Private relay · No accounts

ACMTN

Advanced Confidential Message Transfer Network

Ephemeral encrypted conversations. No accounts. No message history.

Private entry

Create or join a confidential room

Enter a new PIN to create a room, then share the exact PIN with the people you invite.

ASCII characters only, up to 255 characters. Your PIN never leaves this browser.

Privacy by design

Why ACMTN?

ACMTN is a short-lived relay for conversations that should not become a permanent record.

No accounts

Choose a nickname. No email, phone number, profile, or identity check is required.

Ciphertext only

Messages are encrypted in your browser before transfer. The relay cannot read them.

Short memory

Encrypted messages live only in RAM for up to 15 seconds, then are discarded.

Your privacy depends on keeping a strong, unique room PIN secret. Anyone with that PIN can join the room.

The flow

How does it work?

  1. 01

    Choose a room PIN

    A new PIN creates a room; a shared PIN joins one. The PIN is never sent to the server.

  2. 02

    Derive secrets locally

    Your browser derives a room lookup hash and a separate message encryption key from the PIN.

  3. 03

    Encrypt before transfer

    Nickname, message, UTC time, and message ID are encrypted together in your browser.

  4. 04

    Relay, decrypt, discard

    The service relays ciphertext from RAM for 15 seconds. Participants decrypt it locally; expired messages are gone.

Protocol trace

What moves, what stays, and what disappears

  1. Only in your browser

    You enter an ASCII PIN. Your browser applies a slow PIN derivation step, then makes two different values: a room lookup hash and a private AES-256-GCM message key. The PIN and message key are never sent.

  2. Address and request

    The browser opens /room?hash=… and later calls the room API with the lookup hash. This hash identifies a temporary relay bucket; it is not the PIN and cannot decrypt messages.

  3. Before a message leaves

    Your nickname, message text, UTC timestamp, random message ID, and protocol version are serialized together. The browser encrypts that payload with AES-GCM and a fresh 96-bit random nonce.

  4. What the server receives

    The server receives only version, message ID, nonce, and ciphertext. It hashes the lookup hash once more for its RAM map key. It cannot turn that data back into a nickname or message.

  5. 15-second RAM relay

    The server holds the encrypted envelope with an expiry time in RAM only. A GET request returns active envelopes. No message body is written to a database, backup, cookie, or chat log; expired envelopes are removed from memory.

  6. Only participants can read

    A browser with the same PIN derives the same AES key, verifies each ciphertext, decrypts it locally, rejects duplicates by message ID, and orders valid messages by UTC time. Refreshing clears the visible conversation and requires the PIN again.