Every other messenger asks you to trust their protocol. This one asks you to trust yourself.
The entire security model in 10 seconds
Meet your friend. Say “our secret key is tacomonday.” That’s your key exchange. No protocol. No ceremony.
Type a message. Your browser encrypts it with the key before it leaves your device. AES-GCM. Industry standard.
Our server stores your messages. But it can't read them. Even if we get hacked, the attacker gets meaningless ciphertext.
Type a message. Watch the server's view in real time.
These are real tradeoffs. If they bother you, use something else.
You are the security layer. We give you the tools. You decide how to use them.
The secure messaging bell curve
"we agree on a password in person and type it in"
"well ACTUALLY you need Diffie-Hellman key exchange with double ratchet and X3DH extended triple Diffie-Hellman with post-quantum hybrid KEM and..."
"pre-shared key symmetric encryption with zero-knowledge server"
The entire setup is one conversation with a friend.
We're honest about what we can and can't see. Most apps aren't.
| Data | Can we see it? | Why |
|---|---|---|
| Message content | no | Encrypted before it leaves your device |
| Your encryption key | no | Never sent to the server. Ever. |
| When messages are sent | in transit | Observable in real time, but never stored or logged |
| IP addresses | in transit | TCP/IP requires it, but never stored or logged |
| Who's talking to whom | yes | We need this to route messages |
| Message sizes | yes | We store the ciphertext |
| How often you message | yes | We route the messages |
Encrypted before it leaves your device
Never sent to the server. Ever.
Observable in real time, but never stored or logged
TCP/IP requires it, but never stored or logged
We need this to route messages
We store the ciphertext
We route the messages
Good. You shouldn't trust anyone. Run your own.
Fully open source. MIT license.
No email required. No phone number. Just a username and password.
Then meet your friend and agree on a key.
No password recovery. Forget it and it's gone forever.
That's the deal.