Show HN: PrivaMesh – private messaging without servers or phone numbers

privamesh1 pts0 comments

PrivaMesh - Private Encrypted Messenger · PrivaMeshSkip to content<br>End-to-end encrypted · No phone number<br>The Private messenger that knows nothing about you<br>There is no PrivaMesh server. Nothing to subpoena, breach, log, or shut down. Just end-to-end encrypted messages - no phone number, no email, no metadata. Your keys and chats stay on your device. Trust math, not companies.<br>Get PrivaMeshHow the encryption works<br>No Phone Number<br>· No Servers<br>· E2E Encrypted

The differentiator<br>No servers - concretely<br>Most “private” messengers still run servers that see who you talk to. PrivaMesh has none. Here is exactly where every piece of your data lives.

WhatWhere it livesHowYour messagesA public, decentralized transportEncrypted blobs, addressed to one-time addressesYour inboxThe public transport itselfRetrieved and decrypted only on your deviceYour keysYour iPhone Keychain onlyBiometric-locked, never leave the deviceYour contacts & historyYour iPhone onlyNever synced, never uploaded anywhereYour identityAn account phrase you holdEncryption keys on your device - no phone, no emailThe "PrivaMesh server"Does not existNo account server; the transport is public and swappable<br>How the serverless architecture works →

One message, three steps<br>Send → Transport → Receive. No middle box, no inbox on someone else’s computer.

01Send<br>Your message is padded to a fixed size and sealed with AES-256-GCM under a fresh Double Ratchet key - on your device, before it ever leaves.

02Transport<br>The encrypted blob travels over a public, decentralized transport, addressed to a one-time address. No account server ever holds it.

03Receive<br>Your device retrieves and decrypts it locally with keys only you hold, then advances the ratchet. Only your device can read it.

Hide who. Hide when. Hide how.<br>Encryption hides the message. PrivaMesh also hides the metadata - the who, when and how that a server would otherwise see.

One-time addresses<br>Every message is delivered to a fresh one-time address, so an observer cannot reconstruct who talks to whom. The social graph stays hidden.<br>Learn more<br>Cover traffic<br>Decoy messages blend with real ones so an observer cannot tell when you actually send. Timing analysis gets nothing to work with.<br>Learn more<br>Fixed-size padding<br>Every message is padded to a fixed size before it is sealed, so its length leaks nothing about the content inside.<br>Learn more

The cryptography<br>End-to-end encryption, done properly<br>PrivaMesh uses the same battle-tested primitives that secure the best encrypted messengers, adapted for a serverless world. Every message gets a fresh key, so a compromised key can’t unlock your past or future conversations.<br>Read the plain-English encryption explainer →

X3DHCurve25519 handshake establishes a shared secret without a trusted key server.

Double RatchetHKDF + HMAC-SHA256 rotate keys every message for forward secrecy and post-compromise security.

AES-256-GCMAuthenticated encryption seals each payload, padded to a fixed size to hide length.

See it on your iPhone<br>A private messaging app that looks and feels like a premium chat app - with none of the surveillance underneath.

Privacy by default<br>End-to-end encrypted chat<br>Your chats<br>No servers, seriously<br>On-device security<br>A private social graph<br>Privacy by default<br>End-to-end encrypted chat<br>Your chats<br>No servers, seriously<br>On-device security<br>A private social graph

PrivaMesh vs the messengers you know<br>Signal is excellent. Telegram is popular. Neither is serverless. Here is the short version.

FeaturePrivaMeshSignalTelegramNo serversYesNoNoNo phone numberYesNoNoMetadata protectionYesPartialNoEnd-to-end encryptedYesYesPartialOpen sourceYesYesPartial<br>PrivaMesh vs Signal →PrivaMesh vs Telegram →PrivaMesh vs Session →Best private messaging apps 2026 →

Frequently asked questions

Is PrivaMesh really serverless?Yes. There is no PrivaMesh account server, relay, or message database. Encrypted messages travel over a public, decentralized transport, so there is nothing central to breach, subpoena, log, or shut down.<br>How is PrivaMesh encrypted?PrivaMesh uses an X3DH handshake over Curve25519 to establish keys, then a Double Ratchet (HKDF and HMAC-SHA256) that gives every message a new key. Payloads are sealed with AES-256-GCM and padded to a fixed size. You get forward secrecy and post-compromise security by default.<br>Can I use PrivaMesh without a phone number or email?Yes. There is no phone number and no email. Your account is an account phrase that maps to encryption keys stored in the iOS Keychain - device-only and protected by Face ID or Touch ID.<br>What metadata does PrivaMesh collect?None on any server, because there is no server. Delivery uses one-time addresses to hide the social graph, cover traffic hides when you send, and fixed-size padding hides message length.<br>What happens if I lose my phone?Restore your account phrase on a new device to recover your identity. By design your chat history is not recovered - forward secrecy means old message keys are...

privamesh message encrypted phone server device

Related Articles