Real-time communities.
End-to-end encrypted.
Communities, groups, and direct messages — built so the server can't read a single message. The one exception is one you choose and see: Nocx-hosted bots, always labeled. Five conversation types, one app, every major platform.
Download Nocx Free. Open client. Linux, Windows, macOS, Android.Communities deserve real privacy.
Most community chat platforms can read every message on their servers. Most encrypted-DM apps don't do communities. Nocx does both — real-time servers with channels and roles, end-to-end encrypted under per-channel vault keys, plus the X3DH + Double Ratchet protocol family for one-on-one chat.
The server stores opaque ciphertext only. There is no master key, no decryption oracle, no quiet API for "lawful access." Even the server owner of a community holds the same kind of key as every other member.
Pick the right tool for the conversation.
Different conversations have different threat models. Nocx ships five distinct types so you don't have to settle.
Communities at scale
Community-style servers with text, voice, announcement, forum, and file-share channels, organized under collapsible categories. Roles, permissions, moderation tools. Per-channel vault keys; messages encrypt under a key the server can never read.
Private group chats
Closed group conversations with N members. Per-group vault keys rotate when membership changes — leaving members can't read future messages, joining members get explicit grants for past history (or not — your call).
One-on-one
Encrypted with the X3DH + Double Ratchet protocol family. Server stores ciphertext so your messages follow you across devices. Lazy-loaded — a freshly-linked phone doesn't pull years of history at once.
Per-device, no server history
Direct messages with no permanent server storage. In Hybrid mode they ride the 7-day ephemeral queue — server-blind transport, recipient-addressed ciphertext, indistinguishable from a regular-DM blob at the row level. In P2P mode they skip the server entirely. Per-device, so they don't sync to your other devices either. Maximum compartmentalization.
Off-the-record group chats
Group chats with no permanent server storage. Hybrid mode delivers each message through the 7-day ephemeral queue (one server-blind blob per recipient, server can't tell a Secret blob from a regular DM blob). P2P mode runs over libp2p gossipsub instead — server doesn't see the traffic at all. Member management via signed operation log; calls stay peer-hosted — the call initiator runs a temporary SFU sidecar (desktop) or participants mesh directly (mobile), up to 5 participants, never the central Nocx SFU.
Calls, files, and more
1:1 voice and video over WebRTC. Large group calls via SFU. Resumable file transfers with chunk-level encryption. Optional R2-backed file relay for offline recipients.
The server is structurally incapable of reading your messages.
No "we promise we won't look." No "we delete logs after 30 days." The server simply doesn't hold the keys. Ever.
What it stores
- Encrypted message ciphertext (no key to decrypt)
- Public keys + account metadata
- HPKE-sealed wrap blobs (one slot per active member)
- Push notification tokens (opaque wake signals by default; an opt-in setting can add caller/group names — never message content)
- Subscription tier (Stripe-verified)
- Encrypted account backup blob (Argon2id-sealed)
What it never sees
- Your messages — plaintext, ever
- Your private keys — they're generated and stay on-device
- Decrypted vault keys (only HPKE-sealed wraps)
- Your call audio or video — direct or relayed-but-encrypted
- Your file contents or filenames
- Permanent history of your Secret DM and Secret Group conversations (transit-only ciphertext in the 7-day queue; nothing in the history tables)
Multi-device, without trusting the server.
Sign in on a new device, see your DMs and groups already populated. The server delivers ciphertext; only your devices hold the keys to read it.
Lazy history loading
~50 most-recent messages per conversation on cold-link. Older history pulls on scroll, search, or an explicit "Sync all" button. No bandwidth thunder when you add a phone.
Per-conversation keys
Every DM, group, and channel has its own vault key chain. Exposure of one conversation reveals nothing about any other.
SQLCipher on every device
Your local database is encrypted at rest with SQLCipher (Argon2id-derived key). The unlock secret stays in your device's secure keychain; an optional password or biometric check at launch is available in Settings. Plaintext never touches disk unencrypted.
No silent message loss
Monotonic per-conversation sequence numbers. If your client misses a message, it knows and backfills automatically — no "did the message even send?" anxiety.
