One private app for people, groups & teams

Talk freely. Sealed on your device.

Private 1:1 and group messaging, encrypted media, disappearing and password-locked chats, status and live location β€” with a transparent, bounded promise about what our servers can and cannot see.

See how it's built
Try it:

Everything you use every day

These features are live in the app today. The bigger team and creator tools are on the roadmap below β€” we don't show them here until they ship.

Private 1:1 messaging

Direct messages use Olm Double Ratchet envelopes. If no encryption session is available, the app fails the send rather than falling back to plaintext.

Squad messaging

Squad sends use Megolm epochs β€” encrypted once on your device, then fanned out by the server, which never holds the message keys.

Chat lock & PIN protection

Lock specific chats behind a dedicated password. Locked chats stay hidden from the main list until unlocked.

In-chat & person-wise search

Search across all messages or filter by sender inside a room. Everything is indexed locally on your device.

Disappearing messages

Set a timer per chat (24 hours to 90 days). Messages purge locally and from recipient devices after expiry.

Excel report export

Export conversation history to XLSX directly from your phone. Generates locally without sending data to third parties.

Device linking via QR

Link companion browsers by scanning a QR code. Identity certificates are signed by your primary phone.

Granular privacy controls

Control last seen, read receipts, squad invite permissions, and avatar visibility per contact or globally.

In-chat tasks

Assign work inside a thread with an owner and a due date. Title, assignee and due date travel inside the encrypted message payload and are stripped from the wire, so the server never sees them.

Polls & surveys

Ask a question across a group. The question, the options and every individual vote ride inside the encrypted payload; each device tallies the result locally. There is no server-side poll store.

Creator channels & Hearts

Broadcast channels, locked posts and an in-app currency with verified Apple and Google purchases.

Privacy, stated honestly

What we can β€” and can't β€” see

A privacy promise is only worth as much as its bounds. Here are ours, in plain terms.

Sealed on your device

  • Message text, edits, reactions and replies
  • Attachments, files, images, video and thumbnails
  • Voice notes, captions and filenames
  • Private location coordinates
  • Status/story content and backup contents
  • Private keys, session ratchet state and group keys

Needed to run the service

  • Account: user ID, verified phone number, profile name
  • Devices: device ID, platform, model, app version, public keys
  • Groups: group IDs, membership and admin roles
  • Delivery: envelope size, routing, timestamps, delivery status
  • Operations: IP, user-agent, login and security events
  • Commercial: billing and wallet records

Protected direct-message sends use Olm Double Ratchet envelopes and protected group sends use Megolm epochs. If a current encryption session is unavailable, the app fails the send instead of using a static-key fallback or plaintext. Production E2EE verification is still in progress β€” we show a verified indicator only once it is earned, never on the strength of transport encryption alone.

Where this doesn't reach:a compromised or rooted device can read its own messages; anyone you message can screenshot or forward what they can already see; content you report is shared with us by your own choice; and the metadata above is retained, not encrypted. The browser client shares the page's code with the server, so a signed native app is the stronger trust model.
On the roadmap

Clear status, no marketing fluff

Anything on this list is genuinely not available yet, and we say why. Features are moved out of here the moment they ship β€” we would rather under-promise than list something as live before it is.

Voice & video calls

Coming soon

Group and 1:1 calling.

Why off: Requires a provisioned LiveKit SFU on the deployment you are using.
Global compliance

Built for GDPR, CCPA and India's DPDP

We don't sell or monetize your personal data, and we support self-service account deletion and data export.

US CCPA / CPRA & NCMEC CyberTipline reporting
EU GDPR & the 1-hour illegal-content queue
India IT Rules 2021 & DPDP Act 2023
Lawful data requests
Government & law-enforcement portal

A valid legal request returns only what VTOKK lawfully holds β€” account details, device keys, audit logs, and evidence a user chose to report. Unreported message text and private keys stay cryptographically unavailable, to us and to anyone we'd have to hand data to.

Get VTOKK on your devices

iOS, Android and desktop. Link a new device in seconds with an ephemeral QR code.

Multi-device QR linking supported