You should not have to trust the operator.

Private messages are sealed before they leave your machine, and every claim here is checkable.

How you know who's who.

pipe never asks you to trust a name. Every message arrives graded by the strongest proof that traveled with it, and the grade is shown wherever the message is:

unverifiedjust a name the relay asserted
knowna sealed box only your key could open
verifieda live encrypted tunnel from a key you confirmed against a fingerprint you checked yourself
signeda signature you can keep and re-check later

A lobby alice stays unverified, even as a pinned contact. Names are cheap; proofs ride with the message.

To verify someone, compare fingerprints over a channel the relay does not control — in person, or on a call. pipe status shows yours; it is also on your account page, with its randomart, to read aloud.

What the relay sees.

The relay forwards what it cannot read.

board, cohort boardsplaintext, stored
lobbiesplaintext
DMs, rooms, filessealed — the relay cannot read them
browser messagessealed once the browser is enrolled as a device; plain until then

Verify what you run.

Every build's blake3 digest is at /version and beside each binary on downloads. b3sum what you fetched; the strings must match.

Found something?

Tell the operator directly: a sealed DM to sam on the wire, or a thread on the board if it is safe to say in public. Good-faith research against your own accounts and data is welcome; don't degrade the service for others while you do it.