Security & privacy
Iris Chat security and privacy
Iris Chat is an open-source messenger with end-to-end encrypted direct and group conversations. Your identity starts with keys on your device, not a phone number.
What protects your messages?
Iris uses Nostr Double Ratchet for encrypted chat. Message encryption happens at the conversation endpoints, so a message server carries encrypted content rather than needing the keys to read your conversation.
The double-ratchet design updates message keys as a conversation progresses. Iris’s implementation and security properties must be evaluated on their own. “Signal-style” describes a design relationship; it is not a claim that Iris uses the same implementation or has Signal’s security review.
Technical references: Iris Chat overview · Encryption dependencies · Rust core implementation
Your keys are your identity.
The app creates identity keys locally without registering a provider account, phone number, or email. Share a user ID or invite to connect. Keep your secret key private: someone who gets it may gain control of your identity.
Device linking lets you authorize another device. Only approve devices you control, and remove devices you lose or stop using. Protect each device with its operating system’s lock and storage protections.
Recovery of an identity and recovery of message history are different. A secret key is not, by itself, a complete backup of your local conversation state.
How messages travel
You choose the compatible Nostr message servers that carry your online messages, including servers you operate yourself. Your identity is independent of those servers. The app also supports nearby connections over Wi-Fi/LAN and Bluetooth.
You do not need an Iris-operated messaging service to register your identity. Individual servers can set their own access policies, and delivery still needs a reachable route. Choosing your own message servers does not remove every platform dependency, such as mobile notification services.
Nearby messaging needs compatible devices, permissions, and a reachable local path. A working connection can carry local messages without internet, but it cannot deliver to a remote person without a route to them. Mobile operating systems can restrict background activity.
Technical references: Architecture · Messaging features
What encryption does not promise
- It does not make a compromised device safe. A recipient, linked device, or software running at an endpoint can read the content available there.
- It does not make you anonymous. Network services can observe connection information such as IP addresses and timing. Do not assume every kind of metadata is hidden.
- It does not guarantee delivery. Connectivity, background restrictions, and the other person’s device state still matter.
- It does not prevent copying. A recipient can save, forward, or photograph a conversation. An agent in the conversation can process its messages.
Evaluate the implementation.
The native app source is available under the MIT license. Its Rust core is shared across native interfaces. Android, iOS, and macOS are tested most actively; Windows and Linux receive less testing.
This page explains the design and practical limits. It is not an independent security audit. For sensitive use, review the current code, release information, and your own threat model instead of treating a feature comparison as a security certification.