Privacy First  ·  Open Source  ·  Zero Logs

GHOST
PROTOCOL

The world's most private messenger. End-to-end encrypted and operator-blind, with Tor and I2P one tap away — engineered for journalists, dissidents, and anyone who refuses to be the product.

Live encryption plaintext
meet me at the safehouse at 9pm
E2E
Encrypted — every message
0
Server logs — ever
100%
Open source — AGPL-3.0
Free
Forever — no subscription
What we never collect — by architecture, not by promise
No IP address
The relay never sees where you connect from
No GPS / location
No coordinates, no cell towers, no Wi-Fi names
No phone number
No account tied to your SIM or carrier
No email address
No registration, no verification, no inbox
No real name
Your identity is a 24-word phrase on your device
No device ID
No IMEI, no Android ID, no ad identifier
No contact list
We never learn who you talk to
No analytics
No Firebase, no Sentry, no telemetry of any kind

Engineered for the paranoid

Every feature is designed assuming the network is hostile, the device is compromised, and the adversary is watching.

Built-in Tor & I2P

Route messages and calls through Tor or I2P — two independent anonymity networks, both embedded directly in the app. No Orbot, no third-party router required. Tunnels to recent contacts are pre-positioned in the background, so calls to them connect fast.

Post-quantum encryption

Hybrid key exchange combines the proven Signal protocol with post-quantum lattice cryptography. Messages are safe against both classical and quantum adversaries — today and in the future.

Ghost Chat

Self-destructing conversations with Double Ratchet forward secrecy. Every message uses a fresh encryption key — past messages stay unrecoverable even if your device is seized tomorrow.

Ghost Signals

Constant-rate cover traffic masks real message patterns using Poisson-distributed dummy messages. Adversaries watching the network cannot distinguish silence from active conversation.

Encrypted voice & I2P calls

Real-time voice calls with per-call XChaCha20-Poly1305 frame encryption. I2P contacts get direct audio — neither peer's IP is ever exposed. Redundant packet delivery tolerates ~40% network loss so calls stay clear on unstable connections. Keys are ephemeral and never stored.

Duress PIN & panic wipe

Under coercion, a decoy PIN opens a separate, believable profile while your real data stays sealed — and a separate duress phrase wipes the real data. StrongBox-backed keys mean wiping is cryptographically irreversible.

Safe link opening

Tapping a URL in any chat never opens your default browser. Choose "Open via Tor" to hide your IP entirely, or "Private browser" for a fast isolated view — no cookies, no autofill, no saved credentials, completely separate from Chrome.

From keystroke to oblivion

Every message follows the same path — encrypted before it leaves your device, unreadable everywhere in between.

1

You type

Plain message

2

Encrypted

On your device

3

Operator-blind relay

No IP, no logs

4

Delivered

Peer decrypts

5

Deleted

Zero trace

Download Ghost Protocol

Android only for now. Choose the install path that matches your threat model.

Available now

Google Play

Live on Google Play with auto-updates and push notifications. The fastest way to get Ghost Protocol today.

Get it on Google Play Install instructions →

Free · AGPL-3.0

Planned

Direct APK

A Google-free APK with Sigstore verification instructions arrives with our open-source release — best for high-threat users who avoid Play entirely.

Details on the download page →

Coming with the public source release

Planned

F-Droid

Built from source on F-Droid's infrastructure. No Firebase, no Google services. Uses UnifiedPush (Ntfy recommended) for instant delivery.

F-Droid plans →

Planned after the open-source release

Why you can trust it

Trust is earned through transparency, not claims.

Open source (release planned)

Every line of code — app, relay, crypto core — is AGPL-3.0 and will be published for anyone to read, audit, and fork, alongside the independent audit. Current status →

Reproducible builds (planned)

With the public source release, the APK you download will hash identically to one built from source at the same commit — verifiable with commands we will publish on the download page.

Operator-blind

The relay stores no IP address, no metadata, no message history, and no identity — so there is nothing to seize and nothing to hand over. How we stay verifiable →

Sigstore APK attestation (planned)

Public releases will be signed via Sigstore with the signing event logged in the public Rekor transparency log, so you can verify the provenance chain yourself.

Zero telemetry

No Sentry, no Firebase Crashlytics, no Google Analytics, no Mixpanel, no advertising IDs. Adding any of these is a build-time rejected change.

Security audit planned

External audit by a specialist firm (Cure53 / Trail of Bits / Quarkslab) is in procurement. Findings will be published in full when complete.