LockChat

Encrypted chat with no account

Chat without an account. Without history. Without a trace.

LockChat never asks for a phone number or email. Messages are encrypted on your device, split across several servers, then deleted automatically within seconds.

Message encryptionAES-256-GCM
Key exchangeX25519 + ML-KEM-768
Message on server~90 seconds
Account dataNone
Room locked Encrypted
Keys rotated: new member joined
Does the safety number match on your side?Dewi
It matches. We are good to go.You
Great. That invite link was single-use, right?Dewi
Messages vanish from the server in ~90 seconds
Sample viewNotifications without message text

Core principles

Built so there is nothing to store.

The strongest way to protect data is never to hold it. That is the principle LockChat follows.

No account

No phone number, no email. You just enter a room.

No history

Encrypted messages are deleted from the server after about 90 seconds. There is no archive or chat backup.

Keys live in memory only

Keys exist only in device memory while a room is open. The room locks automatically when the app goes to the background.

How it works

One message, from typing to gone.

Every message goes through four stages. No single server ever holds the whole message.

  1. STAGE 1

    Locked on your device

    The message is encrypted with AES-256-GCM, digitally signed, and its length is masked before it leaves your device.

  2. STAGE 2

    Split across several servers

    With Shamir Secret Sharing, the message is split and spread out. One server alone never holds the whole message, not even its encrypted form.

  3. STAGE 3

    Opened only by room members

    Keys are shared between members using hybrid encryption, X25519 + ML-KEM-768. Servers and admins cannot read the contents.

  4. STAGE 4

    Deleted automatically

    The encrypted message disappears from the server in about 90 seconds. No archive, no backup.

    90 s

The diagram simplifies the process. Traffic to the servers also passes through the extra protections described below.

Nine layers of security

LockChat security, one layer at a time.

Each layer has one plain sentence for everyone, followed by technical detail for those who want to check.

Layer 1 · Basics

Core principles

You just enter a room, and nothing is kept afterwards.

  • No account, phone number, or email.
  • Encrypted messages are deleted from the server after about 90 seconds.
  • Keys stay in device memory while the room is open and are not stored on the device or the server.
  • The room locks automatically when the app is in the background.
Layer 2 · Encryption

End-to-end encryption

Messages are locked on the sender's device, and only room members hold the key.

  • Encrypted with AES-256-GCM before it is shown or sent.
  • Servers and admins cannot read it.
  • Every message is signed by its sender, so forged or altered messages are rejected.
  • Message length is masked (padding) so size does not leak the content.
Layer 3 · Forward secrecy

Constantly changing keys

Old keys are discarded, so old recordings cannot be opened later.

  • Keys change when a member joins, leaves, or is removed, and periodically.
  • Old keys are erased from memory. Recorded traffic stays unreadable even if a password or invite leaks later.
  • New members cannot read messages from before they joined.
  • Members who leave cannot read messages sent after they left.
Layer 4 · Post-quantum

Ready for the quantum era

Keys are protected by two layers at once, so breaking just one is not enough to open them.

  • Key sharing uses hybrid encryption, X25519 + ML-KEM-768 (NIST/FIPS 203 post-quantum standard).
  • Both must be broken at the same time to open the key.
Layer 5 · Identity

Identity verification without accounts

You can confirm the person you are talking to is who they say they are, with no account needed.

  • Each member has a temporary identity key generated on their own device.
  • Safety numbers can be compared directly, in person or by phone, to make sure nobody in the middle is impersonating anyone.
Layer 6 · Servers

Servers know as little as possible

Servers only carry sealed packages, without knowing who sent them or what is inside.

  • The room code is never sent to the server, only an irreversible fingerprint of it.
  • The room password is processed with Argon2id on your device. The server never receives it.
  • Servers do not record who sent which message and do not store IP addresses.
  • Messages are split with Shamir Secret Sharing and spread across several servers. The storing servers change periodically.
Layer 7 · Control

Invites and room control

The room owner holds the door: who may enter, for how long, and when it closes.

  • Invites are a link or QR code. The key sits in the part that is never sent to the server.
  • Single-use or limited, valid for 10 minutes, 1 hour, or 24 hours, and revocable at any time.
  • Optional waiting room: new members must be approved by the owner.
  • The owner can lock the room, limit members, require a password, and remove members. When someone is removed, all room keys are replaced.
  • Room settings are signed by the owner and verified by every server and member.
Layer 8 · Extra protection

Additional protection

A few small safeguards close gaps that are often overlooked.

  • Decoy traffic (on by default): fake encrypted messages at random intervals so a network observer cannot tell when you are really chatting. Can be turned off.
  • App integrity check: the app code is compared across servers, and you are warned if any server differs.
  • Screen blur mode, notifications without message text or sender name, a warning before opening external links, and automatic clearing of secrets from the clipboard.
  • Spell checkers and writing extensions are disabled in the chat field.
  • Keeps working if some servers go down.
Layer 9 · Operators

Operator security

Even the people who run the service have no shortcut to your chats.

  • The admin panel requires two-factor authentication (2FA).
  • Per-device sessions and alerts for logins from a new network.
  • Operator keys do not give access to anyone's chat content.

Transparency

Limits you should know about.

No system protects against everything. Here is what LockChat cannot do for you.

Your own device still matters

Malware, screen recorders, or someone looking at your screen can read the messages that are displayed.

An invite works like a key

Anyone holding a valid invite or the room password can ask to join. Use single-use invites and member approval.

Display names are not verified

Compare safety numbers when you need certainty.

Network providers still see the connection

They can tell that you connect to this service, but not what you say.

Lost messages cannot be recovered

Messages are not stored by design, so there is nothing to restore.

FAQ

Frequently asked questions.

Can the admin read my chats?
No. Messages are encrypted on the sender's device, and neither servers nor admins hold a key to open them. Operator keys do not give access to anyone's chat content either.
Are chats stored?
No. Encrypted messages are deleted automatically from the server after about 90 seconds, and there is no archive or backup. Keys exist only in device memory while the room is open.
What if a server is seized or hacked?
Messages are split and spread across several servers, so one server does not hold a whole message, not even its encrypted form. Servers also do not store IP addresses or records of who sent what. The service keeps running if some servers go down, and messages stay end-to-end encrypted.
What is a safety number?
A number calculated from each member's temporary identity key. Compare it directly, in person or by phone. If it is the same on both sides, nobody in the middle is impersonating anyone.
Do I need to turn off decoy traffic?
Usually not. It is on by default and makes it hard for a network observer to guess when you are really chatting. You can turn it off if you need to.
What happens if I leave a room?
The room keys are replaced automatically, so you cannot read messages sent afterwards. Messages that are gone cannot be recovered because they are not stored.

Create your first room.

No sign-up. Create a room, send a single-use invite, and compare safety numbers.

Start chatting