Legal
Coming Soon — December 2026
The Blind Router Network

No number.
No footprint.
Just messaging.

ONYXCHAT is an Android messenger, built by Sednium, that never asks for your phone number and never keeps a copy of your messages. The relay routes an encrypted payload and forgets it existed.

Coming Soon — December 2026
Read the Research
Built by Sednium
No Phone Number
Hybrid Post-Quantum E2EE
ONYXCHAT ghost mascot
Hi, I'm Ony! 👋
Why It's Built This Way
Three decisions, not a marketing checklist
Every architectural choice below removes a specific point of trust you'd otherwise have to place in a server you don't control.

Blind relay server

The backend's only job is moving an encrypted payload from one device to another over Firebase Cloud Messaging. It doesn't parse it, store it, or keep a message log. There's no database table it could hand over even if compelled to.

No phone numbers

Identity is a Routing ID derived from your Google Account, not a SIM card. It removes SIM-swap risk and contact-scraping entirely, and it means your telecom provider is never part of the trust chain.

Hybrid encryption, not homebrew

Encryption is layered from two audited, independent building blocks: libsignal's Double Ratchet and BouncyCastle's ML-KEM-768, combined with a standard HKDF construction. No custom cipher, no unverified primitives.

Coming Soon

Desktop client for Windows & Linux

The same blind-relay architecture and hybrid encryption layer, brought to a native desktop app so your conversations aren't tied to a single phone. In active development.

Your Identity
The Routing ID
An 8-character hex address replaces your phone number as the way people reach you.
  identity.model

When you set up ONYXCHAT, nothing about your telecom carrier or SIM is involved. Instead the app generates a Routing ID: your public address on the network.

To message someone, you only need their Routing ID or their QR code. The network maps that ID to an encrypted delivery token behind the scenes, so the relay knows where to send a payload without knowing who's sending or receiving it.

Public Routing ID0x63101700 :: Hidden Delivery TokendRPE4ertSsevo...xK9
ONYXCHAT new connection screen showing routing ID entry, camera scan and upload QR options
ONYXCHAT secure address screen showing a QR code and routing ID with copy and share options

Share it like a QR code, not a phone number

Your Routing ID can be scanned, copied, or shared as a link. Nobody can bulk-discover you through a contacts sync, because there's no phone number field to scrape in the first place.

Security Architecture
A hybrid encryption layer, built from audited parts
ONYXCHAT wraps the Signal Protocol in a post-quantum envelope instead of replacing it. Here's exactly how a message travels.
Show the technical deep-dive +
  message-lifecycle
ComposePlaintext message created on-device
Hybrid EncryptAES-256-GCM under a key from ML-KEM-768 + ECDH via HKDF-SHA256
RatchetCiphertext passed into libsignal's Double Ratchet, unmodified
Blind RelayServer pushes the envelope via FCM and retains nothing

The inner layer is stock, vetted libsignal (the same Double Ratchet construction used by Signal), providing forward secrecy and post-compromise security exactly as it does there. Nothing about that library is modified.

The outer layer is what's new: a static ML-KEM-768 key pair (BouncyCastle's PQC provider) is combined with the classic ECDH secret, fed through HKDF-SHA256 with a fixed info string, to derive an AES-256-GCM key that wraps the message before it enters the ratchet. This protects the initial handshake against "harvest-now-decrypt-later" attacks: an attacker recording today's traffic can't decrypt it later once quantum computers are viable, because the key material isn't classical-only.

Nonce handling

A fresh 96-bit nonce is generated with SecureRandom for every message and prepended to the ciphertext: no counter, no reuse risk across reinstalls or multiple devices.

Combiner function

Classic ECDH secret and the ML-KEM-768 shared secret are concatenated and run through HKDF-SHA256, matching standard practice for hybrid PQ key exchange.

What's ephemeral, what's not

The ML-KEM keypair is a long-term identity key, not a one-time prekey. It provides authentication and initial confidentiality. Forward secrecy for the conversation still comes from the Double Ratchet underneath.

No custom cryptography

Every primitive (AES-GCM, HKDF-SHA256, ML-KEM-768, the Double Ratchet) comes from an established, independently maintained library. Nothing here is a home-grown cipher.

