The messenger · pre-release

No number. No account. No record.

You do not sign up. Your identity is made on your phone and never sent anywhere. Every message is sealed with post-quantum cryptography and carried over Tor, and the server it passes through has no idea who you are, who you are writing to, or what you said.

No phone number Post-quantum encryption Over Tor Android today · iOS in build

01 — How it works

Built to know as little about you as possible.

01

Nothing at the door

No phone number, no email, no name, no username. Your identity is a cryptographic key generated on your device from a recovery phrase. It is never uploaded. There is no account of yours anywhere for a court to point at.

02

You add people by one-time link

To start talking to somebody, one of you creates a single-use invitation link and gets it to the other however you like. It works exactly once and then it is spent. That is the whole mechanism.

03

Encryption that survives quantum computers

Messages are sealed with libsignal — Signal's own cryptography, used unmodified — including its post-quantum ratchet, which keeps mixing fresh quantum-resistant key material into every single message. Traffic recorded today cannot be opened later by a machine that does not exist yet.

04

The relay moves what it cannot open

Your message crosses our server as one sealed block of a fixed size, under a random code, arriving from inside the Tor network with no sender field attached. There is no account on it, nothing readable, and nothing written to its disk.

02 — In plain words

The clever part isn't the code. It's what they can't see.

Six things Avano does quietly, described without jargon and without overstating any of them.

We cannot see who you talk to

Reading your messages is already off the table for any decent messenger. The harder secret is who, and when. Your messages cross the relay as sealed, identical blocks under random codes, over Tor, with no sender field in the protocol at all. There is no contacts table and no social graph on our servers, because your contacts never leave your phone.

Locked against computers that don't exist yet

Every message carries post-quantum protection — a quantum-resistant key exchange at the start of a conversation and fresh quantum-resistant material mixed in continuously afterwards, so one compromised moment does not open the rest.

Even your files don't show their shape

Send a photo or a document in a one-to-one chat and the relay carrying it cannot tell how big it is, what kind of file it is, or who it is for. It is split into identical padded pieces under unrelated random names. Photos have their location and camera tags stripped before they leave.

A seized phone reads as noise

Everything stored is encrypted item by item, and you can lock the whole app behind a passphrase that is stretched with a deliberately slow, memory-hungry function and bound to a key held in your phone's hardware. Someone who extracts the hardware key still has nothing without the passphrase. What it still leaks →

It hides how much you say

Your phone sends at a steady rate whether or not you are writing, so somebody watching your internet connection cannot read your volume off it. This is on by default, free, for everyone — and it costs roughly 750 MB a month, which is why there is a switch. It hides volume; it does not hide that you are online.

Messages can disappear

You can set a timer after which messages are swept from both ends. It is off unless you turn it on, and it is a single setting that applies to every conversation — there is no per-chat timer, so setting one from inside a chat sets it everywhere. There is no export and no backup, so treat a timer as permanent.

03 — What it actually does today

The honest feature list.

Described against a pre-release Android build. Anything not on this list is either on the roadmap or on the list of things we deliberately refuse.

Text messages
One-to-one and in small groups. Sealed, fixed-size, no sender field.
Photos & files
In one-to-one chats. Chosen from your library — there is no in-app camera. Split into identical padded pieces; location and camera tags stripped first.
Small private groups
Text only for now. Each message is sealed separately for every member, and the group's identifier never appears on the wire.
Disappearing timers
One setting, applying to every conversation. Off by default. There is no per-chat timer yet.
Reactions & read receipts
Receipts ride an existing message rather than costing a separate one, so they add nothing an observer can count. You can turn them off.
Passphrase lock & auto-lock
The app locks when it leaves the foreground and after a short idle. While locked it receives nothing — that is the point.
Link cleaning
Tracking parameters stripped and lookalike addresses flagged before you tap. No previews are ever fetched.
Erase everything
Destroys the identity, every message and every contact on the device, and the platform key they are bound to. Nothing can restore them.
Android now, iOS in build
A pre-release Android build runs the full flow over Tor today. The iOS app is being built and we do not describe it as working until it is.
Three things people expect and will not find

No notifications. Nothing arrives while Avano is closed — a locked app cannot receive, and that is the defence, not a bug. No calls, and not later either. No backup or export, so a lost phone is lost messages. Each of these has a real argument behind it: what Avano deliberately does not do →

04 — The difference

Where Avano goes further, and where it does not.

