Safety
Hollow
Last Updated: Jul 10, 2026
Whenever someone hears about an encrypted messenger, the same question comes up: doesn't this just become a place for criminals? It's a fair question, and it deserves a direct answer rather than silence. This page explains what Hollow can and cannot do, why it is built that way, and what the law actually requires of a service like this. Everything here is checkable. Nothing depends on trusting us.
We cannot read your messages
Not "will not." Cannot. Direct messages are encrypted with Olm (the Double Ratchet protocol, the same one Signal uses), and server channels with OpenMLS. Both mean the keys live on the devices of the people in the conversation and nowhere else. The relay that connects you to other people receives an encrypted blob, forwards it, and forgets it. It holds nothing on disk. It has no key to try.
Your identity is an Ed25519 keypair generated on your device from a recovery phrase. There is no email, no phone number, and no account on any server of ours. We do not know who you are, and there is no record we could be compelled to hand over, because the record was never created.
This is not a promise in a privacy policy. It is the architecture, and the architecture is public. Hollow is AGPL-3.0. You can read the relay source, confirm it never writes user data to disk, and build it yourself. An open codebase turns a claim into something you can check.
We will not scan them either
The usual suggestion is client-side scanning: hash every image on the device against a database of known illegal material before it gets encrypted. People propose this in good faith. We still refuse, for three reasons.
It builds the capability that does not currently exist. Right now, when someone demands access to user content, the answer is that there is nothing to give and no mechanism to give it with. That answer is complete. Ship a scanner and the answer stops being true. The scanner becomes the hook. Every later demand (scan for this too, add these hashes, report these matches) attaches to a mechanism that was built voluntarily. Governments in the EU and UK have spent years trying to force exactly that mechanism into encrypted messengers. Building it ourselves would hand them the fight they lost.
The hash databases are not available to us. The PhotoDNA and IWF lists are distributed only to vetted, licensed members under contract. An independent developer cannot lawfully hold them. Client-side scanning is not an option we are declining. It is an option we do not have.
It does not work. Apple announced on-device scanning of iCloud Photos in August 2021 and abandoned it in December 2022, concluding that child protection is achievable without companies combing through personal data. Within days of the announcement, researchers pulled the algorithm out of iOS and produced a collision: two different images with the same hash. The best-resourced company on earth tried this, got it wrong, and walked it back. False positives are not hypothetical. In 2022, a father who photographed his son's infection at a doctor's request had his Google account terminated and was investigated by police. He was cleared. The account was never restored.
Signal does not scan. Neither do Briar, SimpleX, or Session. Neither does Hollow. Not scanning is not a loophole any of us found. It is the foundation everything else rests on.
What the law actually requires
Most people arguing about this online assume that a service which cannot inspect content is skirting the law. The opposite is true, and the statutes are unusually clear about it.
United States
The federal reporting statute requires a provider to report child sexual abuse material when it obtains actual knowledge of it. The same statute then says, in its own text, that nothing in it requires a provider to monitor users, monitor the content of communications, or affirmatively search, screen, or scan for such material. Congress wrote the no-duty-to-scan rule directly into the law. A service that handles encrypted blobs it cannot decrypt never obtains that knowledge, and so has nothing to report.
18 U.S.C. § 2258A(a) (reporting duty on actual knowledge) and § 2258A(f) (no duty to monitor, search, screen, or scan). Read the statute
The underlying crimes work the same way. Every operative subsection of the criminal statutes requires that the person knowingly receives, distributes, or possesses the material. Knowledge of the content is a required element of the offense. A relay that transmits ciphertext it cannot decrypt cannot knowingly do any of those things. This is the same reason a phone company has not committed a crime when a crime is discussed on a call it carried.
18 U.S.C. § 2252 and § 2252A. Read the statute
European Union
EU law gives a transit-only service two direct protections. The first is the "mere conduit" rule: a provider that transmits information is not liable for it, so long as it does not initiate the transmission, does not select the receiver, and does not select or modify the information. Hollow's relay satisfies all three by design, since it cannot even read what it carries. The second is a prohibition: member states may not impose a general obligation on conduits to monitor what they transmit or to actively look for illegal activity.
e-Commerce Directive 2000/31/EC, Art. 12 (mere conduit) and Art. 15(1) (no general monitoring), carried forward by the Digital Services Act, Art. 4. Read the directive
Hollow is also not an "online platform" under the DSA. That term is defined as a service that stores content at a user's request and disseminates it to the public. The relay stores nothing and disseminates nothing it selected. Private messaging is excluded from the definition outright.
Digital Services Act (EU) 2022/2065, Art. 3(i) and Recital 13. Read the regulation
United Kingdom
The Online Safety Act 2023 contains a power for Ofcom to require "accredited technology" to detect illegal content, including in private communications. It has never been used. No technology has been accredited, the government has conceded that none exists which can do this without breaking encryption, and both Signal and WhatsApp said they would leave the country rather than comply. The clause is on the books and dormant. If it is ever activated, Hollow faces the same choice as everyone else, and will make the same one.
