// Encrypted messenger · Variant C — zero hint

Everything else
is redacted.

No phone number. No email. No accounts. Your key is any file, password or link — and it never leaves your device. The server only ever sees noise.

NO IP · NO LOCATION NO REGISTRATION MANY IDENTITIES OFFLINE KEY EXCHANGE AES-256-GCM POST-QUANTUM HYBRID SHAMIR QUORUM
// What makes it different

Cryptographic access control.
No server-side permissions.

Who reads what is decided entirely by who holds the key — never by an account, a role, or a list on our side. We couldn't hand over your conversations if we tried.

Your key is anything

A password, any file (PDF, photo, MP3), a URL — or a Shamir split across several files. It's hashed locally and never transmitted.

No accounts, ever

No phone number, no email, no username. Your identity is a keypair that lives only on your device — never on our servers — and you share it with a contact only when you choose, by scanning in person.

Many identities, one app

Keep separate personas under a single app-lock — one for work, one for everything else — and decide which one a contact ever sees. No second number, no second phone, nothing to correlate across them.

Per-message encryption

Every message can use a different key. The same room looks different to each person — some lines are text, others are just .

The server is deaf

It stores opaque blocks and timestamps — nothing else. No senders, no key hints, no "who talks to whom". Seized, it reveals noise.

Quorum decryption

Lock a message so it only opens when K of N people combine their keys. One infiltrator with one share is useless.

Offline key exchange

By default, keys are exchanged offline — in person, by file, or by QR scan — never negotiated over the network. That eliminates an entire class of man-in-the-middle attacks.

Messages on your terms

Lock a message to open only after a date, only for a set lifetime, or only when K-of-N people combine their keys — and let it burn after reading. The conditions ride inside the ciphertext; the relay never sees them.

Post-quantum, no server to ask

They record today and decrypt when the hardware catches up. So every contact channel mixes ML-KEM-768 in alongside X25519 — a hybrid that holds if either one does. Other designs park one-time keys on a prekey server; ours holds nothing. Instead your identity carries its own post-quantum key, handed over the same way as the rest of it — in person, by QR or NFC. Nothing deposited, nothing to seize.

A channel that heals

Every reply folds a brand-new key exchange into the conversation root. Steal the state on Tuesday and by Wednesday's round-trip you have lost it again — forward secrecy backwards in time, post-compromise security forwards. No signatures involved, so nothing you send can be used to prove you sent it.

Check the math yourself

Tap the flask and the app re-runs its cryptography on your own phone against known-answer test vectors: key derivation and the message cipher, the handshake and safety number, and a wrong key yielding a locked block with no error and no hint. Not a certificate from someone you've never met — a test you watch pass. We measure the same code's timing on the same class of phone, and publish what leaks next to what doesn't.

Group rooms, still zero-knowledge

Talk to many the way you talk to one: end-to-end, with no member list on our side. Each sender carries their own key, messages stay forward-secret, and removing someone re-keys the room so they're locked out — a deliberate step the app explains before you take it.

// How it works

Three steps. Zero trust in us.

01

Generate locally

Your identity and keys are created on-device and stored encrypted behind your app-lock — a password, a file, a quorum, biometrics, or a YubiKey (NFC). Nothing leaves without a deliberate decision.

02

Share a key offline

Agree on a key with the people who matter — a file you both have, a password, a QR scanned in person. Never through the server.

03

Everything else is redacted

Anyone without the key sees a locked block — or, in stealth rooms, nothing at all. No error, no hint, no oracle.

Choose how each conversation is protected — three levels, no default →

// Defense in depth

Layers, not promises.

Security that survives a bad day is layered — and honest about where each layer ends. Here's ours, and what each one does (and doesn't) do for you.

Tor, bridges, or clearnet — you choose

Reach the network over Tor v3 (the server never learns your IP or where you are), over Tor bridges where Tor itself is blocked, or over a standard connection when hiding your location isn't the point. The app states plainly what each mode reveals — the choice, and the trade-off, are always yours.

Trust you can verify

A key you swap face-to-face can't be tampered with — you watched it happen. Set one up remotely when you can't meet, and the app marks it as such, with a fingerprint to verify later. Trust is shown, never assumed.

You're never both online at once

Messages wait, encrypted, until you reconnect — even across a dropping Tor circuit. Neither of you has to be online at the same moment for a message to land.

Metadata shaped, not just hidden

Beyond Tor, every block is padded to a size bucket and the conversation address rotates per-conversation — and a high-risk mode adds cover traffic the relay can't tell from yours. Even the post-quantum key material rides in every message, not just the ones that rotate keys: we pay the bandwidth so the relay can't read the rhythm off the wire. And what it can still read from timing, we measured and published rather than rounded off.

