Skip to content

SMarTrTalk, a messenger that knows nobody

Reading time: five minutesOperations and Costs

SMarTrTalk is an Android messenger where contacts come into being only when two people hold their phones together. No phone number, no address book, no people search, no location. The first beta is out.

The short version

Every messenger you know wants to know who you are first. A phone number, an email address, ideally your whole address book. Out of that data grows the thing that makes you vulnerable in the end: a map of your relationships that belongs to somebody else. SMarTrTalk goes the other way. It asks for nothing. It does not know you and it does not know your contacts. Two people who want to write to each other hold their phones together once and scan the other code straight off the screen.

Why the scan

Because being there cannot be faked. The code on screen refreshes every minute and carries fresh randomness. A photo of it is worthless shortly after, a printout even more so. There is no link to forward and no import from the gallery. The regular way in runs through two people standing in the same room.

Because then nobody fits in between. During the scan your camera takes a picture and stores it encrypted, sealed with a key that never leaves the phone. That picture is the contact entry. From then on every key used for checking comes from your own records, never from an incoming message. The server therefore cannot slip anyone in.

Because the server is meant to know nothing. It sees mailbox identifiers, signatures and encrypted packets. It does not know who talks to whom, what the groups are called or who is in them. Groups live entirely on the devices; every administrative action travels individually signed over the ordinary channels.

What this beta does

Writing, end to end. The chat runs on the Signal protocol, the same audited library Signal itself uses. We do not build our own encryption, ever. The session setup adds a Kyber scheme, so that anyone recording today and holding a quantum computer in many years still gets nothing out of it.

Inviting without softening the scan. You can send an invitation to someone on your list. That person shows it on their screen, and the third person scans it live. The invitation is valid once and for 72 hours. Here too there is a scan at the end, just not yours.

Groups the server cannot see. Who may invite is decided when the group is founded. A permitted member shows a group code, the other person scans it and is in. That code too is bound to exactly the screen that displayed it.

Writing in groups only if both want it. Two people who know each other only from a group cannot simply message one another. There is a request with no free text field, and a contact comes into being only once both have agreed. If somebody says no, the other side only learns that the request is no longer open, and for seven days no new one gets through. A no should be allowed to stay a no, without an explanation.

And one way for people who cannot meet. There is exactly one exception to the scan rule, and we say plainly what it costs: the invitation card. You can send it or print it, valid once or ongoing. Anyone who gets hold of it can redeem it, even if it was not meant for them. That is why every card has an expiry and a limit, why your app asks you before every new contact, and why a contact made this way stays marked as such. If you do not need the card, you will never notice it.

Everything locked on the device. The database is encrypted with AES-256, files sit in their own vault with one key per file. In front of that is a PIN whose waiting time doubles with every wrong attempt, and the app locks itself as soon as it goes to the background.

What the app asks for

Internet, network state, camera, biometrics. That is the complete list. No location, no contacts, no storage access, no phone state. Anyone who wants to verify that can verify it: the source is open.

Honestly

This is a beta, and we call it that because it is one. It is built, checked by automated tests and signed, but it has not yet run a day on a real phone. The open items are listed in the test matrix in the source, readable without anyone having to ask.

Things are missing, too. There is no group chat yet; the administration is complete, the messages follow. Calls and files in chat come later. Topping up credit is not possible yet, which is why beta installations start with a generous balance, and receiving never costs anything.

And the most honest sentence last: a messenger that asks you to meet in person before you can write is less convenient than one that just reads your address book. That is precisely the point. Anyone looking for convenience is better served elsewhere, and we would rather say so up front.

Trying it

The beta comes as a file, not from the Play Store. Your phone asks the first time whether it may install from this source, and that is exactly right. Next to the file there is a checksum; anyone who does not compare it has not checked the file. On first start there is no account and no sign-in, the identity is created on the device.

Where to get the file and what changes with each build is posted in our channel t.me/smartragents. Security findings go to [email protected] rather than into a public ticket, so we can close them first and talk afterwards.


SMarTrTalk is a project by smartragents.ai. Source open under MIT.

Imprint · Privacy · Terms · Right of withdrawal

Nine AI agents, one workspace

The agents draft quotes, keep the calendar and sort the inbox, and nothing goes out before you approve it.