VOIDEXJournal

Own Your Keys: The VOIDEX Recovery Code and Why We Can't Reset It

Not your keys, not your messages. Why VOIDEX creates keys on your device, what the recovery code does, how to store it safely, and what happens if it is lost.

By the VOIDEX team · 6 min read · 2026-09-29
Own Your Keys: The VOIDEX Recovery Code and Why We Can't Reset It

Cryptocurrency gave the world a blunt little phrase: not your keys, not your coins. If someone else holds the keys to your wallet, then in the moment that counts, the money is theirs to freeze, lose or hand over.

The same is true of private messages. If a company holds the keys to your conversations, those conversations are private only for as long as that company, its staff, its servers and every legal demand it receives all agree to keep them that way.

VOIDEX is built so that the keys are yours. They are created on your devices. Servers store only public keys and ciphertext. And the one secret that opens your message history on a new device, the VOIDEX recovery code, is never held by VOIDEX at all. This article explains what that means, why it forces a genuine trade-off, and how to keep your code safe.

Where your keys are born

In many services, "encrypted" quietly means "encrypted with a key we also keep". That model has real benefits: if you forget your password, the provider can restore everything. It also means the provider can read, or be compelled to produce, what it holds.

End-to-end encryption flips this. The private keys that decrypt your messages are generated on your own device and never leave it in readable form. What the server stores are the public halves, which let other people encrypt messages to you, and the encrypted messages themselves.

In VOIDEX Messenger, direct messages use a hybrid post-quantum key agreement, X25519 with ML-KEM-768, followed by a double ratchet so that every message has its own key. Identities are signed with Ed25519 together with ML-DSA-65. None of the private material that makes this work is sent to VOIDEX. The details are in forward secrecy and the Double Ratchet.

The new-phone problem

Keys that live only on a device create an obvious question: what happens when you get a new one?

If your old phone is gone, the keys on it are gone too. Strong forward secrecy makes this even sharper, because the keys for old messages are deliberately destroyed after use. Without a plan, a new device starts with an empty inbox.

Services solve this in different ways. Some keep a copy they can decrypt. Others, including several of the most privacy-focused products, offer backups protected by a secret only the user holds. WhatsApp, for example, introduced end-to-end encrypted backups in 2021 that can be protected by a password or a 64-digit key. Apple's Advanced Data Protection for iCloud asks users to set up a recovery contact or a recovery key, and explains that Apple cannot help recover data if both are lost.

VOIDEX takes the second path.

The VOIDEX recovery code

Every VOIDEX member has a VOIDEX recovery code. It is the key that opens your encrypted message history on a new device.

VOIDEX never holds it. The code is yours, created for you and shown to you, and the platform keeps no copy it could read. That single design choice has two consequences, and both are intentional.

Nobody else can use it. A VOIDEX employee cannot open your history. A person who breaks into VOIDEX's servers finds encrypted data and no code. A demand sent to VOIDEX for your messages meets the same wall: there is nothing readable to hand over.

Nobody can restore it. If the code is lost, no support team, no identity check and no appeal can bring it back. Not because VOIDEX is unhelpful, but because the only copy that ever existed was yours.

This is the honest shape of owning your keys. The power and the responsibility arrive together.

Why the history copy is different

The encrypted history copy has a property worth understanding. Live messages in VOIDEX are forward-secret: each message has its own key, and old keys are thrown away. The history copy is deliberately not forward-secret, because its entire purpose is to let your recovery code open the past on a new device.

That means your recovery code is the master key to your history. Anyone who obtained both the encrypted copy and your code could read it. VOIDEX documents this openly on its security page, and it is optional: members who would rather keep only forward-secret live messages can switch the history copy off.

For most people the history copy is the right choice, provided the code is stored well. For people with unusually high risk, switching it off is a legitimate decision.

How to store your recovery code

A recovery code should be treated like the deed to a house: rarely touched, never casual, and kept somewhere that survives the loss of any single device.

Good places

  1. Paper, written clearly. Write it by hand, check every character against the screen, and keep it somewhere safe and dry. A second copy in a separate secure location protects against fire or loss.
  2. A password manager you trust, ideally one with strong encryption of its own and access you control. If you use one, protect it with a strong master password and two-step verification.
  3. An offline store, such as an encrypted file on a device that is not routinely connected to the internet.

Places to avoid

  • A screenshot in your photo library. Photos are often synced to cloud services, shared, and scanned by apps.
  • A note in an ordinary notes app that syncs to an account you do not closely protect.
  • An email to yourself. Your inbox is one of the most targeted accounts you own.
  • A message in any chat, including VOIDEX. The code protects your history; it should not live inside the thing it protects.

Check it before you need it

A code with one wrong character is not a code. When you write it down, compare it carefully with what is on screen. Some characters look alike in handwriting, and the moment you discover a typo should never be the moment you actually need it.

What happens if it is lost

If you lose your recovery code while you still have a signed-in device, your conversations on that device are still readable there. The most important step is to keep that device safe while you decide what to do.

If you lose the code and every device that held your history, that history cannot be recovered. You can continue using VOIDEX: your account, your connections and new conversations all carry on. What is gone is the ability to open the old encrypted copy, for you and for everyone else.

It can feel harsh the first time you read it. It is also the clearest possible proof that the design works. A system that could hand your history back after you lost the only key could also hand it to someone else.

Why this is the right trade

Every privacy product chooses where to put the risk. Put it with the provider, and you are safe from forgetting but exposed to breaches, insiders and demands. Put it with the user, and you are safe from all of those, but you must look after one important secret.

VOIDEX puts it with you, then gives you the tools to handle it well: keys made on your devices, a recovery code that never leaves your control, an optional history copy you can switch off, and a public, append-only key log that every VOIDEX client checks before it trusts a new device key. More on that in key transparency.

The cryptographic core is open source at github.com/voidexbycnota/voidex-crypto, so the claim that VOIDEX cannot read your history is something you, or anyone you trust, can verify.

Your keys, your messages

Owning your keys is not a technical detail. It decides who ultimately controls your private life: you, or whoever holds the server. VOIDEX chose you, and asks in return that you keep one code somewhere safe.

VOIDEX is invite-only. Request access, read the VOIDEX FAQ, or see exactly how VOIDEX encryption works.

Sources

Enter VOIDEX

VOIDEX is invite-only and free, with no ads and no trackers. Messages are protected by hybrid post-quantum encryption (X25519 with ML-KEM-768) and checked against a public key transparency log. VOIDEX runs in your browser and as apps for Windows and Mac, with iPhone and Android on the way.

Request access   Get the VOIDEX apps