Wednesday, 26 August 2026 Independent review of faith, culture & public life About the review
Hochland Search

Religion

Can a priest’s chat be more protected than Signal?

D.O.M. is being built as a multi-Christian social and communications platform. Its most unusual privacy idea is not encryption alone, but the possible overlap of technology, church secrecy and legal pastoral privilege.

Can a priest’s chat be more protected than Signal?
D.O.M.

Signal offers a clean promise: the contents of a conversation are protected by end-to-end encryption, so the service itself cannot read them. A conversation with a priest introduces a different kind of question. What if privacy depends not only on who can technically decrypt a message, but also on what kind of relationship exists between the people speaking?

That question sits at the centre of an unusual experiment taking shape around D.O.M., a Christian digital project whose materials describe a social network and communications platform for multiple Christian communities. The planned environment includes a social feed, ordinary user and clergy profiles, comments, reactions, reposts, chats, calls, video conferences and a dedicated workspace for clergy. The project also describes its own infrastructure rather than a simple layer on top of Facebook, Telegram or another existing network.

This is enough to make D.O.M. more than a church bulletin board. It is intended as a place where public community life and private communication can happen inside the same ecosystem. But the most interesting possibility emerges precisely where the public platform ends and a private pastoral conversation begins.

There is an important technical limit. The project materials available for D.O.M. do not establish that its chats are end-to-end encrypted, that servers never see plaintext, or how encryption keys are created and stored. Those details matter. Signal can make a strong technical claim because its system is designed so that message and call content is end-to-end encrypted and inaccessible to Signal itself. D.O.M. cannot simply borrow that claim by analogy.

Yet Christianity brings another privacy tradition into the room, one that is much older than modern cryptography.

In Catholic canon law, the sacramental seal is treated as inviolable. Canon 983 forbids a confessor from betraying a penitent by words or by any other means and for any reason. Canon 984 goes further: information acquired in confession may not be used to the detriment of the penitent even where there is no danger that the information will be disclosed.

The language is ancient in purpose, but the law now meets modern devices directly. Canon 1386 provides penalties not only for a confessor who directly violates the seal, but also for recording what is said in sacramental confession by means of a technical device or maliciously distributing it through social communications. A direct violation by the confessor can bring the Church’s most severe canonical sanction.

Orthodox practice is not identical to Catholic canon law, but it has a comparable insistence on secrecy. The Orthodox Church in America’s 2023 guidelines describe the secrecy of the Mystery of Penance, even under severe external pressure, as a rule binding the whole Orthodox Church and state that betrayal can lead to canonical punishment of the priest.

This does not turn every message sent to a priest into a confession. That distinction is essential. Catholic authorities have repeatedly said that the Sacrament of Penance itself cannot be performed through a telephone, email or other remote communications channel. A priest can offer spiritual advice at a distance, but a digital exchange is not automatically a sacramental confession and cannot simply be labelled one by software.

The legal picture is similarly conditional. Some secular legal systems protect communications with clergy, but the scope depends on jurisdiction, the role in which the clergyman was acting, the expectation of confidentiality and sometimes the rules of the religious body involved.

Wyoming provides a particularly clear American example. State law says a clergyman or priest may not testify about a confession made to him in his professional character when the church requires secrecy. Project documents supplied for D.O.M. identify an associated church non-profit structure in Wyoming. That does not mean every D.O.M. chat is privileged under Wyoming law. It does make the state’s rule relevant to the project’s institutional design.

Germany offers an even broader formulation in some respects. Section 53 of the German Code of Criminal Procedure gives clergy a right to refuse testimony about information entrusted to or learned by them in their capacity as spiritual advisers, or Seelsorger. The civil procedure code contains a parallel protection for matters entrusted in the exercise of pastoral care. Section 160a of the criminal procedure code adds procedural safeguards around some information covered by testimonial privilege, including non-use and deletion rules, although statutory exceptions remain.

The German wording is important because it does not depend solely on whether a formal sacramental confession took place. Pastoral care can be a legally meaningful relationship in its own right. But once again, the context must be real. A verified priest answering a deliberate request for spiritual counsel is a different situation from a casual comment thread or an ordinary direct message.

European data protection law adds another layer, though not an immunity. Under Article 9 of the GDPR, information revealing religious or philosophical beliefs belongs to the special categories of personal data. That means a platform built around faith begins with data that the law regards as unusually sensitive. There is a conditional exception for certain non-profit bodies with religious aims, but it is narrow and does not free an open social network from the ordinary disciplines of data protection.

Taken together, these rules suggest a product opportunity that is more serious than marketing a “Christian Telegram.” A dedicated Pastoral Confidential mode could make the nature of a conversation explicit before the first sensitive message is sent.

Such a mode would need more than a label. The clergy account should be verified, and the user should consciously choose a pastoral conversation rather than fall into it accidentally. The interface should explain that church confidentiality and legal privilege depend on circumstances and jurisdiction. The platform should minimize metadata, exclude the conversation from advertising and recommendation systems, apply strong end-to-end encryption if the technical architecture supports it, and keep retention as short as the pastoral purpose allows.

Controls against forwarding or quoting could reduce casual leakage, although no interface can prevent a determined recipient from photographing a screen. The important security question is not whether a button disappears, but whether the service itself can access content, what metadata it keeps, how long it keeps them, who can compel disclosure and what the recipient is permitted or obliged to do with what has been entrusted to him.

That is where the comparison with Signal becomes useful rather than promotional. Signal protects message content through cryptography. A properly designed pastoral channel could, in some circumstances, add duties and privileges attached to the human relationship itself. One system asks whether the server can read the message. The other also asks whether the recipient may disclose it, use it against the speaker or be forced to testify about it.

Those protections are not interchangeable. Canon law cannot repair weak encryption. Encryption cannot create a sacramental seal. A state evidentiary privilege does not necessarily stop a platform from collecting metadata. GDPR sensitivity does not automatically create clergy privilege. The strength comes only when each layer does its own job.

For D.O.M., the decisive next step is therefore architectural, not rhetorical. If the project wants to make pastoral privacy a defining feature, it will need to publish what the server can see, where keys live, which metadata are retained, how deletion works, how clergy are verified and what precisely distinguishes ordinary chat from confidential pastoral care.

The Church has spent centuries defining situations in which a person may speak and the listener is bound to silence. Digital platforms have spent decades trying to secure packets, devices and servers. D.O.M.’s most original possibility lies in bringing those two traditions together without pretending they are the same. Whether it succeeds will depend on the rules written into both the code and the relationship before anyone types the first confession-like sentence.

Julian Lindner

Author

Editorial Writer

Julian Lindner covers public affairs, politics, business, culture and daily news for Hochland. The role focuses on verification, context, and clear explanations for readers.