ONYXCHAT onboarding screen: End-to-End Privacy, messages encrypted on-device with the Signal Protocol

Why this is worth explaining, not just claiming

Most apps market encryption with a single adjective. We'd rather show the actual construction, documented in full at sednium.com/onyxchat, so it can be reasoned about instead of taken on faith.

The Full Picture
The S.H.I.E.L.D. Protocol
Six components, each closing a specific attack surface. Tap a letter to reveal it.

To see more of the S.H.I.E.L.D. Protocol, visit Shield Protocol on Sednium Research.

See It
Inside the app
A look at onboarding, the blind relay explainer, and day-to-day use.
Make It Yours
Five launcher icons, one ghost
Switch your home-screen icon from Settings → Appearance & Theming without changing anything about how the app works underneath.
ONYXCHAT default app icon, ghost on cool teal background
Default
Cool Teal
✓
ONYXCHAT Fire app icon, ghost on red-orange background
Fire
Ember Red
✓
ONYXCHAT Sunset app icon, ghost on amber background
Sunset
Amber
✓
ONYXCHAT Midnight app icon, ghost on charcoal background
Midnight
Charcoal
✓
ONYXCHAT Gold app icon, ghost on golden yellow background
Gold
Sunshine
✓
Your Data, Your Drive
Backups live in your Google Drive, not ours
There's no ONYXCHAT server that ever holds a copy of your chat history.
  backup.engine

Chat history is encrypted on-device with AES-256 and synced to the hidden appDataFolder of your own Google Drive account, a space only ONYXCHAT can access, and only under your Google login. We never see it, and it doesn't pass through our relay.

The vault key itself is now protected by the same post-quantum layer (ML-KEM-768) used for messaging, rather than being derived solely from your Google Account ID. That closes the earlier gap where knowing an account ID alone could theoretically reconstruct the key. The backup key is now wrapped behind device-held post-quantum key material, not just a hash of a non-secret identifier.

About
Built by Sednium
ONYXCHAT is a closed-source product from Sednium. The architecture is documented publicly even though the code isn't.
  sednium.com

Sednium is the studio behind ONYXCHAT. The full technical architecture (the hybrid encryption design, the blind relay model, the identity system) is written up in detail on our research docs, independent of the closed-source client.

sednium.com Research Docs
Ayush Pal
Bhøid
Developer, Sednium
Ankush Das
Løid
Developer, Sednium
Ayush Rudra
Creative Director, Sednium
Debraj Chandra
Beta Tester, Bug Hunter
Stack
Questions
Before you ask Ony
The short answers. Tap any question.
Does ONYXCHAT store my messages on a server?+
No. The relay server routes your encrypted payload to the recipient's device and does not persist it — there's no message database on the backend.
Do I need a phone number to use ONYXCHAT?+
No. You're identified by a Routing ID, an 8-character hex string tied to your Google Account, not a SIM card or telecom provider.
What encryption does ONYXCHAT use?+
A hybrid scheme: the audited libsignal library provides the Double Ratchet for forward secrecy, wrapped in an outer envelope combining ML-KEM-768 post-quantum key exchange with AES-256-GCM via HKDF-SHA256 — protecting the initial handshake against harvest-now-decrypt-later attacks.
Is ONYXCHAT open source?+
No, it's closed source and developed by Sednium. Technical architecture documentation is published separately at sednium.com/onyxchat for anyone who wants implementation detail without the full source.
Where do my backups go, and can Sednium read them?+
Backups upload to your own Google Drive, not a Sednium server. They're encrypted client-side with AES-256-GCM before upload, so the file sitting in your Drive is unreadable without your device's key — Sednium never has a copy or the key to open one.
Can I change the app icon without losing my data?+
Yes. The five launcher themes are purely a home-screen icon swap done through Android's activity-alias system — it doesn't touch your chats, keys, or Routing ID underneath.
What platforms is ONYXCHAT available on?+
Android today, distributed as a direct APK download rather than through the Play Store. Desktop clients for Windows and Linux are in development — screenshots and downloads will be added here once they're ready. There's no iOS build at this time.
What happens if I delete the app or lose my phone?+
Since there's no server-side message history, anything not backed up to your Google Drive is gone with the device. Restoring on a new phone pulls your last encrypted backup and re-establishes your Routing ID through Google Sign-In.
You can talk with me through this button 💬