whispr
how it works get told

Ditch Discord.
Ditch Signal.

Discord gives you somewhere to be, and reads it. Signal keeps your messages to yourself, and wants your phone number for it. Whispr does both at once, and asks you for nothing.

Pre-alpha

The protocol is built. The desktop client is the next piece of work and it is not finished, so there is nothing to download yet and nothing here you should trust with anything that matters.

What you actually get

A place to talk, and nobody in the room who wasn't invited.

The everyday parts work the way you already expect them to. The difference is what happens to them on the way out of your device.

A server for your friends Channels, roles, invites, the shape everyone already knows. Whoever runs it cannot read a word of what is in it.
A group chat that stays one Your family, or the six people planning a trip. A key stolen tomorrow does not open what you said today.
A username and nothing else Pick a name and you are done. There is no document to check it against, so nobody can ask you for one.
Every device you own One account across all of them, and losing one revokes that device without touching who you are.

What it costs to start talking

One wants your identity. The other wants your phone number.

Both of them begin by asking who you are. Whispr begins with a keypair your device generates on its own, and a username you made up.

discord
  • an email address
  • a phone number, in many cases
  • a government ID, if you are flagged as underage or you live under a mandate

all of it tied to your name

signal
  • a phone number

which is issued to a person

whispr
  • a username you pick
  • a key your device generates

neither of which is you

Nothing to verify

Whispr could not check your age if it wanted to.

An age check needs something to attach itself to: a real name, a number that was issued to someone, a document held on file. A whispr account is a key your device made up, so there is no record to gate and no document for anyone to lose. Complying with an age mandate would mean building the protocol differently.

In October 2025 a Discord customer-service vendor was breached. By Discord's own notice, around 70,000 users had government-ID photos exposed, submitted because their age had been questioned. The gates keep tightening elsewhere: since June 2026 an app that reads message content has to be reviewed once it passes ten thousand users, and reapply every year, while getting an app verified at all still means its owner sending a government ID to a payment processor.

master key ML-DSA-65 · never leaves the device unencrypted

signs only these certificates

desktop signs what you send
phone signs what you send
tablet signs what you send

Why any of this should be believed

You should not have to take our word for it.

Whispr is licensed AGPL-3.0, which is copyleft: anyone who runs a modified relay owes its source to the people using it. And relays are self-hostable, so if you would rather trust nobody's infrastructure, you can run your own and a compromise stops with you.

The repositories are not public yet. Until they are, none of this is checkable from the outside, and it deserves exactly as much of your trust as that implies.

There is nothing to install yet.

Leave an address and you will hear once, when there is a build worth running. Or say hello and ask what is actually finished.

The address, and nothing else. One mail when there is a build.