The world's most private messenger. End-to-end encrypted and operator-blind, with Tor and I2P one tap away — engineered for journalists, dissidents, and anyone who refuses to be the product.
Every feature is designed assuming the network is hostile, the device is compromised, and the adversary is watching.
Route messages and calls through Tor or I2P — two independent anonymity networks, both embedded directly in the app. No Orbot, no third-party router required. Tunnels to recent contacts are pre-positioned in the background, so calls to them connect fast.
Hybrid key exchange combines the proven Signal protocol with post-quantum lattice cryptography. Messages are safe against both classical and quantum adversaries — today and in the future.
Self-destructing conversations with Double Ratchet forward secrecy. Every message uses a fresh encryption key — past messages stay unrecoverable even if your device is seized tomorrow.
Constant-rate cover traffic masks real message patterns using Poisson-distributed dummy messages. Adversaries watching the network cannot distinguish silence from active conversation.
Real-time voice calls with per-call XChaCha20-Poly1305 frame encryption. I2P contacts get direct audio — neither peer's IP is ever exposed. Redundant packet delivery tolerates ~40% network loss so calls stay clear on unstable connections. Keys are ephemeral and never stored.
Under coercion, a decoy PIN opens a separate, believable profile while your real data stays sealed — and a separate duress phrase wipes the real data. StrongBox-backed keys mean wiping is cryptographically irreversible.
Tapping a URL in any chat never opens your default browser. Choose "Open via Tor" to hide your IP entirely, or "Private browser" for a fast isolated view — no cookies, no autofill, no saved credentials, completely separate from Chrome.
Every message follows the same path — encrypted before it leaves your device, unreadable everywhere in between.
Plain message
On your device
No IP, no logs
Peer decrypts
Zero trace
Android only for now. Choose the install path that matches your threat model.
Trust is earned through transparency, not claims.
Every line of code — app, relay, crypto core — is AGPL-3.0 and will be published for anyone to read, audit, and fork, alongside the independent audit. Current status →
With the public source release, the APK you download will hash identically to one built from source at the same commit — verifiable with commands we will publish on the download page.
The relay stores no IP address, no metadata, no message history, and no identity — so there is nothing to seize and nothing to hand over. How we stay verifiable →
Public releases will be signed via Sigstore with the signing event logged in the public Rekor transparency log, so you can verify the provenance chain yourself.
No Sentry, no Firebase Crashlytics, no Google Analytics, no Mixpanel, no advertising IDs. Adding any of these is a build-time rejected change.
External audit by a specialist firm (Cure53 / Trail of Bits / Quarkslab) is in procurement. Findings will be published in full when complete.