What can the server still see despite encryption?

The random AccountId, current public pseudonym, device identifiers, sender and recipient delivery addresses, random group identifier, frame type and size, and current delivery state. These data do not contain content, but they can reveal part of the communications graph.

Can I use one subscription on several devices?

Yes. A subscription belongs to your Baal account, not to a single phone. It covers every device that you explicitly approve and connect to that account.

Can I cancel during the trial?

Yes. After cancellation, you retain access until the end of the three-day trial and the annual fee will not be charged.

What happens to my messages when the subscription expires?

Subscription expiry does not change local retention. An unread message remains in the encrypted vault until first opened and is then logically deleted after 12 hours. Features that require active service access may be limited until you renew.

Closed alpha testing

Help test BAAL before its public launch.

Early access begins on December 4, 2026. We are looking for people willing to test the app on real devices and provide specific feedback. Recruitment is limited to 100 accepted applications, and submitting the form does not guarantee participation.

  • Up to 100 accepted applications
  • Testing the iOS or Android application
  • Reporting bugs and usability issues

The application form opens in a secure window.

Security

Report a vulnerability responsibly.

If you discover a vulnerability in the Baal app, website or service infrastructure, share the details with us through this form.

  • Do not access or copy another person’s data.
  • Do not disrupt service availability or use social engineering.
  • Do not include passwords, private keys or other people’s message content in your report.

You can also email us directly: biuro@skylegaltech.com

No attachments. If needed, we will arrange a secure channel for additional material.