Built by one person, then several.
No venture capital.
Nocx exists because we wanted a real-time community product where the server is structurally incapable of reading messages. We couldn't find one. So we built it. (The one carve-out we ship — Nocx-hosted bots — is opt-in, disclosed before it exists, and labeled to every member.)
The premise.
Privacy products that scale tend to drift. They start E2EE, take investor money, add an unencrypted "cloud chat" fallback "for convenience," ship server-side ML for "moderation," and end up indistinguishable from what they replaced.
We don't have the option to drift. There is no investor whose return depends on extracting value from your messages. There is no growth target whose pursuit makes a privacy exposure look reasonable. The product survives on subscriptions, not on selling access to you.
That's not a marketing claim. It's a structural feature of how Nocx is funded — and the reason every guarantee on the product page is something we can keep without changing our mind under pressure.
Who built this.
Independent developer working out of the European Union. Background in distributed systems and applied cryptography. Started Nocx after years of community-moderation work ended when a platform-policy change on the host service wiped the community without warning. The realization: there was no privacy-respecting alternative with feature parity. Building one was a smaller project than waiting for one.
A real bio with name and photo is going up when the EU company registration completes. Founder identity is not a secret — it's the timing that's deliberate. (Decision still open: pseudonym at launch + real name post-EOOD, OR real name from day one.)
What we'll never do.
These are commitments, not aspirations. Each of them is enforceable by what's in the codebase, not by what we promise.
No unencrypted "cloud chat" fallback.
There is no opt-out for end-to-end encryption. There is no "regular mode" vs "secret mode." Every conversation type — every server channel, group, DM — is E2EE on every platform. Adding an unencrypted path would require ripping out the protocol; we won't.
No tracking. Ever.
No third-party analytics, no behavioral tracking, no usage-profile SDKs, no error-reporting with user identifiers, no first-party server-side analytics that profile users. The optional P2P reliability counters in our privacy policy are aggregate-only, opt-in, and stripped of any per-user identifier before storage.
We publish the protocol.
The wire protocol, the vault-key model, the schema — all documented in the repository, with the public mirror linked here the moment it's live. Verify, break, propose changes. Security through obscurity is not a model we'll defend.
We will not be acquired by an ad business.
Any exit that requires a privacy exposure is not an exit we'll take. The product is funded by subscriptions; that lets us turn down offers that depend on monetizing you differently.
Common misconceptions, pre-empted.
Not federated.
The Nocx server is a single operator (us). Communities are hosted by us; we just can't read what happens in them — unless a community's owner adds a Nocx-hosted bot, which is labeled to every member and limited to the channels that bot is in. We're not a federation protocol.
Not a non-profit.
We're a for-profit company. Profit funds the people who keep the lights on. Profit is not extracted from your data; it comes from the subscription tier you choose to pay for.
Not a fork of an existing messenger.
We use the X3DH + Double Ratchet protocol family for DMs — an openly-specified algorithm — but the rest of the stack (channels, groups, vault keys, P2P modes, the codebase) is original work.
Not "decentralized."
The server is centralized; the P2P modes are decentralized for specific conversation types (Secret DMs, Secret Groups). We don't claim "decentralized" as a blanket label because most of the product isn't.
Jurisdiction.
EU-based; formal entity registration in Bulgaria is pending and will be reflected in the imprint once complete. Operating today under personal capacity; transitioning to the EOOD at incorporation. EU data-protection law (GDPR) applies to all users worldwide.
Questions?
For anything not covered here, reach out.