Conversations that no company can read, host, or delete.

Hollow is an encrypted chat app for friends and communities, with servers, voice channels and screen sharing. The servers run on your members' devices instead of a company's, and you don't need an account.

v0.12.0·free, AGPL-3.0·source on GitHub

Servers that belong to their members

Every member keeps a copy of the server, and changes travel between them as signed updates. There is no central copy for anyone to seize or switch off.

  • Text and voice channels, with roles, labels and temporary access
  • Private channels have their own encryption, so members without access can't read them
  • Public channels anyone can read without joining, in the app or right on this site

Voice, video and screen sharing

Calls go device to device whenever they can and are encrypted frame by frame. Screen shares use a video mode built for screens rather than webcams, so code and small text stay sharp.

Game and app audio
Game or music audio gets its own stream. Where your system supports it, you can share one app's sound instead of everything.
One upload, any number of viewers
Your machine sends one copy, and a forwarder passes it on to everyone watching. The forwarder can't decrypt it.
Fitted to each viewer
Every viewer gets a stream sized to their display, and a weak connection drops to a lighter layer instead of stuttering.
Watching is opt-in
A share sends you nothing until you press Watch.
Noise suppression on your device
RNNoise on every device, plus DeepFilterNet3 on desktop. No cloud service ever touches your audio.
Global push to talk
Push to talk, mute and deafen work while Hollow is in the background, on Windows and Linux.

Messages and files, encrypted end to end

Messages sent while you're offline wait for you on the relay, encrypted and held only in memory, for up to a few days.

  • Files up to 34 MB go device to device, and bigger ones spread across peers the way BitTorrent does
  • Send up to ten photos and videos as one album, and step through everything shared in the viewer
  • Receiving a link preview never makes your device visit the site
  • Messages, files and voice notes are encrypted on your own disk too

Your identity is a key you hold

It's made from a 24-word recovery phrase. There's no email, phone number or password, and nothing to sign up for.

  • Link your phone and desktop with a short code, and remove a lost device from any other
  • Compare a safety number to know you're talking to the right person
  • App Lock on every platform, with a duress code that quietly erases your data instead of unlocking
  • Destroy your identity on all your devices at once, even the ones that are offline

And the rest

Meetings from a link
Anyone with the link can ask to join, and you decide who comes in.
Emotes, stickers and GIFs
Your emotes follow you to every device, and sticker packs travel as plain files. One picker has all of them.
Notifications without Google
Android phones can wake through UnifiedPush apps such as ntfy.
Twitch verification
Open a server only to your followers or subscribers.
Portable mode and profiles
Run Hollow from a folder, or keep separate identities side by side.
The Hollow Shop
Avatars, banners and frames by independent artists. You buy from the artist, and Hollow takes no cut.

What the relay can and can't see

Devices behind home routers can't always reach each other directly, so a relay passes messages between them. The whitepaper lists everything it handles, and this is the short version.

It can't

  • Read your messages, files, profiles or calls
  • Learn your name, phone number or email, because Hollow never asks for them
  • Fake or change a message, because each one is signed by the device that sent it

What it needs to deliver messages

  • A random ID for each of your devices, made by the app
  • Your IP address, which every server you connect to sees. It's used for connection limits and never logged
  • Which device IDs share a room, under random room codes
  • When data is sent and how much, never what it says
  • On phones, the push token that lets it wake the app

All of it stays in memory and is never written to disk.

$ hollow --stack

  • messages Olm (Double Ratchet) · vodozemac · forward secrecy
  • servers MLS · OpenMLS 0.9 · RFC 9420
  • calls SFrame · AES-128-GCM · per frame
  • identity Ed25519 · BIP-39, 24 words
  • storage SQLCipher · files encrypted at rest
  • relay routing metadata · in memory only

Run your own relay

Ours is free and already running, so you never have to. For a network of your own you need a VPS with a public address and about twenty minutes. A free DuckDNS name works, and the certificate renews itself.

One relay held about 572,000 concurrent connections on an $8 a month VPS. See the benchmark

Read the self-hosting guide
$ git clone --recurse-submodules \
    https://github.com/VitalikPro13/HOLLOW.git
$ cd HOLLOW/relay-uws
$ cp .env.example .env
# set your address, TURN secret and email
$ docker compose up -d

Get Hollow

Install it, write down your recovery phrase, and start talking. Our relay is free, paid for by AnonListen and community supporters.