Why I Chose Not to Build a Mobile App

On first discovering SecurityNet, one of the first questions to ask is surprisingly predictable.

"Where's the mobile app?"

It's a fair question.

After all, almost every messaging application today lives on a smartphone. Mobile devices have become our cameras, diaries, wallets, navigation systems and primary means of communication. Building another phone app would have been the obvious choice.

I chose not to.

Not because I couldn't build one.

Because I believed it would take SecurityNet in the wrong direction.


When I first started developing SecurityNet, my objective wasn't to compete with WhatsApp, Signal or any other messaging platform.

I wasn't trying to build a better social network.

I was trying to solve a very specific problem.

How could two authorised people exchange sensitive files and messages directly between their own computers without leaving unnecessary copies behind?

That question led me down a very different path.


Desktop computers encourage a different way of working.

People sit down to write reports, contracts, legal documents, financial models and technical designs. They have larger screens, full keyboards and local storage under their own control.

Those are exactly the situations SecurityNet was designed for.

I wasn't interested in encouraging constant conversation.

I was interested in helping people communicate deliberately.

For me, those are two very different things.


As SecurityNet evolved, another philosophy began to emerge.

Every design decision asked the same question.

Does this reveal more information than it needs to?

That question influenced everything.

Why there are no phone numbers.

Why there is no cloud archive.

Why files move directly between authorised computers instead of being stored on a central server.

Why the software concentrates on desktop communication rather than becoming another mobile application competing for attention.

None of those decisions happened by accident.

They all came from asking the same question.


Of course, smartphones are remarkable devices.

I use one every day.

But I am also very conscious of the amount of information a modern smartphone can generate.

A phone is almost permanently connected. It moves with us throughout the day. It communicates with mobile networks, Wi-Fi networks, operating-system services and the applications we install on it.

Depending on the device, its configuration and the services being used, those interactions can reveal or generate information about location, network activity, application usage and patterns of communication.

  • This information is called metadata.
  • It is the details of Who, What, Where, Why and How of modern communications.
  • And its breadcrumbs trail leads right back to your device.

Some of that information is necessary simply for a mobile phone to function. Some may be collected by applications and service providers.

Some may ultimately contribute to the extensive commercial data ecosystem surrounding online advertising and data brokerage.

That is why I regard the smartphone itself as an inherently difficult environment in which to achieve privacy.


This isn't necessarily a criticism of the individual applications running on it.

Signal, WhatsApp, Keet and other privacy-focused applications can encrypt the information they are responsible for. But no application controls the entire device, the operating system, the mobile network or every other service with which that device communicates.

Encryption doesn't make all of that metadata disappear.

It can protect the contents of a message or file, but information about the device, network connection and surrounding communication may still exist.

That matters to me because SecurityNet developed around a rather different principle:

Does this reveal more information than it needs to?

Adding a mobile application would therefore not simply have meant creating SecurityNet for a smaller screen.

It would have meant placing SecurityNet on the very type of device whose continuous connectivity and extensive exchange of information I was increasingly trying to avoid.

So I made a deliberate choice: SecurityNet would remain on computers.


People sometimes assume that by not supporting phones I am somehow behind the times.

I see it differently.

I started SecurityNet because I wanted to make communication secure.

Somewhere along the journey, that goal became more specific.

I became interested not only in protecting the information being communicated, but in reducing how much information was exposed by the act of communicating at all.

That changed the way I thought about SecurityNet.

  • No phone numbers.
  • No cloud archive of ordinary files and one-to-one chats.
  • No unnecessary central activity history.
  • Direct communication between authorised computers wherever possible.
  • And no mobile app.

Those aren't unrelated features.

They are different consequences of the same question:

Does this reveal more information than it needs to?

Looking back, I think that question explains almost every important design decision I made.


Next: Why every feature has a privacy cost—and why sometimes the best design decision is not to add it.