End-to-end encrypted · post-quantum ready

Your conversations,
yours alone.

Frendy is a privacy-first messenger. Messages, files and calls are encrypted on your device and can only be decrypted by the recipient. No phone number, no email — you join with an invite code and a username you choose.

AES-256-GCM encryption No phone number The server can't read a thing
AES-256-GCM
Keys in secure storage
Forward secrecy
A
Anna
encrypted
Are we still on for tonight?21:04
Yep — sending the address now21:05 ✓✓
9f2a·c41d·7be0·a83f·02ic·kkd8·pl3z·q1w9…
📍 shared securely21:05 ✓✓
Perfect 🔒21:06
Message
2256
Symmetric key strength (AES-256)
0 keys
Messages the server can read
3 apps
Android · Desktop · iOS
Never
Private key leaves your device
Security architecture

Security built for the worst case

Not a marketing slogan — auditable cryptography. Here is exactly how it works.

Sender

Text is encrypted with the dialog key (AES-256-GCM).

plaintext → cipher
TLS + pinning

Server

Stores & forwards ciphertext only. No decryption key exists here.

sees only ciphertext
TLS + pinning

Recipient

Ciphertext is decrypted with the dialog key on-device.

cipher → plaintext
The math of impossible
Layer 1 · the cipher
2256
possible keys

Brute-forcing AES-256 isn't "slow" — it's thermodynamically impossible. Iterating through every key would take about 1013× more energy than the Sun will emit over its entire remaining lifetime. This is literal electricity: to run the brute-force on supercomputers you have to power them from the wall — and running them would take exactly that much energy.

Layer 2 · the recovery phrase
1.6M
× the age of the Universe

The seed key is derived via PBKDF2-SHA-256, so brute-force speed is capped by SHA-256 throughput. Even Earth's largest SHA-256 hashing power — the entire Bitcoin network (~6×1020 hashes/sec) — aimed at one account would need ~2.2×1016 years: about 1.6 million times the age of the Universe.

The Sun's entire remaining energy — ~6×10⁴³ J
To brute-force AES-256 — ~3×10⁵⁶ J
× 10¹³ →

The brute-force bar is 10¹³× longer — it wouldn't fit on any screen. Even all the energy the Sun has left is nowhere near enough.

The honest weak point is never the cipher — it's key theft (malware, phishing, a carelessly stored recovery phrase). That's why keys live in a hardware secure chip and are wrapped under your PIN. See the full breakdown →

Standard, battle-tested primitives — no home-made crypto

Purpose
Algorithm
Also used by
Messages & files
AES-256-GCM
HTTPS, Signal, WhatsApp, banking apps · NIST/FIPS
Key exchange
ECDH · P-256
TLS 1.2/1.3 — the entire secure web · iMessage
Calls (1:1)
DTLS-SRTP
Google Meet, Jitsi, Discord, WhatsApp calls
PIN / key protection
PBKDF2-HMAC-SHA256
1Password, Bitwarden, WPA2, disk encryption
Forward secrecy
Double Ratchet + X3DH
libsignal — the same library as Signal & WhatsApp
Post-quantum handshake
PQXDH · X25519 + ML-KEM-1024
Kyber-1024 (FIPS 203) — same path Signal took in 2023
Device key storage
Keystore / TEE + StrongBox
Google Pay, banking apps, contactless payment
Features

Privacy isn't a setting — it's the foundation

End-to-end by default

Every message, file, photo, voice note and call is encrypted on your device. The server relays sealed envelopes it can never open.

No phone, no email

No phone number, no email, no personal data — you join with an invite code and a username you make up. A rare pairing with post-quantum forward secrecy.

Post-quantum ready

Session setup mixes ML-KEM (Kyber-1024) with classic X25519 — protection against "harvest now, decrypt later" quantum attacks.

Duress PIN

A second, "panic" PIN instantly wipes your keys and revokes the session — protection when you're forced to unlock under pressure.

Encrypted at rest

On Android the local database (SQLCipher) encrypts even metadata. Media is stored as encrypted bytes; plaintext lives only in RAM.

E2EE calls & conferences

1:1 calls over WebRTC (DTLS-SRTP), plus group video conferences with end-to-end encryption — not just one-to-one.

Encrypted avatars

The server stores avatars as ciphertext only — decrypted on the client. Most mainstream messengers keep avatars in plaintext.

2FA & session control

TOTP two-factor auth, a live list of your devices, remote session revocation, and login alerts with IP and country on every device.

Hardened against theft

Even a fully-rooted, unlocked phone can't reveal your chats: with a PIN set, your keys are wrapped under a PIN-derived key that is never stored on the device.

Comparison

How Frendy compares to other messengers

A side-by-side look across 15 messengers on the security properties that matter — a good-faith summary from public sources, including where Frendy still trails (open-source, independent audit).

See the full comparison
No phone + forward secrecy + post-quantum
Encrypted avatars & metadata at rest
Duress PIN & E2EE conferences
~ Open-source & external audit — on the roadmap
Cross-platform

One encryption model, every device

Android flagship

Kotlin / Jetpack Compose. SQLCipher at-rest, StrongBox keys, Play Integrity, R8 hardening.

Desktop Windows

Kotlin / Compose Multiplatform. Full v2 group participant, inline audio & video, local history storage.

iOS in progress

Swift / SwiftUI. Auth, dialogs, chat and E2EE in place; media and calls landing next.

Access & principles

Invite-only, by design

Getting in

No phone number. No email. No personal data. To create an account you need just two things: an invite code and a username you make up. That's it.

To get an invite code, for now write to inviteme@frendy.im.

What Frendy is for

Frendy exists to protect the private conversations of ordinary people — families, friends, journalists, activists, professionals — anyone who believes privacy is a right, not a crime. It is not a tool for the shadows: we do not provide Frendy for drug trafficking, child sexual abuse, terrorism or any other criminal activity, and such use has no place here. Access is invite-only precisely so this stays a network for people, not predators.

Pricing
Free

Frendy is free. The only "condition" to join is an invite. We don't charge for private conversations — that's a right, not a paid feature. Optional add-ons (like extended media storage) may cost money later, but secure messaging stays free, always.

Frendy

Take back control of your privacy

Frendy is in testing and free to use. Your conversations stay yours — always.

Download Frendy Read the whitepaper
Android · APK Windows Desktop iOS — in development

Frendy is young and moving fast. Android and Windows are available today, iOS is actively in development, and we're open to building for other platforms.