A decoy for coercion

Set a second password that opens a fake, empty profile to show under pressure — your real one stays hidden in the same store, indistinguishable on disk. A panic lock disarms biometrics so a forced finger opens nothing.

Nothing to grab off the screen

Screenshots, screen recording, and the "recent apps" thumbnail are blocked — the chat can't be captured from outside the app, even on a seized phone.

ygoow — what we don't pretend.txt
Encryption protects what you write.
Tor hides where you are.
Quorum splits the power to unlock.

// But no messenger — none — survives a compromised device.
// A phone with spyware, or one taken while unlocked,
// reads your screen no matter the cryptography.

$ we tell you this — because the ones who don't are the ones you shouldn't trust

Read the full trust model — what we protect, and where it ends →

When they couldn't break the cipher: how EncroChat and Ricochet actually fell →

// Since 2004

Some philosophies don't age.

YGOOW began two decades ago with one idea: sharing data freely, anonymously, without surveillance. The world finally caught up.

ygoow — manifesto.txt
YGOOW 2004: peer-to-mail. No accounts. No registration.
YGOOW 2026: a messenger. No accounts. No registration.

// "The French faked CAs — ANSSI, 2013.
// The Americans forced backdoors — Apple, 2016.
// The Germans trojaned Skype itself — 2011, so sloppily the CCC laid it bare.
// Encrypt it yourself, and there's nothing to seize — only what you choose to share."

// And when the ciphers finally held, they went around them —
// the central servers (EncroChat, 2020), the standing onion service (Ricochet, 2024).
// so we removed those: no centre to seize, no service to trace — and we mark where it still ends.

// refs — FR: mozilla.org · theregister.com
// US: epic.org · bbc.com · order (archived)
// DE: ccc.de · report (archived)
// EncroChat: CJEU C-670/22 · bverfg.de · judgment (archived) · summary (archived)
// Ricochet: torproject.org · tagesschau.de · response (archived) · report (archived)

$ your key · your rules · everything else is redacted
// Straight talk

The same coaching the app gives you.

Ygoow speaks up at the moments that matter — cheeky, but honest. These are the in-app cards, verbatim. Swipe through.

No default. You choose.

Every other messenger picks your security for you. Ygoow makes you choose how each conversation is protected — or it won't let you chat at all.

Your key is anything — but anything isn't a key.

A password, a file, a link, a quorum of people. Just remember: a public file or a guessable link is not a secret. The app shows you the real strength of what you pick.

Met in person? Trusted. Added remotely? Verify.

A key you swap face-to-face can't be tampered with — you watched it happen. Add one over a channel and the app marks it unverified until you compare fingerprints on a channel you trust.

Tor is on. Leaving it mails your address.

By default the relay never sees your IP. Turn Tor off only on purpose — clearnet hands your address to the server. Your IP literally is an address.

Tor hides WHERE. We also blur WHEN and HOW MUCH.

Message size is the strongest fingerprint a relay has — so every block is padded to a size bucket (measured: 0.04 bit of length per frame) and your conversation address rotates (default: every 15 min). High-risk mode adds cover traffic the relay can't tell from yours.

We can't read you. We can't be forced to.

Keys are agreed between people, offline. Our relay only ever holds ciphertext — there is nothing on our side to hand over, even under a court order.

A password can be compelled. A key in your pocket can't.

Turn on YubiKey 2FA and unlocking needs your secret AND a tap of your hardware key over NFC. Knowing — or extracting — your password is no longer enough. Opt-in; the choice is yours.

A stolen, unlocked phone beats any crypto.

No messenger survives a phone taken while unlocked, or carrying spyware — it reads your screen directly. We tell you this, because the ones who don't are the ones to distrust.

Forced to open it? Hand them a decoy.

Set a second password that opens a fake, empty profile — your real one stays hidden in the same store. A panic lock disarms your fingerprint, so a compelled finger opens nothing.

One you for work. Another for everything else.

Run several personas under one app-lock and pick which one a contact ever sees. No second number, no second phone — no key, contact, or circuit shared between them.

A room is a choice — not a 1:1 that quietly grew.

Group rooms are end-to-end with no member list on our side — each sender has their own key, and removing someone re-keys the room so they're locked out. But a room trades the deniability of a 1:1 for who-said-what among members; the app tells you so before you start one.

swipe · drag · scroll

No phone number. No email. No trace.

YGOOW for Android is on its way. Your key, your rules — everything else is redacted.

Get it on Android — soon