
Peer-to-peer, end-to-end encrypted chat. No inbox. No account to recover. Nobody's listening — not even us.
Peer-to-peer, end-to-end encrypted chat.
No inbox. No account to recover. Nobody's listening — not even us.
Messages travel directly between peers over libp2p and are encrypted with the Signal-style Olm/Megolm protocols (via vodozemac) before they ever leave your device. The only server involved is a small directory that helps peers find each other's current address. It never sees message content, and it's purgeable in one command.
See docs/THREAT_MODEL.md and
docs/SECURITY.md for what's actually protected against
and how.
First run — pick a name; nothing else to set up.
Conversations — the group rail, contact list, and an end-to-end encrypted chat pane.
Settings — mic sensitivity, push-to-talk, launch-at-login, network reachability.
crates/directory-server) maps a user ID to a current network address
and nothing else. It's structurally incapable of reading message content:
its Cargo.toml doesn't even depend on the crates that know how.There are two kinds of identity in this app, and they're deliberately kept separate:
identity::Identity). Your public "user ID" is just the
fingerprint of that key (wire_proto::user_id_from_ed25519). It can't be
issued or revoked by any server, because no server is involved in creating
it.PeerId), used
only for the transport layer. It can change across restarts without
affecting your chat identity at all; the two are bound together only by a
presence record you sign yourself.Finding someone and actually talking to them are two different steps: