Hush Vault

Private preview · Invitation only

Some words belong onlyto those they're meant for.

Hush Vault is a messenger for conversations between people who trust each other. Every message is sealed on your device — and opened only on the device it was written for.

This figure is a guilloche — the pattern that makes banknotes hard to forge. Here, your key draws its own.

  • Invitation only
  • Built on the Signal protocol
  • No ads, no tracking

Frankly: Hush Vault is a private preview. The external audit is still pending — only then will we open up to real users.

The promise

Your conversations belong to you.Not to the network between you.

Most apps make their living by knowing you. Hush Vault is built the other way round: the service knows as little as possible — not out of kindness, but because the design leaves it no choice. What it doesn't have, it can't lose, can't sell, and can't hand over.

Four simple truths

Privacy you don't have to switch on.

No toggles, no fine print. These four things aren't settings — they are the construction.

Only you two can read

Every message is sealed on your device. In transit it's just noise — it becomes readable again only for the person it was written for.

On-device encryption

You are not a number

No phone number as identity, no address-book upload. You pick a name; your device creates the rest — random, and yours alone.

Pseudonymous accounts

We collect nothing

No ads, no tracking, no analysis of your behaviour. Only what delivery strictly requires is stored — and deleted afterwards.

Data minimisation

Safe for tomorrow, too

The encryption is already built for the computers of the day after tomorrow. What someone intercepts and stores today should still be worthless in ten years.

Post-quantum methods

Your message's journey

In transit, it's just noise.

Three stops — your message is readable only at the first and the last.

No trick, no exception: the server receives a string of bytes, a random recipient identifier and a deadline. Nothing more.

  1. 1

    Sealed

    On your device, before it leaves. The key for it exists for this one message and no other.

  2. 2

    In transit

    Our server passes along a locked parcel. It cannot open it — no content, no name, no preview.

  3. 3

    Arrived

    Only the recipient's device can break the seal. Afterwards, the server deletes the parcel.

How you connect

You don't find each other — you invite each other.

Hush Vault has no user search and no directory. A connection only happens when two devices exchange a personal invitation — nothing more is needed, and nothing less will do.

A symbolic film, not a screen recording — the real interface stays with the private preview.
  1. 1

    Create an invitation

    Your app creates an invitation: one-time, short-lived and cryptographically bound to you. No name, no number — just keys.

  2. 2

    Show it or send it

    Shown directly as a QR code — or sent as a link over a channel you already share. The invitation travels device to device, never through a directory.

  3. 3

    Sealed

    Your counterpart redeems the invitation and the devices establish the encrypted session. Our server connects two mailboxes — who you are, it never learns.

Proven craft

No experiments. No homegrown cryptography.

Hush Vault does not invent its own encryption. The foundation is the open Signal protocol stack — the same battle-tested technology billions of conversations trust every day. We build the app around it, not the method itself.

A fresh key for every message

Every message gets its own key, and the old one is deleted. Even someone who steals a key later can't open the past.

If a key changes, you see it immediately.

If the person you're talking to changes device or key, Hush Vault warns you — impossible to miss, impossible to dismiss. That is exactly the moment an intruder would be exposed. Which is why the warning is never allowed to be polite.

For those who want to go deeperPQXDHDouble RatchetML-KEM · FIPS 203libsignal

The difference

Where Hush Vault is built differently.

No marketing duel — a table. This is how the well-known messengers differ in construction, according to their public documentation.

Hush VaultPreview · audit pendingSignalThreemaWhatsAppTelegram
Every chat end-to-end encrypted by defaultby construction; externally audited before releasepresentpresentpresentpresentnot, or not by default
Sign-up entirely without a phone numberpresentnot, or not by defaultpresentnot, or not by defaultnot, or not by default
Your address book stays on your deviceupload isn't even part of the designpresentpartial or optionalpartial or optionalnot, or not by defaultpartial or optional
Free of ads and ad-tech ownershippresentpresentpresentnot, or not by defaultpartial or optional
Invitation only, no public directorypresentnot, or not by defaultnot, or not by defaultnot, or not by defaultnot, or not by default
Post-quantum methods in session setuphybrid, per FIPS 203presentpresentnot, or not by defaultnot, or not by defaultnot, or not by default

Based on the providers' public documentation, as of July 2026, without guarantee. Hush Vault is a private preview — our own column counts as confirmed only once the external audit has passed. Signal deserves respect: we build on their open protocol.

Honestly

What we don't promise.

  • No app in the world can protect a phone that is unlocked or compromised.
  • Anyone allowed to read a message can photograph it or pass it on.
  • Disappearing messages are housekeeping — not protection against a recipient with bad intentions.

And “unbreakable”? You will never hear that word from us. Anyone who uses it has earned your distrust.

Where we stand

Prove it first. Then open up.

Hush Vault doesn't come with a countdown — it comes with an order of steps. Each one is verified before the next begins.

  1. Secure core of the iOS app

    complete and locally verified

  2. Real encrypted messages between two installations

    complete and locally verified

  3. Final checks on the server path

    in progress

  4. Independent security audit

    pending — only then do we open up to real users

See the full status

Plain answers

Common questions.

Can Hush Vault read my messages?

This is how the app is built: messages are sealed on your device, and our server transports only unreadable parcels. And before real users start, an independent audit has to confirm exactly that, in writing.

Do you need my phone number or my contacts?

No. No number as identity, no address book upload. You connect through a personal invitation — a QR code you show each other in person.

How do I find other users?

You don't — there is no search and no directory. An invitation travels device to device: shown directly as a QR code, or sent as a one-time, short-lived link. Whoever you don't invite can't find you.

Can I download the app yet?

Not yet. Hush Vault is in private preview, with a small circle testing. If you'd like to be part of it, write to us — access is granted personally.

What does “safe for tomorrow” mean?

Encrypted data intercepted and stored today could be attacked with future quantum computers. That's why Hush Vault combines a proven classical method with a new one designed for exactly that.

Why invitation only?

Because trust doesn't scale like advertising. The circle grows through people who know each other — slowly, and on purpose.

Some things stay between you.

No store listing, no waitlist countdown. If you'd like to review the private preview with us, get in touch — a person will answer.