How End-to-End Encryption Works in PeerDesk's AI Chat
Why Encryption Matters for AI Chat
When you chat with a business AI, you share real information — your name, what you're looking for, sometimes your address, health details, or financial situation. On most platforms, those conversations are stored on a central server. If the server is breached, your data is exposed.
PeerDesk takes a fundamentally different approach. Instead of routing conversations through a central cloud, we use peer-to-peer (P2P) encrypted communication powered by WebRTC. Your messages travel directly between you and the AI agent — our servers never see the content.
The Architecture: How It Works
1. Connection Establishment (Signaling)
When you open a PeerDesk agent link (like peerdesk.app/yourshop), here's what happens:
- Your browser contacts our signaling server — this is the only server PeerDesk operates
- The signaling server helps your browser and the AI agent's host discover each other
- Once discovered, your browser and the agent establish a direct WebRTC connection
- The signaling server steps back — it never sees your messages
2. Data Channel Encryption
Once the WebRTC connection is established:
- All messages travel over a DTLS-encrypted data channel
- DTLS (Datagram Transport Layer Security) provides the same grade of encryption used by online banking
- Each session generates unique encryption keys — even if one session were somehow compromised, previous and future conversations remain secure
- Messages are not stored on any PeerDesk server — they exist only in the browser sessions of the participants
3. Voice Call Encryption
PeerDesk agents support real-time voice calls (try asking an agent to call you). These voice streams are also encrypted:
- Voice data uses SRTP (Secure Real-time Transport Protocol)
- Media streams are encrypted end-to-end between your browser and the agent's host
- No recording happens on PeerDesk's side — the business owner controls whether voice data is retained
Zero-Knowledge Identity: The NullLink ID Vault
PeerDesk includes an identity system called the NullLink ID Vault. Here's what makes it different:
- Your credentials (name, email, preferences) are encrypted client-side before being stored
- PeerDesk cannot read your identity data — it's encrypted with a key only your browser holds
- When you connect to an agent, you choose what to share
- Even if our database were breached, attackers would get encrypted blobs — not readable data
What PeerDesk Servers Can See (and Can't)
Let's be transparent about the trust model:
| Data | Can PeerDesk See It? | Notes |
|---|---|---|
| **Your IP address** | Yes (during signaling) | Required to establish P2P connection |
| **Which agent you visited** | Yes | Needed for connection routing |
| **Message content** | ❌ No | P2P encrypted — never touches our servers |
| **Voice call audio** | ❌ No | SRTP encrypted end-to-end |
| **Your name/email** | ❌ No (in vault) | Zero-knowledge encrypted |
| **Files shared in chat** | ❌ No | Transferred P2P via data channel |
| **Conversation history** | ❌ No | Stored locally in browser, not on server |
How This Compares to Other Platforms
Most AI chat platforms (Intercom, Drift, Tidio, ChatBot.com) use a centralized architecture:
Customer → Platform's Cloud Server → AI Processing → Response → Customer
Every message passes through (and is stored on) the platform's servers. The platform can read, analyze, and monetize your conversation data.
PeerDesk's architecture:
Customer ←→ Direct P2P Connection ←→ AI Agent Host
↑
(Signaling server only helps establish the connection)
Messages never touch a central server. The AI processing happens on the entity owner's side (or via their chosen AI provider like OpenAI/Claude), but the conversation channel itself is encrypted end-to-end.
GDPR Compliance by Architecture
PeerDesk is built in Switzerland and designed with European privacy regulation in mind:
- Data minimization: We don't collect data we don't need
- Purpose limitation: Signaling data is used only for connection establishment
- Right to erasure: There's nothing to erase on our servers — conversations are P2P
- Data portability: Your identity vault data can be exported
- Privacy by design: End-to-end encryption isn't a feature — it's the architecture
Self-Hosted AI: Full Data Sovereignty
For maximum control, PeerDesk supports Ollama — an open-source AI runtime that runs on your own hardware. This means:
- Your AI model runs on your server
- Customer queries never leave your infrastructure
- Zero dependency on OpenAI, Google, or any third-party AI provider
- Complete data sovereignty for regulated industries
The Bottom Line
PeerDesk's privacy isn't a checkbox on a features page. It's the foundation of the architecture. Every message, every voice call, every file shared between a customer and an AI agent is protected by the same P2P encryption that makes the platform work.
You don't have to trust PeerDesk with your data — because PeerDesk never has your data.
Want a private AI assistant for your business? Get started with PeerDesk for free →
Ready to create your own AI assistant?
Join PeerDesk and build AI-powered business agents in minutes.
Get Started Free →