Frozen Chat
Encrypted messenger

An encrypted messenger, all the way through.

Every message, file, voice note, group and call is end-to-end encrypted by default, with post-quantum keys. There is no unencrypted mode to fall back to.

“Encrypted” is on almost every messenger's website, and it can mean very different things. Sometimes it only means the connection to the company's server is protected, while the company can still read everything it stores. Sometimes end-to-end encryption exists but has to be switched on per chat, or doesn't cover groups. Frozen Chat is an end-to-end encrypted messenger in the strict sense: content is locked on your phone before it leaves, and only the people in the conversation hold the keys. If you are new to the idea, start with what is end-to-end encryption?

What is encrypted

WhatHow it is protected
1:1 messagesSignal protocol (libsignal) with PQXDH and the Double Ratchet
GroupsMLS (RFC 9420), hybrid X25519 + ML-KEM-768 cipher suite
Photos, videos, files, voice messagesFresh key per file, padded size, random name; key sent only inside the encrypted message
1:1 voice and video callsDTLS-SRTP, fingerprints checked over the encrypted chat
Group callsSFrame, with keys from the encrypted group
Group names, photos, rolesEncrypted inside the group; the server sees an opaque id
Who sent a messageSealed sender: the server isn't told
BackupsEncrypted on your device before upload

The Signal protocol, with post-quantum keys

One-to-one chats use libsignal, the library behind the Signal app, without changes. Each conversation begins with PQXDH, which combines classic elliptic-curve key agreement with ML-KEM (Kyber), a post-quantum algorithm standardised by NIST. That protects against “harvest now, decrypt later”, where someone records encrypted traffic today and waits for a quantum computer. Our explainer post-quantum encryption in messaging covers this in plain language.

After the handshake, the Double Ratchet gives every message its own key. One stolen key doesn't unlock earlier messages (forward secrecy), and the conversation heals itself after a compromise (post-compromise security).

Groups on MLS, the IETF standard

Groups use Messaging Layer Security, published by the IETF as RFC 9420, with a hybrid post-quantum cipher suite. The server orders encrypted group messages but is never a member and never holds group keys. It also can't slip a device into a group: every app checks each member against that person's signed device list. When someone leaves or is removed, the group moves to new keys.

An end-to-end encrypted conversation in Frozen Chat with a photo and a voice message
Messages, photos and voice notes: encrypted on your phone.
An encrypted Frozen Chat voice call
Calls: keys checked inside the encrypted chat.
Frozen Chat chat list with groups and one-to-one chats
Groups: MLS with post-quantum keys.

Encryption is only half of privacy

Even with perfect encryption, a server can learn a lot from metadata: who talks to whom, when, and from where. Frozen Chat is designed to keep that small.

  • No phone number, no e-mail. Accounts are usernames, looked up by keyed hash. See messenger without a phone number.
  • Sealed sender. The server delivers messages without being told who sent them.
  • No logs. No access logs and no IP addresses are kept. Stored timestamps are rounded.
  • Empty notifications. Pushes through Google or Apple carry no message, no sender and no chat, just “wake up”.
  • No trackers. No analytics in the app or on this website.

Keys that stay with you

Your private keys are generated on your phone and stored in an encrypted database protected by the phone's secure hardware where available. When you create an account you get a 24-word Recovery Key, shown once, on your device only. You can verify each contact with a safety number and the app warns you if a contact's keys change.

Honest about the limits

No messenger is magic. The first contact with someone is trust-on-first-use until key transparency is added, so compare safety numbers with people who matter. The web app is lower assurance than the phone app, because a browser runs whatever code the server sends. A phone that is unlocked and compromised can read what that phone can read. All of this is documented on the security page.

More than encrypted text

Frozen Chat is a full messenger: voice and video calls, voice messages, one-time photos and videos, stickers bundled with the app, app lock, multi-device with a web app, and self-destructing private notes you can send to anyone as a link. Make it look the way you like with themes. Wondering how it stacks up? Compare it with Signal, WhatsApp or Telegram.

Questions

What does end-to-end encrypted mean in Frozen Chat?

Messages, files and calls are encrypted on your device and can only be decrypted on the devices of the people in the chat. Our server only relays sealed envelopes it can't open.

Is encryption on by default?

Yes. There is no unencrypted mode and no setting to switch on. Every chat, group and call is end-to-end encrypted from the first message.

Which encryption does Frozen Chat use?

libsignal (the Signal protocol) with PQXDH post-quantum key agreement for one-to-one chats, MLS (RFC 9420) with a hybrid X25519 + ML-KEM-768 suite for groups, DTLS-SRTP for 1:1 calls and SFrame for group calls.

Can Frozen Chat read my messages?

No. The keys are created and kept on your devices. The server delivers encrypted envelopes and deletes them when delivered, or after 30 days at most.

Encrypted from the first message.

No phone number, no e-mail. Pick a username, save your recovery words, and every chat is end-to-end encrypted from the first message.

Keep reading