shroudprivate comms
systems sealed
end-to-end encrypted · invite only

Talk like no one’s listening.

Shroud seals every message on your device before it leaves — texts, photos, videos, group chats. The server only ever holds ciphertext. Not us. Not the host. Nobody in the middle.

sealed on device

libsodium crypto — X25519 + Ed25519, fresh keys per message. Your private keys never leave this browser.

your circle

Join with someone's invite link and you're instantly in each other's contacts. Temp-mail domains are blocked outright.

nothing to steal

Admins see counts, never contents. No passwords live in our code — every check happens server-side.

shroud
hey — is this thing actually private?
sealed on my phone before it sent ✓✓
so even the server can't read it?
only ciphertext up there. math, not promises ✓✓
message…
how it works

Inside in three steps.

01
Get an invite link

Someone inside sends you their personal invite link. One link, one human — that's the whole trust model.

02
Create your account

Pick a username, add a real email. No password — we'll send you a one-time code. Your encryption keys are generated in this browser and never leave it.

03
Start talking

Whoever's link you used is already in your contacts. Send your first sealed message — nobody in the middle can read it.

features

Everything a messenger should do.
Nothing it shouldn't.

🔒
Sealed on your device

Every message is encrypted in your browser with libsodium (X25519 + Ed25519) before it leaves. Fresh ephemeral keys per message. The server only ever holds ciphertext.

📞
Voice + video calls

Crystal-clear 1:1 calls right from any chat. Peer-to-peer encrypted media, signed call setup so the server can't fake a call from someone, speakerphone-ready on Android.

🎟️
Invite-only circle

No public signup. You join through someone's invite link and land directly in each other's contacts. Temp-mail domains are blocked at the gate.

👥
1:1 + family groups

Private chats and group conversations with pairwise encryption — each member gets their own sealed copy. No shared group key to leak.

🎙️
Voice messages

Hold to record, release to send. Voice notes are encrypted exactly like text — the server hears nothing.

📎
Encrypted attachments

Photos and videos are sealed with a one-time file key, then that key is sealed per recipient. Filenames never touch the server in plaintext.

⏱️
Disappearing messages

Set a per-chat timer — 24 hours or 7 days — and messages and their attachments are hard-deleted from the server when it lapses. No soft-delete theater.

🔑
Safety numbers

Compare a 60-digit fingerprint of both parties' public keys out-of-band to defeat man-in-the-middle. The app alerts you when a contact's keys change.

💬
Replies, reactions, polls

Quote replies, emoji reactions, read receipts, typing indicators, pinned messages, and polls with server tallies. (Heads up: poll questions and votes are stored in plaintext, not encrypted.)

🛡️
App lock + privacy

PIN-lock the app, control who sees your avatar and last-seen, mute and archive chats. Your metadata, your rules.

security

Paranoid where it counts.

what we can see

Ciphertext. Timestamps. Who messaged whom. That's the full list — everything needed to deliver, nothing that reveals content.

what we can't see

Message text. Photos. Voice notes. Poll questions. File names. Your private keys — they never leave your browser, not even once.

what we enforce

Server-side invite validation. No temp-mail. No client-side admin checks — every privileged action is verified against the database. Rate limits on every endpoint.

faq

Straight answers.

Can the admin read my messages?

No — and that's math, not policy. Message bodies are sealed with your recipient's public key before they leave your device. The admin cannot read message text, call audio/video, or file contents. But be honest about what the server does see in plaintext: group names, poll questions and votes, your contact graph (who invited whom), display names, usernames, bios, avatars, read receipts, reactions, message timestamps and who talked to whom, plus login IPs, cities, and devices. There is no backdoor because there is no key to backdoor with — for message content. The rest is metadata, and it isn't encrypted.

What happens if I lose my device?

Your private keys live in your browser's local storage. If the device is gone and you didn't link a second device, old messages can't be recovered — that's the price of real E2EE. Log in fresh and you'll get new keys; your contacts will see a safety-number change alert.

How do I use two devices?

Open Settings → Linked devices on your main device, copy the device code, and paste it on the second device. It imports your identity so both devices read the same messages.

Why invite-only?

Open signup is how spam, scraping, and abuse get in. Invite links keep the circle human-sized and make every account traceable to someone who vouched for them.

Is my metadata private?

Honest answer: the server sees who messaged whom and when — that's unavoidable for delivery. It never sees message text, call audio/video, or file contents. But poll questions and votes, group names, display names, avatars, read receipts, reactions, and the contact graph are all plaintext server-side. Disappearing messages hard-delete even the ciphertext (and attachments) on a timer.

What crypto do you use?

libsodium — X25519 for encryption, Ed25519 for signatures, fresh ephemeral keys per message, secretbox for file payloads. Trust-on-first-use with out-of-band safety-number verification, same model as Signal.

How do voice and video calls work?

Calls are peer-to-peer over WebRTC — audio and video are encrypted in transit with DTLS-SRTP and never touch our server as media. The call setup is signed with your identity key, so a malicious server can't inject a fake call. Both people need to be online; 1:1 only.

get the app

Install it like a native app.
Free, no app store needed.

android

Open this page in Chrome → tap the ⋮ menu → Install app (or Add to Home screen). That's it — icon, splash screen, fullscreen.

iphone

Open this page in Safari → tap Share → Add to Home Screen. Shroud lands on your home screen like any app.

desktop

Chrome / Edge: click the install icon in the address bar. Shroud runs in its own window, outside the browser tabs.

Your circle is waiting.

Grab an invite link from someone inside and you're two minutes from your first sealed message.