1. The vast majority of our privacy is in product experience. Sharing with less people instead of everyone, making reactions and comments only visible between mutual contacts. 2. Names, Posts, comments and replies are encrypted at rest. 3. We sync your phonebook for contact discovery and don't store it on our servers. Therefore it is not linked to your identity. This is a hard problem to solve as Signal wrote in this blog post (https://signal.org/blog/contact-discovery/)
That said, privacy is a super important issue and external testing and open-sourcing is something that we desire to do. So thanks for the checker here!
We are many that had trust broken one too many times.
IMO encryption/privacy means nothing if I can’t ensure it’s what it says myself. Ability to self-build is the only way to make that happen.