There is no account here. Nothing of yours we could read, sell or hand over.
When the app is running on both phones, messages go from phone to phone: directly when the network allows, otherwise through a relay that cannot read them. When the other phone is offline or does not confirm a message within a few seconds, a sealed copy waits on one of our nodes - we see that something arrived for an address, never a word of what it says. Those nodes are ours by default, and the app can be pointed at others. We never ask for your number, never touch your address book, and never learn your name.
The message is encrypted in the phone's own memory with Phone B's public key. What leaves for the relay is an unreadable stream of bytes. Your history stays on this device - unless you switch backups on, and then a copy sealed with your twelve words rests on a mailbox node too.
Runs without a Google account. It keeps the connection alive in the background, so a message or a call still reaches you while the phone sleeps.
Messaging, calls, video and groups all work. We run it on a real iPhone talking to a real Android phone on our desk - hardware, not a simulator. It is not in the App Store yet; that is the next step.
The same app, built for the desktop. We build and run it on Apple Silicon; Intel Macs are not built yet.
A desktop build with an ordinary window. Not distributed through stores yet.
The same desktop build as Linux and macOS, with a proper installer that updates itself without asking for administrator rights. It just is not in the Microsoft Store.
Nothing is tied to a phone number or an email. Nobody can take over your SIM with a forged letter, intercept a text message and walk off with your conversations - there is no number to take.
Nodryn never opens your contacts. You hand your address to the people you actually want to talk to. No cheerful "your friend just joined" from a list you never shared.
No trackers, no advertising code, no analytics. No company learns when you were online, who you talked to, or how long you stayed. Your accepted contacts do see when you were last around - that is what "last seen" is for, and it turns off in one tap.
An identity is just mathematics
On first launch your phone makes a pair of keys and shows you twelve words. Write them on paper, with a pencil. They are the only way back to your identity if you lose the phone. We do not have them and no server does - the only other copy sits inside your own phone, which is why the app can show them to you again.
We will not tell you "we see nothing" - that would be a lie. Here is what is actually visible:
- The relay sees which device is speaking to which - it could not forward a packet otherwise - plus the network address, the size and the time. It is not forbidden from reading the words. It simply has no way to.
- The mailbox: if you are offline, a sealed envelope waits on our node until your phone confirms it, and at most seven days either way. The envelope is visible. What is inside is not.
- The mailbox holds more than mail. Between messages it keeps your published keys, your list of devices and the address used to wake your phone - thirty days after you last touch that node. If you switch backups on, a sealed copy of your history sits there for up to a year. All of it is on the privacy page, with the exact clocks.
- Losing the twelve words: nobody on earth, us included, can reset anything by text message or bring your conversations back. We do not have your keys and cannot get them.
- Waking an iPhone: Apple draws the notification before our app runs, so the wake-up signal has to say which of three cards to draw - a message, an incoming call, or a missed one. Apple sees that, and never a name or a word. On Android the signal is literally empty.
- An unlocked phone: if someone picks up your device already unlocked, encryption does nothing at all. Lock your screen. That is the only thing that helps here.
Install the app, create your identity, and it connects through our nodes with nothing to configure. Our relays introduce the two phones and carry whatever cannot go direct, our lookup nodes tell your phone which relay the other person's device is on, and our mailbox keeps a sealed envelope for up to seven days when your phone cannot be reached or does not confirm in time. There is nothing to pay and no sign-up: no phone number, no email, no password. What each of them can see is on the privacy page, where the lookup node is called the address book.
The relay, the lookup node and the mailbox are three ordinary programs, small enough for an always-on computer at home if your provider gives you a public address and you can open two ports; a cheap rented server is plenty. Once yours are running, you point the app at them in Settings, Network. Some honest limits. Mail sent to you waits in your mailbox once your contacts' apps know it and it answers; until then it waits in the sender's own mailbox, which is ours by default. The mail you send follows the same rule the other way. A lookup node only helps the apps that list it. And only a mailbox holding the app's Apple and Google keys, which we keep, can wake a sleeping iPhone or an Android that relies on Google's notifications, so your own mailbox cannot wake those phones.
Today, two phones that have each other as contacts find each other on the same home Wi-Fi by themselves, and the conversation moves to a direct path between them. That also means other devices on the same network can see a Nodryn device is there. Guest and office networks that keep devices apart block this, and an iPhone asks your permission to use the local network first. Without any nodes, phones on different networks usually cannot find or reach each other, so a letter would wait in the sender's phone and go out when both are on the same network again with the app running. A mode that uses no outside nodes at all is planned but not built: today the app still talks to the lookup nodes and the mailbox, and an iPhone still registers with Apple for wake-ups.