Privacy for All Apps! Encrypt and Disguise Messages in All Your Apps!
About this app
Oversec transparently encrypts and decrypts any text in any app
You can use it to exchange private encrypted and covert chat- or email messages or store your own encrypted notes on your phone.
See our demo videos: * Introduction * Encrypting Emails * Encrypting Images
Oversec is completely agnostic of the subjacent app, it works with Whatsapp™, Line™, Snapchat™, Instagram™ or any other chat app. It also supports sending and receiving PGP encrypted messages with the Gmail™ or any other Email app.
End-to-End Encryption was yesterday. Oversec introduces "Eye-to-Eye" encryption. Encrypted data is only decrypted while it is shown on the screen! No clear text is ever persisted and thus cannot be extracted from the file system or accidentally be backed up into the cloud.
We also carefully designed Oversec so that it doesn't require internet access. Because of that, you can rest assured that no decrypted information can ever leave your device.
How it works:
Oversec constantly monitors the text on your screen. When it finds an encrypted text, it tries to decrypt it and then shows the decrypted text as an overlay in place of the encrypted text. Conversely, it can read text out of an input field, encrypt it, and then put the encrypted text back into the input field.
In order to encrypt a text, Oversec shows a button next to an active input field. After having entered the secret text, tapping that button makes Oversec read the text, encrypt it and put back the encrypted text into the field. It is now ready to be sent in the subjacent app as usual - the app doesn't even know that it is sending encrypted data!
Oversec also features a unique way of encoding the encrypted messages. It stores the encrypted text in invisible (zero-width) characters and let's you add decoy text at the end. That way, a message will just show e.g. "The sun is shining!" with no visible sign of any encryption, whereas in reality it contains a hidden encrypted message.
You may also encrypt and send photos through Oversec - its unique camera mode even allows you to take and send an encrypted photo without ever storing the original photo on the device.
Oversec encrypts your data either using symmetric keys (using ChaCha20 cipher + Poly1305 MAC ) or using asymmetric PGP encryption (making use of the OpenKeychain app).
The code is open source and can be found here.
This app uses Accessibility services.
Licensed under GPL-3.0-or-later, by oversec.
What's New in v1.5.15
Imported from the F-Droid repository index.
Version history
Mar 28, 2019 · 5.3 MB · Android API 21–28 · code 1005015
Imported from the F-Droid repository index.
SHA-256 487da47eb3ccd7a93aeb397e6e435af0be8f6b79cff7a3a60eaf2051762c20f2
Mar 3, 2019 · 5.3 MB · Android API 21–28 · code 1005014
Imported from the F-Droid repository index.
SHA-256 d7c4c461a71751894aa6287941277001540568bc58e4a7bf26e9ff7d9928fe26
Feb 18, 2019 · 5.3 MB · Android API 21–28 · code 1005013
Imported from the F-Droid repository index.
SHA-256 8ad3ce4dd27a05e07ef13f13e81acf25404803535296c88919d052d9a0a2a610
Will it run on your device?
73%
- Runs on a broad range of modern Android versions.
- ABI coverage is focused on newer 64-bit devices.
Installation Guide
Open Settings on your Android device
Go to Security → Unknown sources (or Install unknown apps)
Enable "Allow from this source" for your browser or file manager
Open the downloaded APK file from your Downloads folder
Tap "Install" and wait for installation to complete
Launch the app from your home screen
Make sure to re-enable Unknown Sources restrictions after installation for security.
How to install this safely
How to verify the file you downloaded
Before you install anything, confirm the file is the one described here. On a computer, run shasum -a 256 your-download.apk (macOS or Linux) or certutil -hashfile your-download.apk SHA256 (Windows), then compare the output character-for-character with the SHA-256 on this page. If a single character differs, the file is not the build we recorded — delete it.
What the signing certificate proves
Every Android app is signed with a private key that only its developer holds. The fingerprint on this page is a hash of the matching public certificate, and it proves continuity rather than identity: it tells you a build came from whoever signed the earlier ones. Android enforces this at install time — if a package claiming to be io.oversec.one is signed with a different key, the system will refuse to install it over your existing copy. A fingerprint that changes between releases is worth pausing on, because a repackaged app that has been modified by someone else cannot keep the original signature.
How to roll back to an earlier version
If the current release misbehaves, 1.5.14 is the last build before it. Android will not install an older version code over a newer one, so you must uninstall Oversec first — which clears its local data unless you have a backup. Reinstall the older APK only if its signing fingerprint matches the build you already trust, and check the API range: an older release may target an Android version your device has moved past.
Why we list sources instead of hosting everything
The official store channel is almost always the right choice: it updates automatically and carries the publisher's own distribution guarantees. A direct APK is useful when a device has no store access, when a rollout has not reached your region, or when you need a specific version — and only when the publisher has authorized that copy. APKBrowse does not list pirated, cracked, or unauthorized rebuilds of Oversec, and a listing is removed when the evidence for it stops holding up.
Get Oversec
Every source we list for io.oversec.one is legality-reviewed. Pirated or cracked builds are never offered.
Other sources
F-Droid listing
officialF-Droid builds this app from source and signs it. This is its official listing, with older builds and full release notes.
Source code
verified publisherThe upstream repository this build is compiled from.
We check legality and signature continuity, but device behaviour still varies. Install at your own discretion.
App Information
Security Verification
We record provenance; we do not run malware scans. Verify the hash yourself before installing.
SHA-256 Hash
487da47eb3ccd7a93aeb397e6e435af0be8f6b79cff7a3a60eaf2051762c20f2
Signing certificate
0e2b5403e89e9334211f8840f2646997b8ae8d67969de19b0edf959af9e5d6c8
Permissions Required
Previous Versions
The signing certificate fingerprint for this release is on record, so a build that does not match it did not come from this publisher.
Report a problem with this listing
A listing is only as good as its corrections. If a source is broken, a signature looks wrong, or this app should not be here, tell the moderation team.