Layer 1 · Basics
Core principles
You just enter a room, and nothing is kept afterwards.
- No account, phone number, or email.
- Encrypted messages are deleted from the server after about 90 seconds.
- Keys stay in device memory while the room is open and are not stored on the device or the server.
- The room locks automatically when the app is in the background.
Layer 2 · Encryption
End-to-end encryption
Messages are locked on the sender's device, and only room members hold the key.
- Encrypted with
AES-256-GCM before it is shown or sent.
- Servers and admins cannot read it.
- Every message is signed by its sender, so forged or altered messages are rejected.
- Message length is masked (padding) so size does not leak the content.
Layer 3 · Forward secrecy
Constantly changing keys
Old keys are discarded, so old recordings cannot be opened later.
- Keys change when a member joins, leaves, or is removed, and periodically.
- Old keys are erased from memory. Recorded traffic stays unreadable even if a password or invite leaks later.
- New members cannot read messages from before they joined.
- Members who leave cannot read messages sent after they left.
Layer 4 · Post-quantum
Ready for the quantum era
Keys are protected by two layers at once, so breaking just one is not enough to open them.
- Key sharing uses hybrid encryption,
X25519 + ML-KEM-768 (NIST/FIPS 203 post-quantum standard).
- Both must be broken at the same time to open the key.
Layer 5 · Identity
Identity verification without accounts
You can confirm the person you are talking to is who they say they are, with no account needed.
- Each member has a temporary identity key generated on their own device.
- Safety numbers can be compared directly, in person or by phone, to make sure nobody in the middle is impersonating anyone.
Layer 6 · Servers
Servers know as little as possible
Servers only carry sealed packages, without knowing who sent them or what is inside.
- The room code is never sent to the server, only an irreversible fingerprint of it.
- The room password is processed with
Argon2id on your device. The server never receives it.
- Servers do not record who sent which message and do not store IP addresses.
- Messages are split with Shamir Secret Sharing and spread across several servers. The storing servers change periodically.
Layer 7 · Control
Invites and room control
The room owner holds the door: who may enter, for how long, and when it closes.
- Invites are a link or QR code. The key sits in the part that is never sent to the server.
- Single-use or limited, valid for 10 minutes, 1 hour, or 24 hours, and revocable at any time.
- Optional waiting room: new members must be approved by the owner.
- The owner can lock the room, limit members, require a password, and remove members. When someone is removed, all room keys are replaced.
- Room settings are signed by the owner and verified by every server and member.
Layer 8 · Extra protection
Additional protection
A few small safeguards close gaps that are often overlooked.
- Decoy traffic (on by default): fake encrypted messages at random intervals so a network observer cannot tell when you are really chatting. Can be turned off.
- App integrity check: the app code is compared across servers, and you are warned if any server differs.
- Screen blur mode, notifications without message text or sender name, a warning before opening external links, and automatic clearing of secrets from the clipboard.
- Spell checkers and writing extensions are disabled in the chat field.
- Keeps working if some servers go down.
Layer 9 · Operators
Operator security
Even the people who run the service have no shortcut to your chats.
- The admin panel requires two-factor authentication (2FA).
- Per-device sessions and alerts for logins from a new network.
- Operator keys do not give access to anyone's chat content.