iPhone · Android · Mac — one identity, every screen · see everything it does →
Your identity is a cryptographic key derived from a 12-word recovery phrase only you hold. Sign-up asks for nothing, because we want to know nothing.
Every message, photo, voice note and call. Our servers only ever see ciphertext — and delete it the moment it's delivered. There is no premium tier for privacy.
We add an ML-KEM-768 post-quantum key exchange on top of the classical one, so traffic harvested today cannot be unlocked later. Verified against NIST's own test vectors on your device, every launch — and it switches itself off rather than pretend if that check ever fails.
Chats live encrypted on your devices, not in our cloud. Optional backups are sealed with your recovery phrase — we can't open them even if asked.
Spojiti runs on infrastructure we own and operate — multi-homed across Europe and India, with no big-cloud lock-in between you and your words.
Not a marketing diagram — the real shape of the system, labelled with what our server can and cannot do.
Sealed envelopes moving between random account IDs — and a coarse wake class (call vs message) so a sleeping phone can still ring. That trade is universal in VoIP push; we're just the ones who tell you.
Your name, your number, your contacts, your message content, your call audio or video. There is nothing to type them into — the app never asks.
Nothing. Every envelope is deleted the moment it's delivered. Your history lives encrypted on your devices — which is why only your 12 words can bring it back.
No account, no email, no name — describe the problem, optionally attach the app's content-free diagnostics, and you get a ticket code. That code is the only key that exists; there is no author field in our database to fill.
Every ticket and every idea lives on a public board — our replies wear the team badge, and statuses move from open to shipped where everyone can see them. Nothing disappears into a private inbox.
The most-loved ideas on the public roadmap get built. Try finding another messenger whose support desk knows nothing about you.
Spojiti for Mac is here — a real native app, not a web wrapper. Link it from your phone with one QR scan; it becomes a full device of the same identity, end-to-end encrypted like everything else.
A proper two-pane layout — chats on the left, conversation on the right — with keyboard-first ergonomics: Enter sends, Esc closes, and the window remembers its place.
Audio and video calls ring straight on the desktop — answer where you're working. Mid-call switch to video, same end-to-end encryption, same zero-knowledge relay.
Close the window and Spojiti lives on in the menu bar — messages keep arriving as native notifications. Windows and Linux builds are on the way from the same codebase.
No forms, no OTPs, no contact-list upload. Here is the entire onboarding:
One tap. Your phone generates a cryptographic identity and shows you 12 recovery words. Pick any nickname — it's a label, not an account.
Add someone by scanning their code face-to-face, or sharing your Account ID. Nobody can look you up, scrape you, or cold-message you.
Messages, calls, payments, stickers — all end-to-end encrypted from the first second. Nothing to configure to be safe.
Text, photos, videos, voice notes, files, location — plus GIFs and brand sticker packs that never touch a third-party server. Reactions, replies, edits, delete-for-everyone, disappearing messages, view-once photos, screenshot protection. Everything end-to-end encrypted, no exceptions.
Crystal audio and video with the same end-to-end protection — engineered to connect even on hostile hotel Wi-Fi and strict corporate networks, and to ring properly on a locked phone.
Request money right in the chat; they pay in their own UPI app. Spojiti holds no financial data, sees no transactions, takes no cut. More regions as we grow.
Optional warnings for abusive content, checked entirely on your phone. Nothing is scanned on our servers — structurally, nothing can be. Protection and privacy, finally on the same side. How that works →
Most messengers keep a tidy list of every group you belong to, who is in it, and who runs it. Ours cannot. A Spojiti group message is sealed separately for each member and travels as ordinary one-to-one traffic — our relay holds no record that a group exists — no roster, no member list, nothing to hand over.
Every add, removal, rename and promotion is cryptographically signed by the admin who made it, so nobody can forge their way into a room — or quietly push someone out of one. Your device checks the signature before it believes anything.
The moment someone leaves or is removed, every remaining device stops accepting their messages. No lingering read access, no ghost in the room — enforced by the members, not by a server being trusted to behave.
Photos, videos, voice notes, files, locations, reactions, edits, delete-for-everyone and disappearing timers all work in groups exactly as they do in a private chat — sealed the same way, for each member.
Encrypting a call is normal. We go further: the signalling that sets a call up rides inside your encrypted conversation, as sealed envelopes the relay cannot read — no names, no numbers, no audio, ever. One honest caveat, stated because most apps won't: an envelope carries a coarse wake class (call vs message) so a switched-off phone can still ring, which reveals that call signalling is in flight — and nothing more. Every VoIP-push app makes this trade. Group calls connect every participant straight to every other — no server sits in the middle holding the roster.
Voice and video, end-to-end encrypted, with a mid-call switch from audio to video whenever the conversation needs a face.
Anyone in a group can start a call and the others hop in. Comfortable up to 8 on audio and 4 on video — the honest limit of doing it without a server in the middle, and we would rather state it than fake it.
Phone, tablet or the native Mac app. The same identity, the same encryption, the same silence from our side of the wire.
Every messenger claims privacy, so claims are worthless. Here are the three that actually separate us — and one where the projects we respect are ahead of us today.
WhatsApp, Telegram and Signal all require one. A phone number is a permanent, government-linked name for you. We never ask, so there is nothing to link.
If your device is stolen tomorrow, your past conversations stay sealed — our keys move forward with every message. Session, the other no-phone-number messenger, still does not have this.
Several messengers claim it. Ours is checked against NIST's published vectors on your own device at every launch, and refuses to run if it fails. Verified, not asserted.
Buy a plan and the payment cannot be linked to the account it unlocked. Not by your bank, not by us. Nobody else in messaging offers this.
Threema, Session and SimpleX are all fully open source and we are not — yet, and we have had no independent audit. One is budgeted for V1.0 and not yet commissioned. Until both land, weigh our claims accordingly.
The core — and every safety feature — is free forever. Power features are a few rupees a year, because servers cost money and your data is not for sale. And every new account starts with 7 days of Premium, free — no card, nothing to cancel.
See plans →