Room to be yourself.

We speak differently when we know someone is listening. Private spaces let us work things out, change our minds, and connect without performing for an audience.

That space should exist online, too. The everyday messages we send deserve the same care as a conversation behind a closed door.

Privacy, built into the conversation.

White Noise uses end-to-end encryption through the Marmot Protocol. Messages are encrypted for the people in the conversation, rather than made readable to the relays that carry them.

You don’t need a phone number or email to create an identity. And because the software is open source, its approach is there for people to inspect and improve.

A choice worth keeping.

We want a world where private communication is ordinary. Where it’s easy to reach people without giving up control of every conversation along the way.

White Noise is one contribution to that work. It’s still growing, and there’s room for you to help shape it.

Holding Ourselves to It

An argument like this one is only worth as much as the practice behind it. White Noise has no accounts and no servers holding your conversations. Your keys are generated and stay on your device, every message is end-to-end encrypted before it leaves, and group messages are published under ephemeral keypairs so that even the relays carrying them cannot tell who sent what. We cannot read your messages, and we cannot see who you talk to.

We do want to know whether the app actually works—which features people use, and where things break. So we ask. Sharing usage and telemetry is off until you turn it on, and declining costs you nothing. Product analytics uses predefined events and bucketed values. Telemetry includes aggregate performance measurements, a resettable installation identifier, app and device information, and relay addresses. Neither stream includes message content, public keys, contacts, or account and group identifiers. We use our own servers for these measurements, and there are no advertising identifiers or trackers in the app. Group diagnostic logs have a separate sharing control; on iOS and Android, enabling sharing automatically uploads eligible logs to IPF. These more detailed logs include group and message identifiers, but never message content or key material.

Asking for permission is easy to claim and harder to document, so we wrote down exactly what leaves your device, what our servers can and cannot infer from it, and how long any of it is kept.