AI summary
OpenPGP app for encrypting, decrypting, signing, and verifying files with hardware key support. Version 4.0.3 adds post-quantum encryption, an API to serve as a crypto backend for other apps, and fixes password fields to prevent keyboard memorization.
Generated by AI. May contain inaccuracies.
About this app
OpenPGP for Android. Encrypt, decrypt, sign, and verify messages and files, manage your keyring, and use a hardware security key over NFC, all on device.
PGPony has no accounts, no ads, no analytics, and no tracking. The foss build contains no Google services and runs fully on de-Googled devices.
Features
- Encrypt, decrypt, sign, and verify text and files - Modern key generation, including RFC 9580 (OpenPGP v6) Ed25519 and X25519, with Argon2id passphrase protection - Hardware security keys over NFC (YubiKey 5 NFC, Token2): on-card key generation, decrypt, sign, PIN management, and factory reset - Read-only password-store (pass) support, including hardware-key entries - Key discovery via WKD and the keys.openpgp.org verifying keyserver - Optional contacts integration, QR import and scanning - Biometric lock and secure-screen protection
License
Apache 2.0
What's new
- PGPony 4.0.3 — The OpenKeychain Succession The biggest release yet: post-quantum encryption, an OpenPGP provider API that lets other Android apps use PGPony as their crypto engine, and complete translations into five languages. (4.0.3 is a security patch on top of 4.0.2 — a build-configuration fix on top of 4.0.1, which rolled up the 4.0.0 feature release plus the localization and Android 16 update. This is the version shipping to F-Droid.)
- 🔒 Security fix (new in 4.0.3) Every passphrase, PIN, and recovery-code field now declares the password input type, so Gboard and other keyboards no longer learn or suggest what you type into them. Previously these fields were visually masked but presented as ordinary text to the keyboard, which meant a keyboard's personal dictionary could memorize typed secrets — reported by a user review, and fixed across all 37 secret-entry fields in the app (key passphrases, message passwords, card PINs, and backup recovery codes).
- If you used earlier versions: the fix stops future learning but can't remove what a keyboard already memorized — clear it once in your keyboard's settings (Gboard: Settings → Dictionary → Delete learned words).
- 🔮 Post-quantum encryption (ML-KEM-768 + X25519) Generate, encrypt to, and decrypt with quantum-resistant composite keys, in both wire formats in use today:
- IETF format (algorithm 35, v6 keys) — implements draft-ietf-openpgp-pqc, verified byte-for-byte against the draft's official test vectors LibrePGP / GnuPG format (algorithm 8, v5 keys) — interoperates with GnuPG 2.5+: messages encrypt and decrypt in both directions, and public keys import cleanly (ky768_cv25519) Includes passphrase-protected composite keys (Argon2id + AEAD for v6, CFB for v5) and full cross-platform parity with PGPony for iOS — messages, public keys, and secret keys all transfer both ways.
- Known limitations (ecosystem, not PGPony): GnuPG cannot yet import post-quantum private keys from any app (it stores them in a proprietary internal format), and current Sequoia (sq) preview builds implement a different draft revision and cannot read IETF-format keys yet — they fail on the draft's own sample key. Classical keys are unaffected.
- 🔌 OpenPGP API provider PGPony now implements the org.openintents.openpgp.IOpenPgpService2 API — the same interface OpenKeychain provided — so it works as the crypto backend for Thunderbird for Android, K-9 Mail, and Password Store:
- Encrypt, decrypt, sign, and verify on behalf of connected apps, including streaming support for large attachments Hardware-key (NFC smartcard) signing and decryption inside provider operations Security first: no default-allow — every client app is authorized on first use with a signature-pinned allow-list, revocable in Settings → Connected apps 🌍 Complete translations PGPony is now fully translated into German, Spanish, French, Japanese, and Brazilian Portuguese — every surface in the app, including all of the features above: post-quantum key generation, the provider consent/key-picker/passphrase and hardware-card prompts, backup and restore, card management, and Password Store. Each language follows its established conventions (formal vous in French, informal address in German and Spanish) with consistent OpenPGP terminology throughout. Translations are machine-generated against the app's per-language glossaries — native-speaker corrections are very welcome as issues or PRs.
- 🗝️ Keyring & privacy Encrypted keyring backup and restore — one file for your whole keyring, plus import of OpenKeychain .sec.pgp backups Default signing key — pin a signer so it's preselected on every Sign + Encrypt Orbot / Tor integration — route keyserver and WKD traffic through SOCKS with one tap Autocrypt support for peer key discovery Under the hood Now compiles against and targets Android 16 (API 36); minimum supported version unchanged Bouncy Castle 1.85; hand-rolled composite packet codecs validated against GnuPG 2.5.21, the draft-ietf-openpgp-pqc vectors, and PGPony iOS ~300 unit tests, including offline PQC interop fixtures and gated cross-tool harnesses Build configuration now fully committed to the repository, so the tagged source matches the published binary for F-Droid's reproducible build verification versionCode 403 · versionName 4.0.3 · Android 8.0+ (API 26) No migration needed — existing keys, contacts, and settings carry over unchanged. Beyond the keyboard security fix, nothing about the app changed from 4.0.1.
About this version
- Version
- 4.0.3 (403)
- Size
- 14.36 MB
- Requires Android
- 8.0
- Target SDK
- 26
- Architecture
- arm64-v8a, armeabi-v7a, x86, x86_64
- Downloads
- 15
- Updated
- Jul 23, 2026
- Package
- com.pgpony.android
Ratings & reviews
- 50
- 40
- 30
- 20
- 10