Open Free and open source, read the code Get it Donate App help Contact
Messenger
The app
Developers
Project
Legal

A flamenet.io account is not a Flamenet Messenger account. The two sign-ins are separate.

Flamenet Messenger

Simple, private messaging.

Messages are locked on your phone and can only be opened by the person you sent them to. No phone number, no ads, and nobody reading over your shoulder. We're also upfront about where the limits are.

No phone number No ads, no trackers Free and open source
The home screen of the app: a row of stories across the top, then four conversations showing the last message, when it arrived, and an unread count.

Free to use, open to read, and yours to run on your own server

Free forever No ads No phone number Open source Yours to host
New in the app

Five new things in the messenger.

Each one works the way the rest of the app does.

A poll nobody can attribute. Ask a group something and no vote is sent to anybody, including you as the person asking. Each vote is split into random pieces, one per member, and everybody publishes only the sum of the pieces they were handed. Adding those sums gives the counts. Everyone other than the voter would have to work together to know how one person voted.

Carry a call to another device. On a call on your phone, pick it up on the tablet and keep talking. The other person hears a short gap, stays where they are, and gets one call in their log rather than two.

A reaction only they see. In a group, react to the person who wrote it rather than to the room. Nobody else is sent it.

React during a call. Say yes without interrupting. It shows for a moment and nothing is saved.

Off the record. Both phones stop writing the conversation down. Close the app and it is gone. It is agreed between the two phones, so it cannot be on for one of you and not the other.

On Android from version 0.18. On iPhone in the TestFlight beta.

What you get

Three things, and they share one lock.

Messages, your files and your keys, the same account, the same passphrase, and the same rule throughout: it's sealed on your phone before it goes anywhere, so there's nothing readable in the middle for anyone to ask us for.

Messages

Chats, groups, voice calls and stories. No phone number, nothing to sell, and conversations that can tidy up after themselves on both phones at once.

See what's in it

Files

Your documents stay on your phone rather than on our servers, marked with how sensitive they are, and sealed the moment you send one to somebody.

See how it works

Wallet

A standard twenty-four-word phrase that works in any other wallet, a new address each time you receive something, and keys nobody but you can reach.

See what's yours

All three are on Android today, and on iPhone in the TestFlight beta. Each page says exactly where its part stands.

Get it

Get Flamenet Messenger

Android is ready to install today, and the iPhone app is open as a TestFlight beta.

Installing on Android? What your phone will ask, how to get updates through F-Droid, and how to check the build is really ours →

Available in the United States, Mexico, Guatemala, El Salvador, Honduras, Costa Rica, Panama, Peru and Bolivia. Signing up from anywhere else is refused, and the app will say so rather than looking broken. This page is readable everywhere on purpose, finding out after you have installed something and chosen a password is a worse way to learn it.

Run it on your own machine.

The server is two containers and a config file. There is nothing to sign up for and nothing that phones home, and it serves this very page, so a fresh install explains itself rather than greeting you with an error.

The server is where your account and any undelivered messages live. Running it yourself keeps all of that on hardware you control.

cp .env.example .env
# fill in the three secrets it asks for
docker compose up -d
Developers

Everything is written down.

This part is for anyone who would like the details. The design is published in full, and the three engines are tested against each other.

One document, start to finish

How the encryption works and how the server behaves are described in one document, so anyone who wants to write their own version has what they need.

Read the specification

Three versions, checked against each other

The JavaScript, Swift and Kotlin engines are tested against each other and against published examples, so compatibility is something we measure rather than assume.

How they are tested

Open source, free to reuse

The encryption engine is public and freely licensed. Read it, reuse it, or let us know if you spot a mistake.

Source code

Nothing here is home-made. The encryption is built from published, standard building blocks that other secure messengers use too, and the specification names every one of them and explains why it was chosen.

Running protocol version 3 · this server answers for relay.flamenet.io

Community

Where to start reading

Some of the most useful help we get isn't code, it's someone reading the design closely and telling us what they find.

FAQ

Common questions.

Can you read my messages?

No. The server holds a sealed envelope and nothing that opens it, and there is no plain mode to switch to, so there is no setting that quietly hands your messages over. That holds even if you run the server yourself: you would be looking at sealed envelopes too.

So what does the server know about me?

That you have an account, who you write to, when, roughly how big the message was, and the internet address you connected from. It has to know where to send things. It doesn't know what any of it said. There's a page listing every last field rather than a paragraph summarising it.

How do I know I'm really talking to my friend?

There are two ways to check, and neither one depends on trusting us. Every key is published to a list that can't be rewritten afterwards. On iPhone the app checks that list before it will use a key, so a substitution leaves a permanent record; the Android app does not check it yet, and until it does that half is a promise about the server rather than something your phone enforces. You can also compare a short safety number with your friend in person or over the phone, and that one works on both: if the numbers match, there is nobody in between.

Do I need a phone number?

No. A username, plus an email address only on a server that keeps its own accounts. People reach you by the name your friends already know you by, and your number never enters the picture.

What does it cost?

Nothing, and there is no paid tier waiting in the wings. There are no ads and nothing to sell either, so donations are what keep it going.

Can I really run it myself?

Yes, and we test it that way. It's a Docker Compose file with the server and its database; the apps can be pointed at your address instead of ours. The instructions fit on one page.

Has it been audited?

Not by an outside firm yet, that costs money we are still raising. The engine has a large test suite, the three implementations are checked against each other, and the design is published so anyone can review it. Those are all worth something, and they are a different thing from a professional review, so we keep the two clearly apart.

What if I lose my phone?

Sign that device out from another one you still have. Its keys and anything still waiting for it are removed together, so a phone that is no longer in your hands can't receive anything new.

Free and open source · No ads · No phone number · Your own server if you want one