No number. No account. No record.
You do not sign up. Your identity is made on your phone and never sent anywhere. Every message is sealed with post-quantum cryptography and carried over Tor, and the server it passes through has no idea who you are, who you are writing to, or what you said.
Built to know as little about you as possible.
Nothing at the door
No phone number, no email, no name, no username. Your identity is a cryptographic key generated on your device from a recovery phrase. It is never uploaded. There is no account of yours anywhere for a court to point at.
You add people by one-time link
To start talking to somebody, one of you creates a single-use invitation link and gets it to the other however you like. It works exactly once and then it is spent. That is the whole mechanism.
Encryption that survives quantum computers
Messages are sealed with libsignal — Signal's own cryptography, used unmodified — including its post-quantum ratchet, which keeps mixing fresh quantum-resistant key material into every single message. Traffic recorded today cannot be opened later by a machine that does not exist yet.
The relay moves what it cannot open
Your message crosses our server as one sealed block of a fixed size, under a random code, arriving from inside the Tor network with no sender field attached. There is no account on it, nothing readable, and nothing written to its disk.
The clever part isn't the code. It's what they can't see.
Six things Avano does quietly, described without jargon and without overstating any of them.
We cannot see who you talk to
Reading your messages is already off the table for any decent messenger. The harder secret is who, and when. Your messages cross the relay as sealed, identical blocks under random codes, over Tor, with no sender field in the protocol at all. There is no contacts table and no social graph on our servers, because your contacts never leave your phone.
Locked against computers that don't exist yet
Every message carries post-quantum protection — a quantum-resistant key exchange at the start of a conversation and fresh quantum-resistant material mixed in continuously afterwards, so one compromised moment does not open the rest.
Even your files don't show their shape
Send a photo or a document in a one-to-one chat and the relay carrying it cannot tell how big it is, what kind of file it is, or who it is for. It is split into identical padded pieces under unrelated random names. Photos have their location and camera tags stripped before they leave.
A seized phone reads as noise
Everything stored is encrypted item by item, and you can lock the whole app behind a passphrase that is stretched with a deliberately slow, memory-hungry function and bound to a key held in your phone's hardware. Someone who extracts the hardware key still has nothing without the passphrase. What it still leaks →
It hides how much you say
Your phone sends at a steady rate whether or not you are writing, so somebody watching your internet connection cannot read your volume off it. This is on by default, free, for everyone — and it costs roughly 750 MB a month, which is why there is a switch. It hides volume; it does not hide that you are online.
Messages can disappear
You can set a timer after which messages are swept from both ends. It is off unless you turn it on, and it is a single setting that applies to every conversation — there is no per-chat timer, so setting one from inside a chat sets it everywhere. There is no export and no backup, so treat a timer as permanent.
The honest feature list.
Described against a pre-release Android build. Anything not on this list is either on the roadmap or on the list of things we deliberately refuse.
No notifications. Nothing arrives while Avano is closed — a locked app cannot receive, and that is the defence, not a bug. No calls, and not later either. No backup or export, so a lost phone is lost messages. Each of these has a real argument behind it: what Avano deliberately does not do →
Where Avano goes further, and where it does not.
| Avano | Signal | ||
|---|---|---|---|
| End-to-end encrypted | Yes | Yes | Yes |
| Post-quantum encryption | Yes | Yes | No |
| No phone number needed | Yes | No | No |
| No account exists at all | Yes | No | No |
| Server holds no contact list | By design | Reduced | No |
| IP hidden from the service, always | Over Tor | Calls only | No |
| Hides how much you send | On by default | No | No |
| App locks itself and stops receiving | Yes | No | No |
| Voice and video calls | No — deliberately | Yes | Yes |
| Notifications | No | Yes | Yes |
| Backup / restore | No | Yes | Yes |
| Source published | Not yet | Yes | No |
| Independent audit | None | Multiple | Some |
| Reproducible builds | Partial, unverified externally | Yes | No |
| In the app stores | Not yet | Yes | Yes |
Signal is an excellent and honest application, and we build on the cryptography its team wrote. Our advantage is metadata and the network layer; theirs is everything to do with shipping software to hundreds of millions of people, which is most of the bottom half of this table. Read the longer version of where we are behind before choosing on the basis of the top half.
The honest FAQ.
Do I really need no phone number? +
Can I add someone by scanning a QR code? +
Is it open source? +
Why don't I get notifications? +
Why are there no calls? +
What if someone takes my phone? +
Is my data backed up? +
Is it finished? +
Will it cost anything? +
Leave one trace: your email.
The Android build runs today; iOS is in build. An email is the only thing we ask for and the only thing we keep.