Online Safety Act 2023, §121 (notices to deal with terrorism or CSEA content). Read the section
The people who were charged, and why
Two cases get raised whenever this comes up. Both are worth understanding, because both turned on the thing Hollow does not have.
Pavel Durov, Telegram, France, 2024. He was indicted on charges including complicity in distributing child exploitation material. The charges rested on platform negligence, insufficient moderation, and refusal to cooperate with legal requests. They did not rest on offering encryption. Telegram is not end-to-end encrypted by default. It can see most content on its service, it has moderation tools, and it chose how to use them. That is knowledge and control, which is exactly what creates exposure. Telegram is the opposite of Hollow's position, not a comparison to it.
Roman Storm, Tornado Cash, United States, 2025. Convicted of operating an unlicensed money transmitting business. The prosecution's theory was that he continued providing the service with knowledge that it was moving criminal proceeds and was personally aware of specific instances. Liability came from knowing facilitation.
The line the law draws is knowledge and control, not encryption. In the fifteen years that default end-to-end encrypted, no-content-storage messengers have existed, no operator of one has been criminally charged or held liable for what users sent through it. Not Signal, not Briar, not SimpleX, not Session.
Where the line actually sits
- No technical capability to know. Cannot decrypt, stores nothing. This is the lawful conduit position.
- Willful blindness. Deliberately structuring to avoid knowledge of specific activity you were told about. Risk zone.
- Knowing facilitation. Has knowledge and control, continues anyway. Telegram, Tornado Cash. Charged.
The distinction between the first and second row matters, and we take it seriously. A service with no capability is not avoiding knowledge. It structurally cannot obtain it. To keep that unambiguous, Hollow's Terms of Use prohibit illegal content by name, there is a reachable contact at the bottom of this page, and we will act on anything we can act on. That is not much, because there is not much that can be done from our side.
What happens when a government asks
We will comply with a valid, binding court order under applicable law. What that produces is nothing, because nothing exists to produce.
- No message content. There are no keys and no stored messages.
- No identities. Accounts are keypairs with no link to a real person.
- No history. The relay keeps no persistent record of activity.
- No social graph. The relay does not persist who talks to whom.
There is no master key. Unlike Lavabit, which was forced to hand over the single TLS key protecting all users in 2013, Hollow has no such key to hand over. Every user holds their own. A court can order us to produce something we do not have, and the order will still produce nothing.
Users will be notified of any request unless we are legally prohibited from doing so. Overbroad or legally questionable requests will be challenged. Every request received will be documented in the transparency report. As of this writing, there have been none.
How Hollow protects you
The safety model is the opposite of the one you are used to. Large platforms try to make everything reachable and then filter what arrives. Hollow makes nothing reachable unless you reach for it first.
- There is no search and no directory. You cannot look up a user. Nobody can look you up. No list of users or servers exists anywhere, including on the relay.
- There is no discovery and no algorithm. Nothing is recommended to you. Nothing surfaces content or people you did not go looking for.
- Strangers cannot contact you. A direct message requires that you accepted a friend request, and a friend request requires that someone already had your identity.
- Servers are invite-only by default. You join a server because someone gave you a link or an ID. There is no browsing.
- Public channels are pull-only. They are readable without joining, but only by someone who already holds the server's identifier. There is no index of them. The relay does not know which servers have them.
Without knowing where you are going, the app does nothing. That is deliberate. It also means the practical advice is short, and it is the same advice that works everywhere else: join communities you already trust, from people you already know. A streamer you follow, a group you are part of. Not a random link. Do not add strangers as friends. Nothing in Hollow will ever push a stranger at you, but nothing stops you from choosing one.
If someone bothers you, block them. Blocking is enforced on your device before anything reaches you, so it works even against someone who has modified their client. You can also report a user to the relay operator, which is anonymous and acts on the one thing that can be acted on from our side: relay access.
Hollow does not have a scanner protecting you. It has a design where the people who would need scanning cannot find you in the first place.
Check it yourself
Every claim on this page is verifiable, and none of them require trusting us.
- The full source is on GitHub under AGPL-3.0. The relay is in
relay-uws/. Read it and confirm it writes no user data to disk. - The whitepaper documents the cryptography and the threat model.
- The legal research behind this page is public, with all sources cited.
- Builds are signed. The certificate reads Open Source Developer Vitalii Rovinskyi. That is a real person whose identity was verified against government ID, not a company that can dissolve.
A named developer stands behind this software, and that developer cannot read your messages. Both of those are on purpose, and they are not in tension. Someone willing to be identified is not the profile of a person building a haven for criminals. The services built for that purpose are anonymous, closed-source, and incorporated somewhere that ignores subpoenas. Hollow is none of those things.
We can come together on a single matter that is taken away from us every single day: privacy and ownership. You deserve it. Don't let anybody tell you otherwise.
Contact
Report abuse or send legal correspondence to privacy@anonlisten.com