Private conversations.
Truly yours.

End-to-end encrypted chat built on the Signal Protocol, running on our own infrastructure. Invite-only. No tracking. No algorithms.

Invite-only · End-to-end encrypted · Free

Why Brume?

Three principles. Zero compromises.

Secure

Signal Protocol (X3DH + Double Ratchet) encrypts every message on your device. Even the server operator cannot read them. Forward secrecy means compromising a key today can't unlock yesterday's messages.

Private

Invite-only registration. No user discovery. No IP logging. No metadata profiling. Self-destruct messages vanish on a timer. GIF searches proxied through your server so providers never see your IP.

Independent

Brume runs on our own infrastructure — not on Big Tech cloud platforms. No corporate intermediary. No third-party data broker. Your conversations never leave a server we control.

Everything you need

Built for real conversations, not engagement metrics.

End-to-end encryption

Signal Protocol for DMs. Sender Keys for groups. Every message encrypted before it leaves your device.

Multi-device sync

Each device gets its own encryption keys. Compromise one device, not your entire account.

Self-destruct messages

5 seconds to 7 days. Client, sender, and server all respect the timer. No traces left behind.

Groups with moderation

Admin, moderator, and member roles. Mute, kick, pin messages. Sender keys rotate automatically on member changes.

Encrypted file sharing

Share files up to 25 MB. Each file encrypted with a unique key. Inline image previews.

Encrypted backups

Restore on a new device with your passphrase. Argon2id key derivation. The server cannot decrypt your backup.

Security, not security theater

We use the same cryptography trusted by security researchers worldwide.

Protocol

Signal Protocol — X3DH key agreement establishes sessions. Double Ratchet provides forward secrecy and break-in recovery for every message.

Key management

Per-device identity keys. Signed pre-keys with one-time pre-keys. Automatic replenishment when the pool runs low.

Group encryption

Sender Keys distributed via pairwise Signal sessions. Keys rotate automatically when members join or leave.

Backup protection

Argon2id KDF (64 MB memory, 3 iterations) derives a wrapping key from your passphrase. The server stores only the encrypted blob.

What the server stores

Encrypted ciphertext, usernames, and timestamps. No plaintext. No IP addresses. No device fingerprints.

What the server cannot do

Read your messages. Decrypt your backups. Identify conversation participants beyond what's in the participant list.

Download

Get Brume for your device

Sign in with your Haloceteki account to download the latest build.