every time something like this surfaces I'm reminded how many privacy guarantees end at the app boundary. you can do all the e2e crypto you want, the OS layer is going to do whatever it does with your strings once they hit a render path. probably an unsolvable category of bug as long as notifications need to show readable text somewhere.
> probably an unsolvable category of bug as long as notifications need to show readable text somewhere.
Let screens always show garbled pixel vomit, decoded on device only by your private AR glasses
If you want security through obscurity you can revert to IPoAC (RFC 1149).