The app

YGOOW for Android puts the whole design in your pocket: a local identity, offline keys, per-message encryption, and a connection that can ride Tor.

Every day · 6 screens →

Home screen: Tor on, tiles for direct chats, groups, contacts and profiles
HomeTor is on by default. One-to-one chats and groups get separate tiles, because they are different things.
List of direct chats, each labelled with its protection mode
Direct chatsEvery conversation with a contact, labelled with its protection. Orange means a second secret guards the content.
A one-to-one conversation with .beat timestamps
A conversationTimestamps in .beat time, not your local clock — a local time would give away your time zone.
List of groups with member counts and how many hold the room key
GroupsEach room shows how many members hold its current key — so you can see when everyone is caught up.
Group members, each with a key icon for their sender key
Who is in the roomEvery member's key at a glance. Remove someone and the room moves to a key they never receive, so they can't read what comes next.
Dead Drop: writing a one-time note with an expiry
Dead DropA one-time note behind a link or QR, for someone who isn't a contact. Text only; gone after one read or when it expires.

Who you're talking to · 5 screens →

Contacts grid with trust shields
ContactsA white shield: met in person, or safety number compared. Amber: added remotely and not verified yet.
A contact with channel tiles and the safety number
A contactTheir channels as tiles, the profile you write to them from, and the safety number.
Safety number in eight groups of five digits
Safety numberComputed from both people's identity and encryption keys. Compare it on another channel; one digit off means stop.
Three identities behind one app-lock
More than one youSeparate keys and contact codes behind one app-lock. You choose which one each contact ever sees.
App-lock with password, file, link and quorum methods
App-lockA password, a file, a link, or a K-of-N quorum — plus an optional YubiKey as a second factor.

Protection you choose · 4 screens →

Choosing a conversation's protection: Standard, Matrioshka, saved modes, or none
Choose the protectionEvery new conversation starts with a deliberate choice. There is no insecure default to slide into.
Conditions: per-message key, disappearing messages, open-after, burn after reading, validity
ConditionsPer-message keys, disappearing messages, open-after, burn-after-reading. Where a rule is app policy rather than cryptography, the app says so.
Dialog explaining background delivery without Google
Background deliveryNo Google, no push broker — and before you switch it on, the app spells out what it costs and when it stops.
Crypto self-test with all checks passing
Self-testShows which crypto implementation actually runs on your phone — including the check that a swapped key changes the safety number.

The app explains itself · 4 of 14 tips →

Tip: No default. You choose.
No defaultFourteen short cards, blunt on purpose — each at the point where you make the choice it's about.
Tip: A matching number means both keys match
Both keysWhat a matching safety number proves — and why a known identity with a new key is refused.
Tip: Not a contact? Leave a dead drop
Dead DropIncluding its weak spot: in a browser, the page code comes from our server.
Tip: The relay forgets after a day
24 hoursThe price of a server that keeps nothing, said before it costs you a message.

Status

The app is in active development and headed for Google Play. The screens above come from the current development build (September 2026), filled with demo contacts. What is finished and what is still ahead is on the progress page; follow the blog for news.

What it does

Who it’s for

YGOOW is a deliberate tool, not a default one. It fits:

It is not built for a family group chat, a lifetime message archive, or a contact who will lose their key — there is no recovery and no override. If you need something a non-technical relative can use without instructions, YGOOW is the wrong tool, and we would rather say so before you install it than after.

Getting started

  1. Open the app. An identity is created locally on first launch — no sign-up.
  2. Add a contact. Scan each other’s QR in person — a key swapped face-to-face can’t be tampered with — or add someone remotely and confirm their safety number over another channel.
  3. Just message them. The conversation key comes from your two identities; there is nothing to agree and no room code to share. (For a one-off with someone who isn’t a contact, carry a shared key or a random key in the invite QR instead.)
  4. Add conditions if you want. A separate content secret, a lifetime, an open-after date, or burn-after-read — per conversation or per message. Anyone without what it takes sees only a locked block.

Connection modes

Mode Server sees your IP? Use when
Tor No You want to hide where you are
Tor bridges No Tor itself is blocked on your network
Clearnet Yes Hiding your location isn’t the point

Tor is on by default — you ride the onion service unless you deliberately switch to bridges or clearnet. The app makes the choice explicit and remembers it.

Your keys, your responsibility

There is no account recovery and no administrative override — by design, we can’t read your messages or restore lost keys even if compelled. Back up your keys: the app exports a single sealed file (Argon2id, 256 MiB per guess; padded; optionally without history), which opens with the secret alone. See the trust model, the FAQ, and the whitepaper.