Every major platform.
Single Flutter codebase, native performance, with a Rust core for cryptographic primitives.
| Platform | Status | Hybrid (default) | P2P | Secret Groups |
|---|---|---|---|---|
| Linux | Available | ✓ | ✓ | ✓ |
| Windows | Available | ✓ | ✓ | ✓ |
| macOS (Apple Silicon) | Available | ✓ | ✓ | ✓ |
| Android | Available | ✓ | ✓ (Background opt-in) | ✓ |
| iOS | Coming soon | ✓ | Foreground only (by design) | ✓ |
A note on mobile P2P: iOS and Android restrict background processes — pure peer-to-peer networking normally runs only while the app is open. Android extends this via an opt-in foreground service (battery cost, you control the toggle). On iOS, P2P mode is foreground-only by design: we use the VoIP entitlement for what it's actually for (community voice channels), not as a hidden access path for background libp2p. Hybrid mode handles the background case transparently for every conversation type: the server relays ciphertext through a 7-day ephemeral queue when peers can't reach each other directly.
Hybrid by default. P2P when you want it.
Server
Server WebSocket only. The libp2p substrate is off; Secret DMs and Secret Groups are unavailable. For users who want the simplest configuration: one delivery path, server-mediated, full push notifications.
Hybrid (default)
Server WebSocket + libp2p in parallel. Regular DMs, groups, and channels keep permanent encrypted history server-side (your devices hold the keys). Secret DMs and Secret Groups use the 7-day ephemeral queue or direct libp2p — server-blind transport, no permanent row. Reliable delivery on every platform; the server never sees plaintext.
P2P
After sign-in, no server contact: no HTTP API calls, no WebSocket, no push registration. The server is still used for account authentication (login, registration, password recovery — first contact only) and, only if you explicitly opt in, a daily anonymous P2P-reliability counter. Everything else rides libp2p — gossipsub for groups, DHT for delivery. Server-backed conversations become read-only until you switch back. Local accounts (no server at all) live entirely in P2P mode and pair multi-device via direct QR-rendezvous over a community relay.
The modes don't all reach each other equally — and that's the point.
Mode choice is a privacy/reachability trade-off. P2P mode keeps your message traffic off the server entirely, but that means the server can't deliver a message to you on someone else's behalf. Here's the actual matrix:
| Sender ↓ / Receiver → | Server | Hybrid | P2P |
|---|---|---|---|
| Server | ✓ | ✓ | Queued until receiver switches modes |
| Hybrid | ✓ | ✓ | Queued; Secret DM works only if Hybrid initiated |
| P2P | No transport | Secret DM only, if Hybrid initiated first | ✓ peer-to-peer Secret DMs |
Why the asymmetry: P2P mode routes no message traffic through the server, no exceptions. The server is what makes a regular DM reachable by an offline user — without it, an offline P2P user can't be notified. Queued messages on the server side stay in the encrypted 7-day relay queue (and, for regular DMs, permanent encrypted history per your tier) and drain to the receiver when they next switch to Hybrid. Nothing is lost; some things are deferred.
What we can moderate, and what we can't.
End-to-end encryption is the feature. It also creates a real limit on what the operator (us) can do when something goes wrong.
Server-mediated chat (regular DMs, groups, channels)
We can't read your messages — they're end-to-end encrypted on the server. But we can act on user-id-level reports: ban accounts, remove users from servers we host, revoke push tokens, freeze subscriptions. If you report a server-side abuse, we can do something about the account. (In communities that opted into a Nocx-hosted bot, we can additionally act on reported content in that bot's readable channels — the one scope where we can see content, because the owner chose it.)
Secret DMs and P2P chats
We can't moderate these. By design. The server is structurally outside the conversation: ciphertext-only relay (7-day TTL) or no involvement at all. We can't ban a peer from the network because their identity exists only on their devices. If you receive harassment in a P2P or Secret DM chat, you can block the user locally, but we cannot remove them. For chat where we can act on reports, use regular DMs in Hybrid or Server mode.
Ready to try it?
Free. Open client. No account required to read this page.
Download Nocx