One-time channel
Bomb messages ride a to-device, end-to-end encrypted channel. Once delivered, the server deletes them. They are never written into the stored conversation, so there is nothing to hand over later.
End to end encrypted. Your keys never leave your device. The server sees only noise.
Public launch in
Your conversation, as you read it.
Synced end to end. Never unencrypted anywhere but your screen.
Two terminals. Same message. Two very different outcomes.
What your device does, every single time.
What a mandated scanner would face, and why it fails.
A bomb message never rests on the server like an ordinary one. It travels a one-time, end-to-end encrypted channel, and the moment it lands the server drops it. It never enters any history. It burns on both sides on your timer, and detonates the instant the other person reads it.
Bomb messages ride a to-device, end-to-end encrypted channel. Once delivered, the server deletes them. They are never written into the stored conversation, so there is nothing to hand over later.
Set a timer, say five minutes. When it runs out the message is wiped on both devices and on the server too, so retention never quietly keeps a copy. Set it to detonate on read, and it goes the second the other person opens it.
Safety does not have to be grim. When a bomb goes off, a burst of balloons floats it away. A small, playful, premium touch on top of hard cryptography.
In the Android app, while a bomb is in the conversation the screenshot is blocked: the system captures a black frame, and the other person is told someone tried.
Honest: browsers cannot block an OS screenshotStraight talk: no website in any browser can stop your operating system from taking a screenshot, and we will not pretend otherwise. Full screenshot protection lives in the Android app. In the browser, the burn timer and the one-time channel still do their job.
Not a setting you switch on. The defaults are the promise.
Built on Matrix with Olm and Megolm. Keys are generated on your device. The server relays ciphertext it can never read.
The server is ours, not a rented platform. You can run your own. No third party sits between you and the people you trust.
Join by invite code or a private email. No number, no address book upload, no social graph for anyone to map.
We do not scan your messages, not for ads, not for training, not for anyone. Your data is yours, full stop.
Encryption hides what you say. A network layer hides that you said it at all. Here is exactly what Hush does, and what it does not.
Run Hush through your own VPN, a trusted provider, or the Tor network. Traffic stays inside your tunnel and does not leak around it, so the path stays as private as the tunnel you chose.
There is no address book upload and no contact discovery by phone number. The server relays ciphertext and cannot build a map of who knows whom.
For an extra layer of anonymity, we recommend running Hush over Tor or a no-logs VPN. It is the honest way to hide the network trail, and it puts that choice in your hands.
Honest note: Hush does not currently ship its own built-in VPN. Routing through Tor and an in-app VPN are planned Pro features that will only go live after an independent security audit. Until then, use your own VPN or Tor, and we will tell you the day the built-in option is real, not before.
No store account, no middleman. Install the app directly and verify it yourself.
Direct APK, signed release build. Android 8.0 or newer.
Download APKDesktop app is in active development. No installer yet, check back soon.
SoonNot in an app store, on purpose. Verify the checksum before you install anything, from us or anyone else.
You do not need a phone number, and you do not even need someone to invite you. Register with a private email from Proton Mail or another privacy-first provider, and stay unlinked from your real identity from the very first step.
Do not have a private mailbox yet? Proton Mail is free, based in Switzerland, and end to end encrypted. Creating one there first is a good move before you sign up anywhere.
Not marketing. Concrete promises about what happens to your words and what never does.
Anything we cannot honestly guarantee yet, like a built-in VPN or video calls, lives on the roadmap and stays there until it is real. Encryption itself is free forever.
Hush is built by people, not a company. No investors, no owner, no key held in reserve. A Kickstarter campaign will fund the one thing money can honestly buy here: proof.
Every pledge is public. Every euro is accounted for in the sponsors ledger below. Encryption itself is free forever, with or without the campaign.
Encryption is never behind a paywall. Paid tiers activate only after an independent security audit.
The same lock, now on the line. Voice and video are on the way, encrypted end to end like every message you send.
Talk in real time with the same end to end encryption. No number to dial, no operator in the middle. Coming soon.
SoonFace to face, encrypted the whole way. The server relays only noise, never a frame it can watch. Coming soon.
SoonWhat exists. What does not. Why.
No marketing spin. If we cannot answer it honestly, we do not ship it.