Standard text messages are not private. SMS travels through your carrier in the clear, and most chat apps store some form of your conversation on a server. If you want a message that only your recipient can read — on any phone, through any app — you need to encrypt the text yourself before you send it. Here is how to do that on both iPhone and Android.
Step 1: Install CipherPigeon on both phones
CipherPigeon is available on the App Store for iPhone and on Google Play for Android. Both versions run the same cipher, so an iPhone can send to an Android and back with no compatibility step. The app works fully offline and does not create an account.
Step 2: Agree on a passphrase out of band
Encryption is only as private as the key. Choose a passphrase and share it in person, over a phone call, or through a channel separate from the one you will use to send messages. Never send the key through the same app you will send the ciphertext through. A short sentence you both remember works better than a random string you have to write down.
Step 3: Encrypt the message
Open CipherPigeon, type your plaintext, enter the passphrase, and tap encrypt. The app produces a VS//PACKET — a block of plain text that looks like noise. Everything happens on the device; nothing is uploaded.
Step 4: Send it through any app
- iPhone: copy the packet and paste it into Messages, Mail, WhatsApp, Signal, or Notes.
- Android: copy the packet and paste it into Google Messages, Gmail, Telegram, or any chat app.
The carrier or app only ever sees ciphertext. Because the packet is ordinary text, it survives copy and paste, screenshots of the text, and even being read aloud or printed.
Step 5: Decrypt on the other side
Your recipient copies the packet, pastes it into CipherPigeon, enters the same passphrase, and taps decrypt. The plaintext appears on their screen only. If the passphrase is wrong, the output is meaningless — there is no hint, no partial reveal, and no attempt counter to leak information.
Practical tips
- Rotate the passphrase periodically, especially for ongoing conversations.
- Keep messages reasonably short so packets paste cleanly into SMS.
- Delete the plaintext from your notes app after encrypting it.
- For maximum protection, send the packet through an end-to-end encrypted messenger, so the message is protected twice.
That is the whole workflow. No servers, no accounts, and no need to trust the app carrying your message — just a shared key and math that runs in your pocket.