 AvanoSignalWhatsApp
End-to-end encryptedYesYesYes
Post-quantum encryptionYesYesNo
No phone number neededYesNoNo
No account exists at allYesNoNo
Server holds no contact listBy designReducedNo
IP hidden from the service, alwaysOver TorCalls onlyNo
Hides how much you sendOn by defaultNoNo
App locks itself and stops receivingYesNoNo
Voice and video callsNo — deliberatelyYesYes
NotificationsNoYesYes
Backup / restoreNoYesYes
Source publishedNot yetYesNo
Independent auditNoneMultipleSome
Reproducible buildsPartial, unverified externallyYesNo
In the app storesNot yetYesYes

Signal is an excellent and honest application, and we build on the cryptography its team wrote. Our advantage is metadata and the network layer; theirs is everything to do with shipping software to hundreds of millions of people, which is most of the bottom half of this table. Read the longer version of where we are behind before choosing on the basis of the top half.

05 — Questions

The honest FAQ.

Do I really need no phone number? +
None at all, and no email either. Your identity is a cryptographic key made on your device from a recovery phrase. You add contacts with a one-time invitation link. Nothing ties the app to your real name unless you tell somebody.
Can I add someone by scanning a QR code? +
No. It is a one-time link only. The app does not request camera permission and there is no code scanner in it — a screen elsewhere in the interface draws a decorative pattern that is not a real code and a camera pointed at it would read nothing. We mention it because the wrong version of this answer was on our own store listing until we caught it.
Is it open source? +
Not yet. The code is licensed AGPL-3.0-or-later, and the repository is currently private. Until it is public, "open source" is an intention rather than a fact and we will not print it as one — the app's own trust screen reads Open-source · PLANNED and this page agrees with it. When it is published, the link will be here.
Why don't I get notifications? +
Because Avano locks itself when it leaves the foreground, and a locked Avano cannot receive anything — it cannot even learn that mail is waiting. That is the defence that makes a seized phone worth so little. A notification would require either telling Apple or Google that a message arrived for your device, or keeping your keys unlocked in the background. We refused both. The full argument →
Why are there no calls? +
Three separate reasons, any one of which is enough: a locked phone cannot ring; onion routing is seconds slow where a call needs a fifth of a second; and a call is the one traffic pattern that identifies itself, since everything else Avano sends is one fixed-size block. The full argument →
What if someone takes my phone? +
Everything stored is encrypted item by item and can be locked behind a passphrase bound to your phone's hardware key. A forensic tool reads sealed blocks, not your conversations. It does still recover the names you gave your contacts, because a few housekeeping records are stored under keys built from those names — we are closing that and we are not going to pretend it is already closed. The detail →
Is my data backed up? +
No. There is no cloud copy and no export. If you lose the phone, the messages are gone — your recovery phrase restores your identity, not your history. That is a deliberate choice: any hosted backup is a second copy of everything, held by somebody who can be ordered to produce it.
Is it finished? +
No. Avano is pre-release. The Android build runs the real messaging flow over Tor today and is installed by hand rather than from a store. iOS is still being built. We have not had an independent security audit and the source is not published yet. Everything on this site is written to that state rather than to where we intend to be.
Will it cost anything? +
Private messaging stays free, with no ads and nothing sold. Cover traffic — the part that hides how much you send — is free and on by default for everyone, deliberately: a privacy feature you have to buy marks the people who bought it. A paid tier may later cover things that do not change your traffic shape, like large files or storage.
Be first

Leave one trace: your email.

The Android build runs today; iOS is in build. An email is the only thing we ask for and the only thing we keep.