No accounts
Choose a nickname. No email, phone number, profile, or identity check is required.
Advanced Confidential Message Transfer Network
Ephemeral encrypted conversations. No accounts. No message history.
Private entry
Enter a new PIN to create a room, then share the exact PIN with the people you invite.
Privacy by design
ACMTN is a short-lived relay for conversations that should not become a permanent record.
Choose a nickname. No email, phone number, profile, or identity check is required.
Messages are encrypted in your browser before transfer. The relay cannot read them.
Encrypted messages live only in RAM for up to 15 seconds, then are discarded.
Your privacy depends on keeping a strong, unique room PIN secret. Anyone with that PIN can join the room.
The flow
A new PIN creates a room; a shared PIN joins one. The PIN is never sent to the server.
Your browser derives a room lookup hash and a separate message encryption key from the PIN.
Nickname, message, UTC time, and message ID are encrypted together in your browser.
The service relays ciphertext from RAM for 15 seconds. Participants decrypt it locally; expired messages are gone.
Protocol trace
You enter an ASCII PIN. Your browser applies a slow PIN derivation step, then makes two different values: a room lookup hash and a private AES-256-GCM message key. The PIN and message key are never sent.
The browser opens /room?hash=… and later calls the room API with the lookup hash. This hash identifies a temporary relay bucket; it is not the PIN and cannot decrypt messages.
Your nickname, message text, UTC timestamp, random message ID, and protocol version are serialized together. The browser encrypts that payload with AES-GCM and a fresh 96-bit random nonce.
The server receives only version, message ID, nonce, and ciphertext. It hashes the lookup hash once more for its RAM map key. It cannot turn that data back into a nickname or message.
The server holds the encrypted envelope with an expiry time in RAM only. A GET request returns active envelopes. No message body is written to a database, backup, cookie, or chat log; expired envelopes are removed from memory.
A browser with the same PIN derives the same AES key, verifies each ciphertext, decrypts it locally, rejects duplicates by message ID, and orders valid messages by UTC time. Refreshing clears the visible conversation and requires the PIN again.