01View Once
View Once turns every message into a self-destructing capsule. The recipient gets exactly one viewing — once they close the content, it is permanently erased from our servers and their device. There is no cache, no thumbnail, and no recovery path. The sender receives a confirmation that the message was viewed and destroyed. Combined with screenshot protection, View Once is the closest digital equivalent to a whispered conversation.
02Recall
Recall gives the sender a permanent undo button. Even after a message has been delivered and read, you can pull it back. The content is removed from the recipient's device and our servers instantly. Unlike email recall (which is just a polite request), City of Hats Recall is server-enforced — the content is cryptographically shredded. Works on text, images, files, and voice messages.
03Sealed File
Sealed File wraps your attachment in a PIN-protected vault. The recipient receives a notification that a sealed file is waiting, but cannot view its contents until they enter the correct PIN. You share the PIN through a separate channel — a phone call, an in-person meeting, or another message. This two-factor approach ensures that intercepting the message alone is not enough to access the content.
04Unlock Content
Unlock Content places a payment gate on any file or image you share. The recipient must pay a fee set by the sender before the content is decrypted and revealed. Payments are processed securely, and the sender receives a notification when the content is purchased. This mode is designed for creators, consultants, and anyone who wants to monetize their digital content directly through a conversation.
05Verified Eyes Only
Verified Eyes Only requires the recipient to pass a real-time biometric face liveness check before the message content is decrypted. This is not a simple face-unlock — the system verifies the recipient is physically present, alive, and matches their registered identity. The check runs entirely on-device: no biometric data is transmitted or stored on our servers. This ensures that only the intended human being can read the message.
06GeoLock
GeoLock ties message access to a specific physical location. The sender defines a GPS coordinate and radius — the recipient can only decrypt and view the content when their device confirms they are within the approved zone. Leave the zone, and the content locks again. GeoLock is enforced at the application level with server verification, preventing GPS spoofing through multiple validation layers.
07Voice Lock
Voice Lock requires the recipient to speak a specific passphrase that matches a voice signature registered during setup. The speech recognition runs entirely on-device using a neural model — no audio leaves the phone. The system checks both what is said and how it is said, creating a voice biometric gate that is extremely difficult to bypass with recordings or synthetic speech.
08Hold to Reveal
Hold to Reveal requires the recipient to maintain continuous physical contact with their screen to view the message content. The moment they lift their finger, the content is instantly hidden behind an overlay. This prevents over-the-shoulder reading, casual screenshots, and screen recording. The content is only visible for as long as the recipient is actively pressing the screen.
09Certified Send
Certified Send opens the message in a tamper-proof Protected Viewer and generates a cryptographic receipt proving exactly who opened the content, on which device, at what time, and from what location. This receipt is signed and immutable — it can be used as evidence in legal or compliance contexts. The sender receives the receipt automatically, creating an auditable chain of custody for sensitive communications.