AI summary
Serverless Tor-based messenger with no accounts or central servers. Uses v3 .onion addresses as identities, with RAM-only chat mode for forensic resistance. Includes obfs4/Snowflake bridges, group chat, file sharing, and contact QR codes. Note: no application-layer encryption yet—relies on Tor transport encryption. Requires Camera permission for QR scanning.
Generated by AI. May contain inaccuracies.
About this app
A censorship-resistant, serverless messenger for Android. Your .onion address is your username. No accounts. No servers. No metadata for anyone to collect.
LCha is a from-scratch, Ricochet/Briar-style messenger: two phones talk directly to each other over the Tor network, end-to-end encrypted, with no central server in between — nothing to block, subpoena, or shut down.
Why LCha exists Modern messaging platforms are surveillance machines, and not just for their content:
Metadata is the goldmine — who you talk to, when, from where, how often. Traffic analysis of metadata reveals more about you than the messages themselves, and it's all sitting on someone's server. Central servers are chokepoints — one court order, one ISP block, one domain seizure, and an entire population loses its communication channel. Censorship regimes block by domain and IP — if an app's servers are known, they're blockable. A serverless overlay has no address to block. LCha is designed so that none of these attacks have a target.
How LCha fights back Surveillance / censorship threat How LCha defeats it Content interception (ISP, MITM, passive wiretap) Tor onion-to-onion encryption: all traffic is encrypted end-to-end through Tor circuits. No plaintext leaves your device. Metadata collection (who talks to whom, when, from where) All traffic rides Tor circuits. Your peer sees a Tor rendezvous point — never your IP. There is no server that ever sees the conversation graph. App-level censorship / blocking (DNS, domain, IP filtering) No central domains or IPs exist. Peers are reached by v3 .onion addresses that are meaningless to DNS-based filters; built-in obfs4 and Snowflake bridges work out of the box — no external binaries needed. Server compromise / seizure / subpoena There is no server. Nothing to log, nothing to seize, nothing to coerce. Forensic data recovery (device seized, disk imaged) Chats in RAM mode: messages exist only in memory and are wiped the instant the app closes. No SQLite file, no WAL journal, no recovery possible. Toggle on/off in Settings. Account takeover / impersonation Identity is a cryptographic ed25519 key — the v3 onion address is derived from the key itself. There is no password to phish, no account to reset. Identity linkage across devices Optional identity rotation: generate a brand-new onion address any time, leaving the old one behind. Threat model — what LCha does not defend against (yet) Honesty matters in security tooling:
No application-layer encryption — messages are plaintext at the app layer, relying on Tor for transport encryption. A per-message ratchet (Double-Ratchet-style) is the top crypto priority on the roadmap. Tor reachability — Tor must be reachable. In heavily censored regions, use the in-app Tor bridges setting (Settings → Tor bridges): built-in obfs4 or Snowflake work out of the box (IPtProxy is bundled). You can also use custom bridge lines or plain TCP bridges. Device compromise — anyone with your unlocked phone can read everything, exactly like every other messenger. Android Keystore (non-exportable AES-256-GCM) protects keys at rest, but a rooted or physically compromised device is out of scope.
Features Embedded Tor (tor-android) with an in-app on/off toggle — no Orbot required. Tor bridges for censorship circumvention (Settings → Tor bridges): built-in obfs4 or Snowflake (one tap, no setup), direct, or custom bridge lines. Plain TCP bridges work with the bundled Tor; the config is written to torrc and Tor restarts to apply it. Identity = a v3 onion service address, generated on first run, stable across restarts (share via copy or QR). Tor-encrypted 1:1 chat: all messages ride Tor onion-to-onion circuits with built-in encryption. Instant contact addition: share your onion address or invite link — adding a contact is instant, no handshake round-trip, no waiting, nothing to fail. Opening/sharing an lcha:// link opens Add-contact prefilled for one-tap confirmation. Fast, persistent connections: each peer keeps one long-lived Tor circuit that is reused across messages — the first message pays for the circuit, every message after it rides it for free (no more 15–30s-per-message stalls). A dead circuit is transparently rebuilt and the message retried. Offline message queue: undelivered messages are retried (concurrently per contact) every 30s while Tor is up until the peer acks. Online presence: contacts are pinged over Tor (with short, cheap probes); a green dot and Online/Offline status show who is reachable right now. Emoji picker in 1:1 and group chat, and delete conversations (chat screen, or long-press a chat in the list). Contact search: find contacts and conversations by name or onion address, and start a chat straight from the search results (tap any contact in the Contacts tab to message them). Tor + event logs: a Logs screen (Settings → Connection & event logs) shows Tor bootstrap progress, deliveries and errors as they happen. Group chats: one symmetric group key, rotated and re-wrapped on every membership change. File sharing over Tor (encrypted, ≤ 8 MB, opened via the system viewer). Chats in RAM (Settings → Chats in RAM): when enabled, messages exist only in memory — nothing is written to disk. All chat history is wiped the moment the app closes or the phone restarts. No forensic recovery is possible. Toggle it on/off at any time; contacts and your identity key are always saved.
About this version
- Version
- 2.1.0 (12)
- Size
- 185.01 MB
- Requires Android
- 9
- Target SDK
- 28
- Architecture
- arm64-v8a, armeabi-v7a, x86, x86_64
- Downloads
- 9
- Updated
- Sep 4, 2026
- Package
- com.lcha.app
Similar apps
Ratings & reviews
- 50
- 40
- 30
- 20
- 10